DPDR: Gradient Decomposition and Reconstruction for Differentially Private Deep Learning

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Liu, Yixuan, Xiong, Li, Liu, Yuhan, Gu, Yujie, Liu, Ruixuan, Chen, Hong
Format: Preprint
Published: 2024
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866929374423416832
author Liu, Yixuan
Xiong, Li
Liu, Yuhan
Gu, Yujie
Liu, Ruixuan
Chen, Hong
author_facet Liu, Yixuan
Xiong, Li
Liu, Yuhan
Gu, Yujie
Liu, Ruixuan
Chen, Hong
contents Differentially Private Stochastic Gradients Descent (DP-SGD) is a prominent paradigm for preserving privacy in deep learning. It ensures privacy by perturbing gradients with random noise calibrated to their entire norm at each training step. However, this perturbation suffers from a sub-optimal performance: it repeatedly wastes privacy budget on the general converging direction shared among gradients from different batches, which we refer as common knowledge, yet yields little information gain. Motivated by this, we propose a differentially private training framework with early gradient decomposition and reconstruction (DPDR), which enables more efficient use of the privacy budget. In essence, it boosts model utility by focusing on incremental information protection and recycling the privatized common knowledge learned from previous gradients at early training steps. Concretely, DPDR incorporates three steps. First, it disentangles common knowledge and incremental information in current gradients by decomposing them based on previous noisy gradients. Second, most privacy budget is spent on protecting incremental information for higher information gain. Third, the model is updated with the gradient reconstructed from recycled common knowledge and noisy incremental information. Theoretical analysis and extensive experiments show that DPDR outperforms state-of-the-art baselines on both convergence rate and accuracy.
format Preprint
id arxiv_https___arxiv_org_abs_2406_02744
institution arXiv
publishDate 2024
record_format arxiv
spellingShingle DPDR: Gradient Decomposition and Reconstruction for Differentially Private Deep Learning
Liu, Yixuan
Xiong, Li
Liu, Yuhan
Gu, Yujie
Liu, Ruixuan
Chen, Hong
Cryptography and Security
Machine Learning
Differentially Private Stochastic Gradients Descent (DP-SGD) is a prominent paradigm for preserving privacy in deep learning. It ensures privacy by perturbing gradients with random noise calibrated to their entire norm at each training step. However, this perturbation suffers from a sub-optimal performance: it repeatedly wastes privacy budget on the general converging direction shared among gradients from different batches, which we refer as common knowledge, yet yields little information gain. Motivated by this, we propose a differentially private training framework with early gradient decomposition and reconstruction (DPDR), which enables more efficient use of the privacy budget. In essence, it boosts model utility by focusing on incremental information protection and recycling the privatized common knowledge learned from previous gradients at early training steps. Concretely, DPDR incorporates three steps. First, it disentangles common knowledge and incremental information in current gradients by decomposing them based on previous noisy gradients. Second, most privacy budget is spent on protecting incremental information for higher information gain. Third, the model is updated with the gradient reconstructed from recycled common knowledge and noisy incremental information. Theoretical analysis and extensive experiments show that DPDR outperforms state-of-the-art baselines on both convergence rate and accuracy.
title DPDR: Gradient Decomposition and Reconstruction for Differentially Private Deep Learning
topic Cryptography and Security
Machine Learning
url https://arxiv.org/abs/2406.02744