On the Inherent Privacy of Zeroth Order Projected Gradient Descent

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Gupta, Devansh, Razaviyayn, Meisam, Sharan, Vatsal
Format: Preprint
Published: 2025
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866911046455787520
author Gupta, Devansh
Razaviyayn, Meisam
Sharan, Vatsal
author_facet Gupta, Devansh
Razaviyayn, Meisam
Sharan, Vatsal
contents Differentially private zeroth-order optimization methods have recently gained popularity in private fine tuning of machine learning models due to their reduced memory requirements. Current approaches for privatizing zeroth-order methods rely on adding Gaussian noise to the estimated zeroth-order gradients. However, since the search direction in the zeroth-order methods is inherently random, researchers including Tang et al. (2024) and Zhang et al. (2024a) have raised an important question: is the inherent noise in zeroth-order estimators sufficient to ensure the overall differential privacy of the algorithm? This work settles this question for a class of oracle-based optimization algorithms where the oracle returns zeroth-order gradient estimates. In particular, we show that for a fixed initialization, there exist strongly convex objective functions such that running (Projected) Zeroth-Order Gradient Descent (ZO-GD) is not differentially private. Furthermore, we show that even with random initialization and without revealing (initial and) intermediate iterates, the privacy loss in ZO-GD can grow superlinearly with the number of iterations when minimizing convex objective functions.
format Preprint
id arxiv_https___arxiv_org_abs_2507_05610
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle On the Inherent Privacy of Zeroth Order Projected Gradient Descent
Gupta, Devansh
Razaviyayn, Meisam
Sharan, Vatsal
Optimization and Control
Machine Learning
Differentially private zeroth-order optimization methods have recently gained popularity in private fine tuning of machine learning models due to their reduced memory requirements. Current approaches for privatizing zeroth-order methods rely on adding Gaussian noise to the estimated zeroth-order gradients. However, since the search direction in the zeroth-order methods is inherently random, researchers including Tang et al. (2024) and Zhang et al. (2024a) have raised an important question: is the inherent noise in zeroth-order estimators sufficient to ensure the overall differential privacy of the algorithm? This work settles this question for a class of oracle-based optimization algorithms where the oracle returns zeroth-order gradient estimates. In particular, we show that for a fixed initialization, there exist strongly convex objective functions such that running (Projected) Zeroth-Order Gradient Descent (ZO-GD) is not differentially private. Furthermore, we show that even with random initialization and without revealing (initial and) intermediate iterates, the privacy loss in ZO-GD can grow superlinearly with the number of iterations when minimizing convex objective functions.
title On the Inherent Privacy of Zeroth Order Projected Gradient Descent
topic Optimization and Control
Machine Learning
url https://arxiv.org/abs/2507.05610