TY - JOUR
T1 - Differentially Private GAN with Group-wise Purification of Local Gradients
AU - Sun, Kai
AU - Chang, Peiju
AU - Hu, Junying
AU - Ji, Lizhen
AU - Zhang, Jiangshe
N1 - Publisher Copyright:
© 2015 IEEE.
PY - 2026
Y1 - 2026
N2 - Generative Adversarial Network (GAN) based on differential privacy (DP) have been widely studied to mitigate the privacy leakage problem of GAN. By injecting noise into model parameters, DP obscures sensitive information. However, the magnitude and manner of noise injection critically affect both privacy guarantees and data utility. To address this trade-off, we propose a localized and adaptively grouped gradient sanitization method, termed LAGS-DPGAN, which enhances both privacy preservation and generation quality. Leveraging the chain rule and the post-processing property of differential privacy, LAGS-DPGAN injects noise exclusively into the gradients of the generator's output layer, thereby reducing the number of sanitized parameters while maintaining the same privacy budget. Furthermore, we design an adaptive group-wise noise injection mechanism, which divides the output layer's derivatives into multiple groups based on their magnitudes and injects different levels of noise into each group. We provide rigorous proof for the privacy guarantee, together with comprehensive empirical evidence demonstrating that our proposed LAGS-DPGAN can generate high-quality synthetic data while keeping high-level privacy protection compared with prior works.
AB - Generative Adversarial Network (GAN) based on differential privacy (DP) have been widely studied to mitigate the privacy leakage problem of GAN. By injecting noise into model parameters, DP obscures sensitive information. However, the magnitude and manner of noise injection critically affect both privacy guarantees and data utility. To address this trade-off, we propose a localized and adaptively grouped gradient sanitization method, termed LAGS-DPGAN, which enhances both privacy preservation and generation quality. Leveraging the chain rule and the post-processing property of differential privacy, LAGS-DPGAN injects noise exclusively into the gradients of the generator's output layer, thereby reducing the number of sanitized parameters while maintaining the same privacy budget. Furthermore, we design an adaptive group-wise noise injection mechanism, which divides the output layer's derivatives into multiple groups based on their magnitudes and injects different levels of noise into each group. We provide rigorous proof for the privacy guarantee, together with comprehensive empirical evidence demonstrating that our proposed LAGS-DPGAN can generate high-quality synthetic data while keeping high-level privacy protection compared with prior works.
KW - Differential Privacy
KW - Gaussian Mechanism
KW - Generative Adversarial Network
KW - Rényi Differential Privacy
UR - https://www.scopus.com/pages/publications/105045524320
U2 - 10.1109/TBDATA.2026.3712222
DO - 10.1109/TBDATA.2026.3712222
M3 - 文章
AN - SCOPUS:105045524320
SN - 2332-7790
JO - IEEE Transactions on Big Data
JF - IEEE Transactions on Big Data
ER -