NeurIPS 2019poster57 citations

Generalization in Generative Adversarial Networks: A Novel Perspective from Privacy Protection

Bingzhe Wu, Shiwan Zhao, Chaochao Chen, Haoyang Xu, Li Wang, Xiaolu Zhang, Guangyu Sun, Jun Zhou

Abstract

In this paper, we aim to understand the generalization properties of generative adversarial networks (GANs) from a new perspective of privacy protection. Theoretically, we prove that a differentially private learning algorithm used for training the GAN does not overfit to a certain degree, i.e., the generalization gap can be bounded. Moreover, some recent works, such as the Bayesian GAN, can be re-interpreted based on our theoretical insight from privacy protection. Quantitatively, to evaluate the information leakage of well-trained GAN models, we perform various membership attacks on these models. The results show that previous Lipschitz regularization techniques are effective in not only reducing the generalization gap but also alleviating the information leakage of the training dataset.

BibTeX
@inproceedings{NEURIPS2019_47d1e990,
 author = {Wu, Bingzhe and Zhao, Shiwan and Chen, Chaochao and Xu, Haoyang and Wang, Li and Zhang, Xiaolu and Sun, Guangyu and Zhou, Jun},
 booktitle = {Advances in Neural Information Processing Systems},
 editor = {H. Wallach and H. Larochelle and A. Beygelzimer and F. d\textquotesingle Alch\'{e}-Buc and E. Fox and R. Garnett},
 pages = {},
 publisher = {Curran Associates, Inc.},
 title = {Generalization in Generative Adversarial Networks: A Novel Perspective from Privacy Protection},
 url = {https://proceedings.neurips.cc/paper_files/paper/2019/file/47d1e990583c9c67424d369f3414728e-Paper.pdf},
 volume = {32},
 year = {2019}
}
Generalization in Generative Adversarial Networks: A Novel Perspective from Privacy Protection · NeurIPS 2019