REVIEW 3 cited by
Differentially Private Learning with Adaptive Clipping
Not yet reviewed by Pith; the record is open.
This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.
SPECIMEN: schema-true, not a live event
T0 review · schema-true
One-sentence machine reading of the paper's core claim.
pith:XXXXXXXX · record.json · timestamp
Signed reviews
read the original abstract
Existing approaches for training neural networks with user-level differential privacy (e.g., DP Federated Averaging) in federated learning (FL) settings involve bounding the contribution of each user's model update by clipping it to some constant value. However there is no good a priori setting of the clipping norm across tasks and learning settings: the update norm distribution depends on the model architecture and loss, the amount of data on each device, the client learning rate, and possibly various other parameters. We propose a method wherein instead of a fixed clipping norm, one clips to a value at a specified quantile of the update norm distribution, where the value at the quantile is itself estimated online, with differential privacy. The method tracks the quantile closely, uses a negligible amount of privacy budget, is compatible with other federated learning technologies such as compression and secure aggregation, and has a straightforward joint DP analysis with DP-FedAvg. Experiments demonstrate that adaptive clipping to the median update norm works well across a range of realistic federated learning tasks, sometimes outperforming even the best fixed clip chosen in hindsight, and without the need to tune any clipping hyperparameter.
Forward citations
Cited by 3 Pith papers
-
AdaCliP: Adaptive Clipping for Private SGD
Coordinate-wise adaptive clipping in DP-SGD, with per-coordinate scales derived from a noise-minimization problem, yields higher MNIST accuracy than standard L2 clipping at the same privacy budget.
-
Fast Fourier Transform-Based Spectral and Temporal Gradient Filtering for Differential Privacy
FFTKF applies an FFT low-pass mask and a Kalman filter to privatized gradients, reporting modest accuracy gains over DP-SGD and DiSK on several image benchmarks, but with incomplete privacy accounting.
-
Federated Learning: Challenges, Methods, and Future Directions
This survey maps federated learning's core challenges, reviews existing methods, and lists open problems.
Discussion (0). Continue with ORCID to comment.