IP Library Granted Patent US 12,417,314
Granted Patent B2
US 12,417,314 · App. 18/195,746 · Granted Sep 16, 2025

Task-aware privacy preservation for multi-dimensional data

Inventors: Ao Tang (Ithaca, NY); Jiangnan Cheng (Ithaca, NY); Sandeep Chinchali (Austin, TX)
Assignees: Cornell University; Board of Regents, The University of Texas System
G06F21/6254G06N3/0455G06N3/084
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,417,314
App. No.
18/195,746
Granted
Sep 16, 2025
Kind
B2
Abstract

A method performed by at least one processing device in an illustrative embodiment comprises applying an input data sample to an encoder of an encoder-decoder network to generate a corresponding latent representation, combining the latent representation from the encoder with noise, applying the combined latent representation and noise to a decoder of the encoder-decoder network to generate an estimated data sample, and outputting the estimated data sample. Respective sets of parameters of the encoder and decoder of the encoder-decoder network are configured based at least in part on an iterative optimization process utilizing a task loss determined from a task function that relates the input data sample to a task output. A given iteration of the iterative optimization process illustratively generates an estimated task output from the estimated data sample, determines a loss measure using the estimated task output, and adjusts one or more parameters using the loss measure.

Claims (55)

1. A method comprising:

applying an input data sample to an encoder of an encoder-decoder network to generate a corresponding latent representation;

combining the latent representation from the encoder with noise;

applying the combined latent representation and noise to a decoder of the encoder-decoder network to generate an estimated data sample; and

outputting the estimated data sample;

wherein respective sets of parameters of the encoder and decoder of the encoder-decoder network are configured based at least in part on an iterative optimization process utilizing a task loss determined from a task function that relates the input data sample to a task output; and

wherein the method is performed by at least one processing device comprising a processor coupled to a memory.

2. The method of claim 1 wherein a given iteration of the iterative optimization process comprises:

applying an instance of the estimated data sample to the task function to generate an estimated task output;

determining a loss measure based at least in part on the estimated task output; and

adjusting at least one of the respective sets of parameters of the encoder and decoder based at least in part on the loss measure.

3. The method of claim 2 wherein adjusting at least one of the respective sets of parameters of the encoder and decoder based at least in part on the loss measure comprises:

updating at least one parameter in the set of parameters of the encoder utilizing a first negative gradient of the loss measure; and

updating at least one parameter in the set of parameters of the decoder utilizing a second negative gradient of the loss measure, the second negative gradient of the loss measure being different than the first negative gradient of the loss measure.

4. The method of claim 3 wherein the first negative gradient has an associated regularization term and the second negative gradient does not have an associated regularization term.

5. The method of claim 2 wherein the given iteration of the iterative optimization process further comprises at least one of:

computing a sensitivity value for the encoder; and

selecting a noise vector for combining with an instance of the latent representation.

6. The method of claim 1 wherein at least one of the encoder, the decoder and the task function is implemented as a linear function.

7. The method of claim 1 wherein at least one of the encoder, the decoder and the task function is implemented as a neural network.

8. The method of claim 1 wherein combining the latent representation from the encoder with noise comprises combining the latent representation with a noise vector selected from a specified noise domain.

9. The method of claim 1 wherein the encoder is implemented at least in part on a first processing device, and the decoder is implemented at least in part on a second processing device that communicates with the first processing device over at least one network.

10. The method of claim 1 wherein outputting the estimated data sample comprises providing the estimated data sample from the encoder-decoder network to a machine learning system for further processing with one or more other estimated data samples generated from one or more other input data samples.

11. The method of claim 1 wherein the estimated data sample provides local differential privacy relative to the input data sample within a specified privacy budget.

12. The method of claim 1 wherein the task function relating the input data sample to the task output is determined in an offline training phase.

13. The method of claim 1 wherein the task function is represented at least in part in the form of a task matrix.

14. The method of claim 1 wherein the encoder-decoder network comprises an encoder-decoder neural network.

15. A system comprising:

at least one processing device comprising a processor and a memory;

the at least one processing device being configured:

to apply an input data sample to an encoder of an encoder-decoder network to generate a corresponding latent representation;

to combine the latent representation from the encoder with noise;

to apply the combined latent representation and noise to a decoder of the encoder-decoder network to generate an estimated data sample; and

to output the estimated data sample;

wherein respective sets of parameters of the encoder and decoder of the encoder-decoder network are configured based at least in part on an iterative optimization process utilizing a task loss determined from a task function that relates the input data sample to a task output.

16. The system of claim 15 wherein a given iteration of the iterative optimization process comprises:

applying an instance of the estimated data sample to the task function to generate an estimated task output;

determining a loss measure based at least in part on the estimated task output; and

adjusting at least one of the respective sets of parameters of the encoder and decoder based at least in part on the loss measure.

17. The system of claim 16 wherein adjusting at least one of the respective sets of parameters of the encoder and decoder based at least in part on the loss measure comprises:

updating at least one parameter in the set of parameters of the encoder utilizing a first negative gradient of the loss measure; and

updating at least one parameter in the set of parameters of the decoder utilizing a second negative gradient of the loss measure, the second negative gradient of the loss measure being different than the first negative gradient of the loss measure.

18. A computer program product comprising a non-transitory processor-readable storage medium having stored therein program code of one or more software programs, wherein the program code, when executed by at least one processing device comprising a processor coupled to a memory, causes the at least one processing device:

to apply an input data sample to an encoder of an encoder-decoder network to generate a corresponding latent representation;

to combine the latent representation from the encoder with noise;

to apply the combined latent representation and noise to a decoder of the encoder-decoder network to generate an estimated data sample; and

to output the estimated data sample;

wherein respective sets of parameters of the encoder and decoder of the encoder-decoder network are configured based at least in part on an iterative optimization process utilizing a task loss determined from a task function that relates the input data sample to a task output.

19. The computer program product of claim 18 wherein a given iteration of the iterative optimization process comprises:

applying an instance of the estimated data sample to the task function to generate an estimated task output;

determining a loss measure based at least in part on the estimated task output; and

adjusting at least one of the respective sets of parameters of the encoder and decoder based at least in part on the loss measure.

20. The computer program product of claim 19 wherein adjusting at least one of the respective sets of parameters of the encoder and decoder based at least in part on the loss measure comprises:

updating at least one parameter in the set of parameters of the encoder utilizing a first negative gradient of the loss measure; and

updating at least one parameter in the set of parameters of the decoder utilizing a second negative gradient of the loss measure, the second negative gradient of the loss measure being different than the first negative gradient of the loss measure.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 6, 2024
From: CHINCHALI, SANDEEP
To: BOARD OF REGENTS, THE UNIVERSITY OF TEXAS SYSTEM
Reel/Frame 066391/0839 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 10, 2023
From: TANG, AO; CHENG, JIANGNAN
To: CORNELL UNIVERSITY
Reel/Frame 063600/0150 →
Continuity (2)
Provisional Application 63340554 · May 11, 2022
Related Publication 20230367906A1 · Nov 16, 2023
References Cited (80)
US 11023594B2 · Nissim Kobliner et al. · 2021 [cited by applicant]
US 11232478B2 · Brown et al. · 2022 [cited by applicant]
US 20160071170A1 · Massoulie et al. · 2016 [cited by applicant]
US 20190370334A1 · Bhowmick · 2019 [cited by examiner]
US 20210365580A1 · Klucar, Jr. et al. · 2021 [cited by applicant]
US 20210374605A1 · Qian et al. · 2021 [cited by applicant]
US 20230299788A1 · Agustsson · 2023 [cited by examiner]
WO 2013120780A2 · 2013 [cited by applicant]
WO 2020248149A1 · 2020 [cited by applicant]
WO 2020248150A1 · 2020 [cited by applicant]
A. Smith et al., “Differentially Private Feature Selection via Stability Arguments, and the Robustness of the Lasso,” Journal of Machine Learning Research, vol. 30, Jan. 2013, 30 pages. [cited by applicant]
D. Wang et al., “Empirical Risk Minimization in the Non-interactive Local Model of Differential Privacy,” Journal of Machine Learning Research, vol. 21, Sep. 2020, 39 pages. [cited by applicant]
J. Wang et al., “Not Just Privacy: Improving Performance of Private Deep Learning in Mobile Cloud,” Proceedings of the 24th ACM SIGKDD International Conference on Knowledge Discovery & Data Mining, Jul. 2018, pp. 2407-2… [cited by applicant]
N. Wang et al., “Collecting and Analyzing Multidimensional Data with Local Differential Privacy,” arXiv:1907.00782v1, Jun. 28, 2019, 12 pages. [cited by applicant]
Y.-X. Wang et al., “Subsampled Renyi Differential Privacy and Analytical Moments Accountant,” Proceedings of the 22nd International Conference on Artificial Intelligence and Statistics (AIStats), Apr. 2019, 10 pages. [cited by applicant]
X. Xiao et al., “Differential Privacy via Wavelet Transforms,” arXiv:0909.5530v1, Sep. 30, 2009, 15 pages. [cited by applicant]
J. Zhao et al., “Achieving Differential Privacy of Data Disclosure in the Smart Grid,” IEEE Conference on Computer Communications, Apr. 2014, 9 pages. [cited by applicant]
Y, Zhou et al., “VoxelNet: End-to-End Learning for Point Cloud Based 3D Object Detection,” IEEE/CVF Conference on Computer Vision and Pattern Recognition (CVPR), Jun. 2018, pp. 4490-4499. [cited by applicant]
J. C. Duchi et al., “Local Privacy and Statistical Minimax Rates,” IEEE 54th Annual Symposium on Foundations of Computer Science, Oct. 2013, pp. 429-438. [cited by applicant]
F. McSherry et al., “Mechanism Design via Differential Privacy,” 48th Annual IEEE Symposium on Foundations of Computer Science, Oct. 2007, pp. 94-103. [cited by applicant]
A. Ruhe, “Perturbation Bounds for Means of Eigenvalues and Invariant Subspaces,” BIT Numerical Mathematics, vol. 10, Sep. 1970, pp. 343-354. [cited by applicant]
T. Wang et al., “End-to-End Text Recognition with Convolutional Neural Networks,” 21st International Conference on Pattern Recognition, Nov. 2012, pp. 3304-3308. [cited by applicant]
I.-C. Yeh et al., “Building Real Estate Valuation Models with Comparative Approach through Case-based Reasoning,” Applied Soft Computing, vol. 65, Apr. 2018, pp. 260-271. [cited by applicant]
Y. Nie et al., “A Utility-Optimized Framework for Personalized Private Histogram Estimation,” IEEE Transactions on Knowledge and Data Engineering, vol. 31, No. 4, Apr. 2019, pp. 656-669. [cited by applicant]
J. Casey, “A Treatise of the Analytical Geometry of the Point, Line, Circle, and Conic Sections,” Dublin University Press Series, 1893, Accessed from University of Michigan Historical Math Collection,https://quod.lib.um… [cited by applicant]
G. H. Dunteman, “Principal Components Analysis,” Quantitative Application in the Social Sciences, vol. 69, 1989, Extract Only, 14 pages. [cited by applicant]
C. Dwork et al., The Algorithmic Foundations of Differential Privacy, Foundations and Trends in Theoretical Computer Science, 2013, Full text available at: http://dx.doi.org/10.1561/0400000042, Extract Only, 26 pages. [cited by applicant]
Y. Zhang et al., “Understanding Bag-of-Words Model: A Statistical Framework,” International Journal of Machine Learning and Cybernetics, vol. 1, Aug. 28, 2010, 16 pages. [cited by applicant]
L. Wasserman et al., “A Statistical Framework for Differential Privacy,” arXiv:0811.2501v2, Oct. 2, 2009, 42 pages. [cited by applicant]
J. Von Neumann, “Some Matrix Inequalities and Metrization of Matrix Space,” Tomsk. Univ. Rev. 1, 286-300 (1937). Reprinted in Collected Works, vol. 4, Pergamon Press, New York, 1962. Citation Only. [cited by applicant]
W. N. Street et al., “Nuclear Feature Extraction for Breast Tumor Diagnosis,” Center for Parallel Optimization, Computer Sciences Technical Report #1131, Dec. 28, 1992, 10 pages. [cited by applicant]
J. Cheng et al., “Task-aware Privacy Preservation for Multi-dimensional Data,” arXiv:2110.02329v3, Aug. 8, 2022, 17 pages. [cited by applicant]
J. Cheng et al., “Task-aware Privacy Preservation for Multi-dimensional Data,” arXiv:2110.02329v1, Oct. 5, 2021, 20 pages. [cited by applicant]
J. Cheng et al., “Task-aware Privacy Preservation for Multi-dimensional Data,” Proceedings of the 39th International Conference on Machine Learning, Jun. 28, 2022, 17 pages. [cited by applicant]
Q. Chen et al., “Differentially Private Data Generative Models,” sevarXiv:1812.02274v1, Dec. 6, 2018, 18 pages. [cited by applicant]
J. Acharya et al., “Context-Aware Local Differential Privacy,” arXiv:1911.00038v2, Jul. 27, 2020, 24 pages. [cited by applicant]
J. Acharya et al., “Context-Aware Local Differential Privacy,” Proceedings of the 37th International Conference on Machine Learning, Jul. 2020, 11 pages. [cited by applicant]
M. Abadi et al., “Deep Learning with Differential Privacy,” arXiv:1607.00133v2, Oct. 24, 2016, 14 pages. [cited by applicant]
M. S. Alvim et al., “Differential Privacy: On the Trade-off between Utility and Information Leakage,” arXiv:1103.5188v3, Aug. 25, 2011, 30 pages. [cited by applicant]
B. Amos et al., “Differentiable MPC for End-to-end Planning and Control,” Advances in Neural Information Processing Systems, vol. 31, Dec. 2018, 12 pages. [cited by applicant]
P. C. M. Arachchige et al., “Local Differential Privacy for Deep Learning,” arXiv:1908.02997v3l, Nov. 9, 2019, 16 pages. [cited by applicant]
Z. Bu et al., “Deep Learning with Gaussian Differential Privacy,” Harvard Data Science Review, Sep. 30, 2020, 31 pages. [cited by applicant]
J.-W. Chen et al., “Perceptual Indistinguishability-Net (PI-Net): Facial Image Obfuscation with Manipulable Semantics,” IEEE/CVF Conference on Computer Vision and Pattern Recognition (CVPR), Jun. 2021, pp. 6474-6483. [cited by applicant]
J. Cheng et al., “Data Sharing and Compression for Cooperative Networked Control,” Advances in Neural Information Processing Systems, Sep. 29, 2021, 12 pages. [cited by applicant]
J. Cortes et al., “Differential Privacy in Control and Network Systems,” IEEE 55th Conference on Decision and Control, Dec. 2016, pp. 4252-4272. [cited by applicant]
F. K. Dankar et al., “Practicing Differential Privacy in Health Care: A Review,” Transactions on Data Privacy, vol. 6, No. 1, Apr. 1, 2013, pp. 35-67. [cited by applicant]
Apple Differential Privacy Team, “Learning with Privacy at Scale,” https://machinelearning.apple.com/research/learning-with-privacy-at-scale, Dec. 2017, 25 pages. [cited by applicant]
B. Ding et al., “Collecting Telemetry Data Privately,” 31st Conference on Neural Information Processing Systems, Dec. 2017, 10 pages. [cited by applicant]
P. L. Donti et al., “Task-based End-to-end Model Learning in Stochastic Optimization,” 31st Conference on Neural Information Processing Systems, Dec. 2017, 11 pages. [cited by applicant]
D. Dua et al., “UCI Machine Learning Repository,” http://archive.ics.uci.edu/ml, University of California, School of Information and Computer Science, Accessed May 1, 2023, 2 pages. [cited by applicant]
C. Dwork et al., “Calibrating Noise to Sensitivity in Private Data Analysis,” Theory of Cryptography, Lecture Notes in Computer Science, vol. 3876, Mar. 2006, 20 pages. [cited by applicant]
U. Erlingsson et al., “RAPPOR: Randomized Aggregatable Privacy-Preserving Ordinal Response,” Proceedings of the 2014 ACM SIGSAC Conference on Computer and Communications Security, Nov. 2014, pp. 1054-1067. [cited by applicant]
A. Friedman et al., “Data Mining with Differential Privacy,” Proceedings of the 16th ACM SIGKDD International Conference on Knowledge Discovery and Data Mining, Jul. 2010, 10 pages. [cited by applicant]
Q. Geng et al., “The Optimal Noise-Adding Mechanism in Differential Privacy,” IEEE Transactions on Information Theory, vol. 62, No. 2, Feb. 2016, 28 pages. [cited by applicant]
L. Gondara et al. “Differentially Private Small Dataset Release Using Random Projections,” Proceedings of the 36th Conference on Uncertainty in Artificial Intelligence (UAI), PMLR vol. 124, Aug. 2020, 10 pages. [cited by applicant]
M. Hardt et al., “On the Geometry of Differential Privacy,” arXiv:0907.3754v3, Nov. 9, 2009, 27 pages. [cited by applicant]
M. U. Hassan, “Differential Privacy Techniques for Cyber Physical Systems: A Survey,” arXiv:1812.02282v3, Sep. 27, 2019, 46 pages. [cited by applicant]
G. Hebrail et al., “Individual Household Electric Power Consumption Data Set,” https://archive.ics.uci.edu/ml/datasets/individual+household+electric+power+consumption, UCI Machine Learning Repository, University of Cali… [cited by applicant]
M. Joseph et al., “The Role of Interactivity in Local Differential Privacy,” arXiv:1904.03564v2, Nov. 8, 2019, 36 pages. [cited by applicant]
P. Kairouz et al., “Extremal Mechanisms for Local Differential Privacy,” Journal of Machine Learning Research, vol. 17, Apr. 2016, 51 pages. [cited by applicant]
S. P. Kasiviswanathan et al., “What Can We Learn Privately?” arXiv:0803.0924v3, Feb. 19, 2010, 35 pages. [cited by applicant]
K. Kenthapadi et al., “Privacy via the Johnson-Lindenstrauss Transform,” arXiv:1204.2606v1, Apr. 12, 2012, 24 pages. [cited by applicant]
Y. Lecun et al., “Gradient-Based Learning Applied to Document Recognition,” Proceedings of the IEEE, Nov. 1998, 46 pages. [cited by applicant]
C. Li et al., “The Matrix Mechanism: Optimizing Linear Counting Queries Under Differential Privacy,” The VLDB Journal, Aug. 18, 2015, 25 pages. [cited by applicant]
C. Liu et al., “Dependence Makes You Vulnerable: Differential Privacy Under Dependent Tuples,” Network and Distributed System Security Symposium, Jan. 2016, 15 pages. [cited by applicant]
R. Liu et al., “FedSel: Federated SGD under Local Differential Privacy with Top-k Dimension Selection,” International Conference on Database Systems for Advanced Applications, Mar. 24, 2020, 18 pages. [cited by applicant]
A. Makhdoumi et al., “Privacy-Utility Tradeoff under Statistical Uncertainty,” Fifty-first Annual Allerton Conference, Oct. 2013, 8 pages. [cited by applicant]
A. Mansbridge et al., “Representation Learning for High-Dimensional Data Collection under Local Differential Privacy,” arXiv:2010.12464v3, May 14, 2022, 24 pages. [cited by applicant]
B. McMahan et al., “Private Online Prefix Sums via Optimal Matrix Factorizations,” arXiv:2202.08312v1, Feb. 16, 2022, 23 pages. [cited by applicant]
H. B. McMahan et al., “A General Approach to Adding Differential Privacy to Iterative Training Procedures,” arXiv:1812.06210v2, Mar. 4, 2019, 8 pages. [cited by applicant]
F. Mireshghallah et al., “A Principled Approach to Learning Stochastic Representations for Privacy in Deep Neural Inference,” arXiv:2003.12154v1, Mar. 26, 2020, 15 pages. [cited by applicant]
U. Muller et al., “Off-Road Obstacle Avoidance through End-to-End Learning,” Proceedings of the 18th International Conference on Neural Information Processing Systems, Dec. 2005, 8 pages. [cited by applicant]
T. Murakami et al, “Utility-Optimized Local Differential Privacy Mechanisms for Distribution Estimation,” Proceedings of the 28th USENIX Security Symposium, Aug. 2019, pp. 1877-1894. [cited by applicant]
M. Nakanoya et al., “Co-Design of Communication and Machine Inference for Cloud Robotics,” Robotics: Science and Systems, Jul. 2021, 10 pages. [cited by applicant]
N. Papernot et al., “Semi-supervised Knowledge Transfer for Deep Learning from Private Training Data,” arXiv:1610.05755v4, Mar. 3, 2017, 16 pages. [cited by applicant]
N. Phan et al., “Differential Privacy Preservation for Deep Auto-Encoders: An Application of Human Behavior Prediction,” Proceedings of the Thirtieth AAAI Conference on Artificial Intelligence, Feb. 2016, pp. 1309-1316. [cited by applicant]
N. Phan et al., “Adaptive Laplace Mechanism: Differential Privacy Preservation in Deep Learning,” arXiv:1709.05750v2, Apr. 23, 2018, 13 pages. [cited by applicant]
N. Phan et al., “Heterogeneous Gaussian Mechanism: Preserving Differential Privacy in Deep Learning with Provable Robustness,” arXiv:1906.01444v1, Jun. 2, 2019, 10 pages. [cited by applicant]
R. Shokri et al., “Privacy-Preserving Deep Learning,” Proceedings of the 22nd ACM SIGSAC Conference on Computer and Communications Security, Oct. 2015, 12 pages. [cited by applicant]
S. Song et al., “Stochastic Gradient Descent with Differentially Private Updates,” IEEE Global Conference on Signal and Information Processing (GlobalSIP), Dec. 2013, pp. 245-248. [cited by applicant]