DP-SGD with weight clipping

Fuente: arXiv
Guardado en:
Detalles Bibliográficos
Autores principales: Barczewski, Antoine, Ramon, Jan
Formato: Preprint
Publicado: 2023
Materias:
Acceso en línea:
Etiquetas: Agregar Etiqueta
Sin Etiquetas, Sea el primero en etiquetar este registro!
_version_ 1866913685395472384
author Barczewski, Antoine
Ramon, Jan
author_facet Barczewski, Antoine
Ramon, Jan
contents Recently, due to the popularity of deep neural networks and other methods whose training typically relies on the optimization of an objective function, and due to concerns for data privacy, there is a lot of interest in differentially private gradient descent methods. To achieve differential privacy guarantees with a minimum amount of noise, it is important to be able to bound precisely the sensitivity of the information which the participants will observe. In this study, we present a novel approach that mitigates the bias arising from traditional gradient clipping. By leveraging a public upper bound of the Lipschitz value of the current model and its current location within the search domain, we can achieve refined noise level adjustments. We present a new algorithm with improved differential privacy guarantees and a systematic empirical evaluation, showing that our new approach outperforms existing approaches also in practice.
format Preprint
id arxiv_https___arxiv_org_abs_2310_18001
institution arXiv
publishDate 2023
record_format arxiv
spellingShingle DP-SGD with weight clipping
Barczewski, Antoine
Ramon, Jan
Machine Learning
Cryptography and Security
Recently, due to the popularity of deep neural networks and other methods whose training typically relies on the optimization of an objective function, and due to concerns for data privacy, there is a lot of interest in differentially private gradient descent methods. To achieve differential privacy guarantees with a minimum amount of noise, it is important to be able to bound precisely the sensitivity of the information which the participants will observe. In this study, we present a novel approach that mitigates the bias arising from traditional gradient clipping. By leveraging a public upper bound of the Lipschitz value of the current model and its current location within the search domain, we can achieve refined noise level adjustments. We present a new algorithm with improved differential privacy guarantees and a systematic empirical evaluation, showing that our new approach outperforms existing approaches also in practice.
title DP-SGD with weight clipping
topic Machine Learning
Cryptography and Security
url https://arxiv.org/abs/2310.18001