Balls-and-Bins sampling for DP-SGD has a tight privacy analysis: as private as Poisson at large epsilon, with shuffle-comparable utility, verified by Monte Carlo accounting.
Improved Differential Privacy for SGD via Optimal Private Linear Operators on Adaptive Streams
1 Pith paper cite this work. Polarity classification is still indexing.
abstract
Motivated by recent applications requiring differential privacy over adaptive streams, we investigate the question of optimal instantiations of the matrix mechanism in this setting. We prove fundamental theoretical results on the applicability of matrix factorizations to adaptive streams, and provide a parameter-free fixed-point algorithm for computing optimal factorizations. We instantiate this framework with respect to concrete matrices which arise naturally in machine learning, and train user-level differentially private models with the resulting optimal mechanisms, yielding significant improvements in a notable problem in federated learning with user-level differential privacy.
fields
cs.LG 1years
2024 1verdicts
CONDITIONAL 1representative citing papers
citing papers explorer
-
Balls-and-Bins Sampling for DP-SGD
Balls-and-Bins sampling for DP-SGD has a tight privacy analysis: as private as Poisson at large epsilon, with shuffle-comparable utility, verified by Monte Carlo accounting.