信息安全研究2026,Vol.12Issue(6):490-502,13.DOI:10.12379/j.issn.2096-1057.2026.06.01
基于自适应裁剪的深度学习差分隐私保护方案
A Deep Learning Differential Privacy Protection Scheme Based on Adaptive Clipping
摘要
Abstract
To address the issues of utility degradation in deep learning models under differential privacy protection and the gap between theoretical and actual privacy protection effectiveness,this paper proposes a deep learning differential privacy protection scheme based on adaptive clipping.The scheme optimizes the process through a four-step mechanism:firstly,gradient adaptive clipping controls the gradient magnitude during training by dynamically adjusting the gradient clipping threshold,thereby enabling the control of the magnitude of noise added subsequently;secondly,group label selection identifies the group with the smallest gradient as the privacy-preserving object,and more accurate privacy loss can be obtained by training this group;thirdly,optimized privacy loss calculation combines the gaussian mechanism based on subsampling to reduce the computational overhead of model privacy loss calculation;finally,optimized gradient adaptive descent realizes the adaptive descent of gradients by adjusting the conditional smoothing parameter,thus improving the usability of the model.Experiments were conducted on the VGG architecture using the MNIST,CIFAR-10,and Medical-MNIST datasets.The results show that the model accuracy rates after training with this scheme are 81.08%,72.30%,and 67.91%respectively,representing improvements of 15.60%,10.60%,and 9.71%compared to the traditional DPSGD,and 0.63%,2.50%,and 4.40%over the widely used Nadam algorithm in recent years.The model training efficiency has been improved by 35.5%and 39.4%,respectively.关键词
深度学习/差分隐私/梯度自适应裁剪/标签选择/平滑损失函数Key words
deep learning/differential privacy/gradient adaptive clipping/label selection/smoothed loss function分类
信息技术与安全科学引用本文复制引用
程宇航,尚涛,姜亚彤,杜瑞忠..基于自适应裁剪的深度学习差分隐私保护方案[J].信息安全研究,2026,12(6):490-502,13.基金项目
河北省重点研发计划项目(22340701D) (22340701D)
网络空间安全态势感知与评估安徽省重点实验室开放课题(CSSAE-2023-015) (CSSAE-2023-015)
北京市自然科学基金项目(L251066) (L251066)