Scaling up the Banded Matrix Factorization Mechanism for Differentially Private ML

Fuente: arXiv
Saved in:
Bibliographic Details
Main Author: McKenna, Ryan
Format: Preprint
Published: 2024
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866909606609944576
author McKenna, Ryan
author_facet McKenna, Ryan
contents Correlated noise mechanisms such as DP Matrix Factorization (DP-MF) have proven to be effective alternatives to DP-SGD in large-epsilon few-epoch training regimes. Significant work has been done to find the best correlated noise strategies, and the current state-of-the-art approach is DP-BandMF, which optimally balances the benefits of privacy amplification and noise correlation. Despite it's utility advantages, severe scalability limitations prevent this mechanism from handling large-scale training scenarios where the number of training iterations may exceed $10^4$ and the number of model parameters may exceed $10^7$. In this work, we present techniques to scale up DP-BandMF along these two dimensions, significantly extending it's reach and enabling it to handle settings with virtually any number of model parameters and training iterations, with negligible utility degradation.
format Preprint
id arxiv_https___arxiv_org_abs_2405_15913
institution arXiv
publishDate 2024
record_format arxiv
spellingShingle Scaling up the Banded Matrix Factorization Mechanism for Differentially Private ML
McKenna, Ryan
Machine Learning
Cryptography and Security
Data Structures and Algorithms
Correlated noise mechanisms such as DP Matrix Factorization (DP-MF) have proven to be effective alternatives to DP-SGD in large-epsilon few-epoch training regimes. Significant work has been done to find the best correlated noise strategies, and the current state-of-the-art approach is DP-BandMF, which optimally balances the benefits of privacy amplification and noise correlation. Despite it's utility advantages, severe scalability limitations prevent this mechanism from handling large-scale training scenarios where the number of training iterations may exceed $10^4$ and the number of model parameters may exceed $10^7$. In this work, we present techniques to scale up DP-BandMF along these two dimensions, significantly extending it's reach and enabling it to handle settings with virtually any number of model parameters and training iterations, with negligible utility degradation.
title Scaling up the Banded Matrix Factorization Mechanism for Differentially Private ML
topic Machine Learning
Cryptography and Security
Data Structures and Algorithms
url https://arxiv.org/abs/2405.15913