GeoClip: Geometry-Aware Clipping for Differentially Private SGD

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Gilani, Atefeh, Tasnim, Naima, Sankar, Lalitha, Kosut, Oliver
Format: Preprint
Published: 2025
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866912673256439808
author Gilani, Atefeh
Tasnim, Naima
Sankar, Lalitha
Kosut, Oliver
author_facet Gilani, Atefeh
Tasnim, Naima
Sankar, Lalitha
Kosut, Oliver
contents Differentially private stochastic gradient descent (DP-SGD) is the most widely used method for training machine learning models with provable privacy guarantees. A key challenge in DP-SGD is setting the per-sample gradient clipping threshold, which significantly affects the trade-off between privacy and utility. While recent adaptive methods improve performance by adjusting this threshold during training, they operate in the standard coordinate system and fail to account for correlations across the coordinates of the gradient. We propose GeoClip, a geometry-aware framework that clips and perturbs gradients in a transformed basis aligned with the geometry of the gradient distribution. GeoClip adaptively estimates this transformation using only previously released noisy gradients, incurring no additional privacy cost. We provide convergence guarantees for GeoClip and derive a closed-form solution for the optimal transformation that minimizes the amount of noise added while keeping the probability of gradient clipping under control. Experiments on both tabular and image datasets demonstrate that GeoClip consistently outperforms existing adaptive clipping methods under the same privacy budget.
format Preprint
id arxiv_https___arxiv_org_abs_2506_06549
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle GeoClip: Geometry-Aware Clipping for Differentially Private SGD
Gilani, Atefeh
Tasnim, Naima
Sankar, Lalitha
Kosut, Oliver
Machine Learning
Cryptography and Security
Information Theory
Differentially private stochastic gradient descent (DP-SGD) is the most widely used method for training machine learning models with provable privacy guarantees. A key challenge in DP-SGD is setting the per-sample gradient clipping threshold, which significantly affects the trade-off between privacy and utility. While recent adaptive methods improve performance by adjusting this threshold during training, they operate in the standard coordinate system and fail to account for correlations across the coordinates of the gradient. We propose GeoClip, a geometry-aware framework that clips and perturbs gradients in a transformed basis aligned with the geometry of the gradient distribution. GeoClip adaptively estimates this transformation using only previously released noisy gradients, incurring no additional privacy cost. We provide convergence guarantees for GeoClip and derive a closed-form solution for the optimal transformation that minimizes the amount of noise added while keeping the probability of gradient clipping under control. Experiments on both tabular and image datasets demonstrate that GeoClip consistently outperforms existing adaptive clipping methods under the same privacy budget.
title GeoClip: Geometry-Aware Clipping for Differentially Private SGD
topic Machine Learning
Cryptography and Security
Information Theory
url https://arxiv.org/abs/2506.06549