Towards Reliable and Generalizable Differentially Private Machine Learning (Extended Version)

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Bao, Wenxuan, Bindschaedler, Vincent
Format: Preprint
Published: 2025
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866909746666143744
author Bao, Wenxuan
Bindschaedler, Vincent
author_facet Bao, Wenxuan
Bindschaedler, Vincent
contents There is a flurry of recent research papers proposing novel differentially private machine learning (DPML) techniques. These papers claim to achieve new state-of-the-art (SoTA) results and offer empirical results as validation. However, there is no consensus on which techniques are most effective or if they genuinely meet their stated claims. Complicating matters, heterogeneity in codebases, datasets, methodologies, and model architectures make direct comparisons of different approaches challenging. In this paper, we conduct a reproducibility and replicability (R+R) experiment on 11 different SoTA DPML techniques from the recent research literature. Results of our investigation are varied: while some methods stand up to scrutiny, others falter when tested outside their initial experimental conditions. We also discuss challenges unique to the reproducibility of DPML, including additional randomness due to DP noise, and how to address them. Finally, we derive insights and best practices to obtain scientifically valid and reliable results.
format Preprint
id arxiv_https___arxiv_org_abs_2508_15141
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle Towards Reliable and Generalizable Differentially Private Machine Learning (Extended Version)
Bao, Wenxuan
Bindschaedler, Vincent
Machine Learning
Cryptography and Security
There is a flurry of recent research papers proposing novel differentially private machine learning (DPML) techniques. These papers claim to achieve new state-of-the-art (SoTA) results and offer empirical results as validation. However, there is no consensus on which techniques are most effective or if they genuinely meet their stated claims. Complicating matters, heterogeneity in codebases, datasets, methodologies, and model architectures make direct comparisons of different approaches challenging. In this paper, we conduct a reproducibility and replicability (R+R) experiment on 11 different SoTA DPML techniques from the recent research literature. Results of our investigation are varied: while some methods stand up to scrutiny, others falter when tested outside their initial experimental conditions. We also discuss challenges unique to the reproducibility of DPML, including additional randomness due to DP noise, and how to address them. Finally, we derive insights and best practices to obtain scientifically valid and reliable results.
title Towards Reliable and Generalizable Differentially Private Machine Learning (Extended Version)
topic Machine Learning
Cryptography and Security
url https://arxiv.org/abs/2508.15141