DPDR: Gradient Decomposition and Reconstruction for Differentially Private Deep Learning

Fuente: arXiv
Enregistré dans:
Détails bibliographiques
Auteurs principaux: Liu, Yixuan, Xiong, Li, Liu, Yuhan, Gu, Yujie, Liu, Ruixuan, Chen, Hong
Format: Preprint
Publié: 2024
Sujets:
Accès en ligne:
Tags: Ajouter un tag
Pas de tags, Soyez le premier à ajouter un tag!
_version_ 1866929374423416832
author Liu, Yixuan
Xiong, Li
Liu, Yuhan
Gu, Yujie
Liu, Ruixuan
Chen, Hong
author_facet Liu, Yixuan
Xiong, Li
Liu, Yuhan
Gu, Yujie
Liu, Ruixuan
Chen, Hong
contents Differentially Private Stochastic Gradients Descent (DP-SGD) is a prominent paradigm for preserving privacy in deep learning. It ensures privacy by perturbing gradients with random noise calibrated to their entire norm at each training step. However, this perturbation suffers from a sub-optimal performance: it repeatedly wastes privacy budget on the general converging direction shared among gradients from different batches, which we refer as common knowledge, yet yields little information gain. Motivated by this, we propose a differentially private training framework with early gradient decomposition and reconstruction (DPDR), which enables more efficient use of the privacy budget. In essence, it boosts model utility by focusing on incremental information protection and recycling the privatized common knowledge learned from previous gradients at early training steps. Concretely, DPDR incorporates three steps. First, it disentangles common knowledge and incremental information in current gradients by decomposing them based on previous noisy gradients. Second, most privacy budget is spent on protecting incremental information for higher information gain. Third, the model is updated with the gradient reconstructed from recycled common knowledge and noisy incremental information. Theoretical analysis and extensive experiments show that DPDR outperforms state-of-the-art baselines on both convergence rate and accuracy.
format Preprint
id arxiv_https___arxiv_org_abs_2406_02744
institution arXiv
publishDate 2024
record_format arxiv
spellingShingle DPDR: Gradient Decomposition and Reconstruction for Differentially Private Deep Learning
Liu, Yixuan
Xiong, Li
Liu, Yuhan
Gu, Yujie
Liu, Ruixuan
Chen, Hong
Cryptography and Security
Machine Learning
Differentially Private Stochastic Gradients Descent (DP-SGD) is a prominent paradigm for preserving privacy in deep learning. It ensures privacy by perturbing gradients with random noise calibrated to their entire norm at each training step. However, this perturbation suffers from a sub-optimal performance: it repeatedly wastes privacy budget on the general converging direction shared among gradients from different batches, which we refer as common knowledge, yet yields little information gain. Motivated by this, we propose a differentially private training framework with early gradient decomposition and reconstruction (DPDR), which enables more efficient use of the privacy budget. In essence, it boosts model utility by focusing on incremental information protection and recycling the privatized common knowledge learned from previous gradients at early training steps. Concretely, DPDR incorporates three steps. First, it disentangles common knowledge and incremental information in current gradients by decomposing them based on previous noisy gradients. Second, most privacy budget is spent on protecting incremental information for higher information gain. Third, the model is updated with the gradient reconstructed from recycled common knowledge and noisy incremental information. Theoretical analysis and extensive experiments show that DPDR outperforms state-of-the-art baselines on both convergence rate and accuracy.
title DPDR: Gradient Decomposition and Reconstruction for Differentially Private Deep Learning
topic Cryptography and Security
Machine Learning
url https://arxiv.org/abs/2406.02744