| 注册
首页|期刊导航|信息安全研究|基于自适应裁剪的深度学习差分隐私保护方案

基于自适应裁剪的深度学习差分隐私保护方案

程宇航 尚涛 姜亚彤 杜瑞忠

信息安全研究2026,Vol.12Issue(6):490-502,13.
信息安全研究2026,Vol.12Issue(6):490-502,13.DOI:10.12379/j.issn.2096-1057.2026.06.01

基于自适应裁剪的深度学习差分隐私保护方案

A Deep Learning Differential Privacy Protection Scheme Based on Adaptive Clipping

程宇航 1尚涛 1姜亚彤 1杜瑞忠2

作者信息

  • 1. 北京航空航天大学网络空间安全学院 北京 100191||网络空间安全态势感知与评估安徽省重点实验室(国防科技大学) 合肥 230037
  • 2. 河北大学网络空间安全与计算机学院 河北保定 071002
  • 折叠

摘要

Abstract

To address the issues of utility degradation in deep learning models under differential privacy protection and the gap between theoretical and actual privacy protection effectiveness,this paper proposes a deep learning differential privacy protection scheme based on adaptive clipping.The scheme optimizes the process through a four-step mechanism:firstly,gradient adaptive clipping controls the gradient magnitude during training by dynamically adjusting the gradient clipping threshold,thereby enabling the control of the magnitude of noise added subsequently;secondly,group label selection identifies the group with the smallest gradient as the privacy-preserving object,and more accurate privacy loss can be obtained by training this group;thirdly,optimized privacy loss calculation combines the gaussian mechanism based on subsampling to reduce the computational overhead of model privacy loss calculation;finally,optimized gradient adaptive descent realizes the adaptive descent of gradients by adjusting the conditional smoothing parameter,thus improving the usability of the model.Experiments were conducted on the VGG architecture using the MNIST,CIFAR-10,and Medical-MNIST datasets.The results show that the model accuracy rates after training with this scheme are 81.08%,72.30%,and 67.91%respectively,representing improvements of 15.60%,10.60%,and 9.71%compared to the traditional DPSGD,and 0.63%,2.50%,and 4.40%over the widely used Nadam algorithm in recent years.The model training efficiency has been improved by 35.5%and 39.4%,respectively.

关键词

深度学习/差分隐私/梯度自适应裁剪/标签选择/平滑损失函数

Key words

deep learning/differential privacy/gradient adaptive clipping/label selection/smoothed loss function

分类

信息技术与安全科学

引用本文复制引用

程宇航,尚涛,姜亚彤,杜瑞忠..基于自适应裁剪的深度学习差分隐私保护方案[J].信息安全研究,2026,12(6):490-502,13.

基金项目

河北省重点研发计划项目(22340701D) (22340701D)

网络空间安全态势感知与评估安徽省重点实验室开放课题(CSSAE-2023-015) (CSSAE-2023-015)

北京市自然科学基金项目(L251066) (L251066)

信息安全研究

2096-1057

访问量0
|
下载量0
段落导航相关论文