PCDP-SGD: Improving the Convergence of Differentially Private SGD via Projection in Advance

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Sha, Haichao, Liu, Ruixuan, Liu, Yixuan, Chen, Hong
Format: Preprint
Published: 2023
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866915238632226816
author Sha, Haichao
Liu, Ruixuan
Liu, Yixuan
Chen, Hong
author_facet Sha, Haichao
Liu, Ruixuan
Liu, Yixuan
Chen, Hong
contents The paradigm of Differentially Private SGD~(DP-SGD) can provide a theoretical guarantee for training data in both centralized and federated settings. However, the utility degradation caused by DP-SGD limits its wide application in high-stakes tasks, such as medical image diagnosis. In addition to the necessary perturbation, the convergence issue is attributed to the information loss on the gradient clipping. In this work, we propose a general framework PCDP-SGD, which aims to compress redundant gradient norms and preserve more crucial top gradient components via projection operation before gradient clipping. Additionally, we extend PCDP-SGD as a fundamental component in differential privacy federated learning~(DPFL) for mitigating the data heterogeneous challenge and achieving efficient communication. We prove that pre-projection enhances the convergence of DP-SGD by reducing the dependence of clipping error and bias to a fraction of the top gradient eigenspace, and in theory, limits cross-client variance to improve the convergence under heterogeneous federation. Experimental results demonstrate that PCDP-SGD achieves higher accuracy compared with state-of-the-art DP-SGD variants in computer vision tasks. Moreover, PCDP-SGD outperforms current federated learning frameworks when DP is guaranteed on local training sets.
format Preprint
id arxiv_https___arxiv_org_abs_2312_03792
institution arXiv
publishDate 2023
record_format arxiv
spellingShingle PCDP-SGD: Improving the Convergence of Differentially Private SGD via Projection in Advance
Sha, Haichao
Liu, Ruixuan
Liu, Yixuan
Chen, Hong
Cryptography and Security
Machine Learning
The paradigm of Differentially Private SGD~(DP-SGD) can provide a theoretical guarantee for training data in both centralized and federated settings. However, the utility degradation caused by DP-SGD limits its wide application in high-stakes tasks, such as medical image diagnosis. In addition to the necessary perturbation, the convergence issue is attributed to the information loss on the gradient clipping. In this work, we propose a general framework PCDP-SGD, which aims to compress redundant gradient norms and preserve more crucial top gradient components via projection operation before gradient clipping. Additionally, we extend PCDP-SGD as a fundamental component in differential privacy federated learning~(DPFL) for mitigating the data heterogeneous challenge and achieving efficient communication. We prove that pre-projection enhances the convergence of DP-SGD by reducing the dependence of clipping error and bias to a fraction of the top gradient eigenspace, and in theory, limits cross-client variance to improve the convergence under heterogeneous federation. Experimental results demonstrate that PCDP-SGD achieves higher accuracy compared with state-of-the-art DP-SGD variants in computer vision tasks. Moreover, PCDP-SGD outperforms current federated learning frameworks when DP is guaranteed on local training sets.
title PCDP-SGD: Improving the Convergence of Differentially Private SGD via Projection in Advance
topic Cryptography and Security
Machine Learning
url https://arxiv.org/abs/2312.03792