Gradients Look Alike: Sensitivity is Often Overestimated in DP-SGD

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Thudi, Anvith, Jia, Hengrui, Meehan, Casey, Shumailov, Ilia, Papernot, Nicolas
Format: Preprint
Published: 2023
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866929421519159296
author Thudi, Anvith
Jia, Hengrui
Meehan, Casey
Shumailov, Ilia
Papernot, Nicolas
author_facet Thudi, Anvith
Jia, Hengrui
Meehan, Casey
Shumailov, Ilia
Papernot, Nicolas
contents Differentially private stochastic gradient descent (DP-SGD) is the canonical approach to private deep learning. While the current privacy analysis of DP-SGD is known to be tight in some settings, several empirical results suggest that models trained on common benchmark datasets leak significantly less privacy for many datapoints. Yet, despite past attempts, a rigorous explanation for why this is the case has not been reached. Is it because there exist tighter privacy upper bounds when restricted to these dataset settings, or are our attacks not strong enough for certain datapoints? In this paper, we provide the first per-instance (i.e., ``data-dependent") DP analysis of DP-SGD. Our analysis captures the intuition that points with similar neighbors in the dataset enjoy better data-dependent privacy than outliers. Formally, this is done by modifying the per-step privacy analysis of DP-SGD to introduce a dependence on the distribution of model updates computed from a training dataset. We further develop a new composition theorem to effectively use this new per-step analysis to reason about an entire training run. Put all together, our evaluation shows that this novel DP-SGD analysis allows us to now formally show that DP-SGD leaks significantly less privacy for many datapoints (when trained on common benchmarks) than the current data-independent guarantee. This implies privacy attacks will necessarily fail against many datapoints if the adversary does not have sufficient control over the possible training datasets.
format Preprint
id arxiv_https___arxiv_org_abs_2307_00310
institution arXiv
publishDate 2023
record_format arxiv
spellingShingle Gradients Look Alike: Sensitivity is Often Overestimated in DP-SGD
Thudi, Anvith
Jia, Hengrui
Meehan, Casey
Shumailov, Ilia
Papernot, Nicolas
Machine Learning
Artificial Intelligence
Cryptography and Security
Differentially private stochastic gradient descent (DP-SGD) is the canonical approach to private deep learning. While the current privacy analysis of DP-SGD is known to be tight in some settings, several empirical results suggest that models trained on common benchmark datasets leak significantly less privacy for many datapoints. Yet, despite past attempts, a rigorous explanation for why this is the case has not been reached. Is it because there exist tighter privacy upper bounds when restricted to these dataset settings, or are our attacks not strong enough for certain datapoints? In this paper, we provide the first per-instance (i.e., ``data-dependent") DP analysis of DP-SGD. Our analysis captures the intuition that points with similar neighbors in the dataset enjoy better data-dependent privacy than outliers. Formally, this is done by modifying the per-step privacy analysis of DP-SGD to introduce a dependence on the distribution of model updates computed from a training dataset. We further develop a new composition theorem to effectively use this new per-step analysis to reason about an entire training run. Put all together, our evaluation shows that this novel DP-SGD analysis allows us to now formally show that DP-SGD leaks significantly less privacy for many datapoints (when trained on common benchmarks) than the current data-independent guarantee. This implies privacy attacks will necessarily fail against many datapoints if the adversary does not have sufficient control over the possible training datasets.
title Gradients Look Alike: Sensitivity is Often Overestimated in DP-SGD
topic Machine Learning
Artificial Intelligence
Cryptography and Security
url https://arxiv.org/abs/2307.00310