Related: do GANs work well as a data augmentation technique and can their exact contribution to how much a model could potentially be improved be quantified.
EDIT: Added some clarifications
Encrypting the data secures the data loading part but it's not like your model didn't learn anything.
There might be encryption schemes which make learning such a "language" harder for an rnn, but it does not necessarily mean these methods are harder to break. So it might be possible to find/design an encryption method which is easy to learn (map x to y), but hard to break. I don't know much about encryption though, so I might be wrong.
Proof: You can easily train an RNN to return the n-th letter of its input and ignore everything else. Take that function to be f_n. Then g_n is the function that takes the encrypted input and returns the n-th letter, encrypted. If the encryption scheme is learnable in the above sense, then you can also train an RNN to perform that task. You can use multiple of those RNNs to extract an encryption of each individual letter in the input, which is equivalent to having the input encrypted with a substitution cipher. Substitution ciphers are so easy to break with frequency analysis that people have been doing it by hand for more than a thousand years.
Conversely, if you have a secure encryption scheme, then all statistical regularities in the input should be obfuscated so that they cannot be exploited by an RNN.
I can think of two ways that procedure can fail:
1. If some aspects of the private data aren't represented in the public dataset (e.g. codewords in classified documents), the final classifier won't recognize them. On the other hand, I'm not sure whether there's an actual use case for making a classifier public that's required to work on data that can only be obtained from a non-public source.
2. If some aspects of your labels are sensitive (e.g. which political opinions you agree with) then labeling the public dataset retains that information. In that case, you'd likely need to apply techniques similar to those studied for removing racial or gender bias from a model.
Using complex NN models (let's say, LSTM) doesn't give much better results than simple neurons with deep layers. Seems that the model extraction (how to represent some author style) is the only point that matters, and it then easily forged (i.e., not hard to reproduce the desired style on purpose).
I'm trying to use GAN as a mean of desconstruction, of removal of the ease patterns to see if some NN can use subtle characteristics to identify the author.
IIUC, that's something that's been looked at in the ML Fairness literature. See this paper for example: http://www.aies-conference.com/wp-content/papers/main/AIES_2...
I'll answer what I think you're asking and you can tell me if I got it wrong:
There's been a lot of effort spent on coming up with different loss functions for GANs, but https://arxiv.org/abs/1711.10337 shows that, according to the metrics in problem 5, they don't really improve results compared to the original GAN loss function.
There's something called a Wasserstein GAN https://arxiv.org/abs/1701.07875 that you may have heard about, but IMO the useful thing to take away from that paper is their 'gradient penalty' technique and not the new loss function.