In plain words: A training trick that adds random noise to each person's data influence, so no single user can be identified, was tested on real ad tasks like predicting clicks and conversions. Unlike earlier work on text and images, it kept predictions useful while protecting privacy.
Abstract
A well-known algorithm in privacy-preserving ML is differentially private stochastic gradient descent (DP-SGD). While this algorithm has been evaluated on text and image data, it has not been previously applied to ads data, which are notorious for their high class imbalance and sparse gradient updates. In this work we apply DP-SGD to several ad modeling tasks including predicting click-through rates, conversion rates, and number of conversion events, and evaluate their privacy-utility trade-off on real-world datasets. Our work is the first to empirically demonstrate that DP-SGD can provide both privacy and utility for ad modeling tasks.
Carson Denison, Badih Ghazi, Pritish Kamath, Ravi Kumar, Pasin Manurangsi, Krishna Giri Narra, Amer Sinha, Avinash V Varadarajan, Chiyuan Zhang
arXiv:2211.11896 · cs.LG, cs.CR · submitted Nov 21, 2022 · updated Oct 4, 2023
abstract · pdf · html · AdKDD 2023, 8 pages, 5 figures