Page 761

Ming Ding | Information Security and

Privacy Group | Data61, CSIROVisual experiments

•More concrete results on the utility -privacy trade -off?

•Train a classifier using the synthetic images and then test it on the

original images

•Multi -Layer Perceptron ( MLP) network with one hidden layer containing 128

hidden units.

•ReLU ; softmax of 10 classes; cross -entropy loss function; 128epochs of

training

ε=5