Privacy of SGD under Gaussian or Heavy-Tailed Noise: Guarantees without Gradient Clipping

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Şimşekli, Umut, Gürbüzbalaban, Mert, Yıldırım, Sinan, Zhu, Lingjiong
Format: Preprint
Published: 2024
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866909606565904384
author Şimşekli, Umut
Gürbüzbalaban, Mert
Yıldırım, Sinan
Zhu, Lingjiong
author_facet Şimşekli, Umut
Gürbüzbalaban, Mert
Yıldırım, Sinan
Zhu, Lingjiong
contents The injection of heavy-tailed noise into the iterates of stochastic gradient descent (SGD) has garnered growing interest in recent years due to its theoretical and empirical benefits for optimization and generalization. However, its implications for privacy preservation remain largely unexplored. Aiming to bridge this gap, we provide differential privacy (DP) guarantees for noisy SGD, when the injected noise follows an $α$-stable distribution, which includes a spectrum of heavy-tailed distributions (with infinite variance) as well as the light-tailed Gaussian distribution. Considering the $(ε, δ)$-DP framework, we show that SGD with heavy-tailed perturbations achieves $(0, O(1/n))$-DP for a broad class of loss functions which can be non-convex, where $n$ is the number of data points. As a remarkable byproduct, contrary to prior work that necessitates bounded sensitivity for the gradients or clipping the iterates, our theory can handle unbounded gradients without clipping, and reveals that under mild assumptions, such a projection step is not actually necessary. Our results suggest that, given other benefits of heavy-tails in optimization, heavy-tailed noising schemes can be a viable alternative to their light-tailed counterparts.
format Preprint
id arxiv_https___arxiv_org_abs_2403_02051
institution arXiv
publishDate 2024
record_format arxiv
spellingShingle Privacy of SGD under Gaussian or Heavy-Tailed Noise: Guarantees without Gradient Clipping
Şimşekli, Umut
Gürbüzbalaban, Mert
Yıldırım, Sinan
Zhu, Lingjiong
Machine Learning
Cryptography and Security
Statistics Theory
The injection of heavy-tailed noise into the iterates of stochastic gradient descent (SGD) has garnered growing interest in recent years due to its theoretical and empirical benefits for optimization and generalization. However, its implications for privacy preservation remain largely unexplored. Aiming to bridge this gap, we provide differential privacy (DP) guarantees for noisy SGD, when the injected noise follows an $α$-stable distribution, which includes a spectrum of heavy-tailed distributions (with infinite variance) as well as the light-tailed Gaussian distribution. Considering the $(ε, δ)$-DP framework, we show that SGD with heavy-tailed perturbations achieves $(0, O(1/n))$-DP for a broad class of loss functions which can be non-convex, where $n$ is the number of data points. As a remarkable byproduct, contrary to prior work that necessitates bounded sensitivity for the gradients or clipping the iterates, our theory can handle unbounded gradients without clipping, and reveals that under mild assumptions, such a projection step is not actually necessary. Our results suggest that, given other benefits of heavy-tails in optimization, heavy-tailed noising schemes can be a viable alternative to their light-tailed counterparts.
title Privacy of SGD under Gaussian or Heavy-Tailed Noise: Guarantees without Gradient Clipping
topic Machine Learning
Cryptography and Security
Statistics Theory
url https://arxiv.org/abs/2403.02051