On the Benefits of Public Representations for Private Transfer Learning under Distribution Shift

Fuente: arXiv
Gespeichert in:
Bibliographische Detailangaben
Hauptverfasser: Thaker, Pratiksha, Setlur, Amrith, Wu, Zhiwei Steven, Smith, Virginia
Format: Preprint
Veröffentlicht: 2023
Schlagworte:
Online-Zugang:
Tags: Tag hinzufügen
Keine Tags, Fügen Sie den ersten Tag hinzu!
_version_ 1866916940104073216
author Thaker, Pratiksha
Setlur, Amrith
Wu, Zhiwei Steven
Smith, Virginia
author_facet Thaker, Pratiksha
Setlur, Amrith
Wu, Zhiwei Steven
Smith, Virginia
contents Public pretraining is a promising approach to improve differentially private model training. However, recent work has noted that many positive research results studying this paradigm only consider in-distribution tasks, and may not apply to settings where there is distribution shift between the pretraining and finetuning data -- a scenario that is likely when finetuning private tasks due to the sensitive nature of the data. In this work, we show empirically across three tasks that even in settings with large distribution shift, where both zero-shot performance from public data and training from scratch with private data give unusably weak results, public features can in fact improve private training accuracy by up to 67\% over private training from scratch. We provide a theoretical explanation for this phenomenon, showing that if the public and private data share a low-dimensional representation, public representations can improve the sample complexity of private training even if it is impossible to learn the private task from the public data alone. Altogether, our results provide evidence that public data can indeed make private training practical in realistic settings of extreme distribution shift.
format Preprint
id arxiv_https___arxiv_org_abs_2312_15551
institution arXiv
publishDate 2023
record_format arxiv
spellingShingle On the Benefits of Public Representations for Private Transfer Learning under Distribution Shift
Thaker, Pratiksha
Setlur, Amrith
Wu, Zhiwei Steven
Smith, Virginia
Machine Learning
Cryptography and Security
Public pretraining is a promising approach to improve differentially private model training. However, recent work has noted that many positive research results studying this paradigm only consider in-distribution tasks, and may not apply to settings where there is distribution shift between the pretraining and finetuning data -- a scenario that is likely when finetuning private tasks due to the sensitive nature of the data. In this work, we show empirically across three tasks that even in settings with large distribution shift, where both zero-shot performance from public data and training from scratch with private data give unusably weak results, public features can in fact improve private training accuracy by up to 67\% over private training from scratch. We provide a theoretical explanation for this phenomenon, showing that if the public and private data share a low-dimensional representation, public representations can improve the sample complexity of private training even if it is impossible to learn the private task from the public data alone. Altogether, our results provide evidence that public data can indeed make private training practical in realistic settings of extreme distribution shift.
title On the Benefits of Public Representations for Private Transfer Learning under Distribution Shift
topic Machine Learning
Cryptography and Security
url https://arxiv.org/abs/2312.15551