Abstract
Generative Adversarial Network (GAN) based on differential privacy (DP) have been widely studied to mitigate the privacy leakage problem of GAN. By injecting noise into model parameters, DP obscures sensitive information. However, the magnitude and manner of noise injection critically affect both privacy guarantees and data utility. To address this trade-off, we propose a localized and adaptively grouped gradient sanitization method, termed LAGS-DPGAN, which enhances both privacy preservation and generation quality. Leveraging the chain rule and the post-processing property of differential privacy, LAGS-DPGAN injects noise exclusively into the gradients of the generator's output layer, thereby reducing the number of sanitized parameters while maintaining the same privacy budget. Furthermore, we design an adaptive group-wise noise injection mechanism, which divides the output layer's derivatives into multiple groups based on their magnitudes and injects different levels of noise into each group. We provide rigorous proof for the privacy guarantee, together with comprehensive empirical evidence demonstrating that our proposed LAGS-DPGAN can generate high-quality synthetic data while keeping high-level privacy protection compared with prior works.
| Original language | English |
|---|---|
| Journal | IEEE Transactions on Big Data |
| DOIs | |
| State | Accepted/In press - 2026 |
| Externally published | Yes |
Keywords
- Differential Privacy
- Gaussian Mechanism
- Generative Adversarial Network
- Rényi Differential Privacy
Fingerprint
Dive into the research topics of 'Differentially Private GAN with Group-wise Purification of Local Gradients'. Together they form a unique fingerprint.Cite this
- APA
- Author
- BIBTEX
- Harvard
- Standard
- RIS
- Vancouver