Differentially Private Learning Needs Better Model Initialization and Self-Distillation

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Ngong, Ivoline C., Near, Joseph P., Mireshghallah, Niloofar
Format: Preprint
Published: 2024
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866917813056176128
author Ngong, Ivoline C.
Near, Joseph P.
Mireshghallah, Niloofar
author_facet Ngong, Ivoline C.
Near, Joseph P.
Mireshghallah, Niloofar
contents Differentially private SGD (DPSGD) enables privacy-preserving training of language models, but often reduces utility, diversity, and linguistic quality. We introduce DPRefine, a three-phase method that initializes a model using data synthesis from a small pre-trained LM with rigorous filtering, applies DP finetuning on private data, and performs self-distillation to refine outputs. This approach significantly outperforms vanilla DPSGD, with AlpacaEval preferring DPRefine's generations in 78.4% of cases across all datasets. Our analysis reveals that DPRefine reduces linguistic errors in generated text by 84.0%, mitigating grammar and spelling errors, commonly associated with DPSGD. It also reduces inconsistencies of non-private models, such as hallucinated details and misattributed quotes. We find that small models like GPT-2 can be effective for initialization and distillation, highlighting their potential in enabling scalable and efficient deployment of privacy-preserving language.
format Preprint
id arxiv_https___arxiv_org_abs_2410_17566
institution arXiv
publishDate 2024
record_format arxiv
spellingShingle Differentially Private Learning Needs Better Model Initialization and Self-Distillation
Ngong, Ivoline C.
Near, Joseph P.
Mireshghallah, Niloofar
Machine Learning
Artificial Intelligence
Computation and Language
Cryptography and Security
Differentially private SGD (DPSGD) enables privacy-preserving training of language models, but often reduces utility, diversity, and linguistic quality. We introduce DPRefine, a three-phase method that initializes a model using data synthesis from a small pre-trained LM with rigorous filtering, applies DP finetuning on private data, and performs self-distillation to refine outputs. This approach significantly outperforms vanilla DPSGD, with AlpacaEval preferring DPRefine's generations in 78.4% of cases across all datasets. Our analysis reveals that DPRefine reduces linguistic errors in generated text by 84.0%, mitigating grammar and spelling errors, commonly associated with DPSGD. It also reduces inconsistencies of non-private models, such as hallucinated details and misattributed quotes. We find that small models like GPT-2 can be effective for initialization and distillation, highlighting their potential in enabling scalable and efficient deployment of privacy-preserving language.
title Differentially Private Learning Needs Better Model Initialization and Self-Distillation
topic Machine Learning
Artificial Intelligence
Computation and Language
Cryptography and Security
url https://arxiv.org/abs/2410.17566