DP-SGD Without Clipping: The Lipschitz Neural Network Way

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Bethune, Louis, Massena, Thomas, Boissin, Thibaut, Prudent, Yannick, Friedrich, Corentin, Mamalet, Franck, Bellet, Aurelien, Serrurier, Mathieu, Vigouroux, David
Format: Preprint
Published: 2023
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866929251957080064
author Bethune, Louis
Massena, Thomas
Boissin, Thibaut
Prudent, Yannick
Friedrich, Corentin
Mamalet, Franck
Bellet, Aurelien
Serrurier, Mathieu
Vigouroux, David
author_facet Bethune, Louis
Massena, Thomas
Boissin, Thibaut
Prudent, Yannick
Friedrich, Corentin
Mamalet, Franck
Bellet, Aurelien
Serrurier, Mathieu
Vigouroux, David
contents State-of-the-art approaches for training Differentially Private (DP) Deep Neural Networks (DNN) face difficulties to estimate tight bounds on the sensitivity of the network's layers, and instead rely on a process of per-sample gradient clipping. This clipping process not only biases the direction of gradients but also proves costly both in memory consumption and in computation. To provide sensitivity bounds and bypass the drawbacks of the clipping process, we propose to rely on Lipschitz constrained networks. Our theoretical analysis reveals an unexplored link between the Lipschitz constant with respect to their input and the one with respect to their parameters. By bounding the Lipschitz constant of each layer with respect to its parameters, we prove that we can train these networks with privacy guarantees. Our analysis not only allows the computation of the aforementioned sensitivities at scale, but also provides guidance on how to maximize the gradient-to-noise ratio for fixed privacy guarantees. The code has been released as a Python package available at https://github.com/Algue-Rythme/lip-dp
format Preprint
id arxiv_https___arxiv_org_abs_2305_16202
institution arXiv
publishDate 2023
record_format arxiv
spellingShingle DP-SGD Without Clipping: The Lipschitz Neural Network Way
Bethune, Louis
Massena, Thomas
Boissin, Thibaut
Prudent, Yannick
Friedrich, Corentin
Mamalet, Franck
Bellet, Aurelien
Serrurier, Mathieu
Vigouroux, David
Machine Learning
Cryptography and Security
State-of-the-art approaches for training Differentially Private (DP) Deep Neural Networks (DNN) face difficulties to estimate tight bounds on the sensitivity of the network's layers, and instead rely on a process of per-sample gradient clipping. This clipping process not only biases the direction of gradients but also proves costly both in memory consumption and in computation. To provide sensitivity bounds and bypass the drawbacks of the clipping process, we propose to rely on Lipschitz constrained networks. Our theoretical analysis reveals an unexplored link between the Lipschitz constant with respect to their input and the one with respect to their parameters. By bounding the Lipschitz constant of each layer with respect to its parameters, we prove that we can train these networks with privacy guarantees. Our analysis not only allows the computation of the aforementioned sensitivities at scale, but also provides guidance on how to maximize the gradient-to-noise ratio for fixed privacy guarantees. The code has been released as a Python package available at https://github.com/Algue-Rythme/lip-dp
title DP-SGD Without Clipping: The Lipschitz Neural Network Way
topic Machine Learning
Cryptography and Security
url https://arxiv.org/abs/2305.16202