{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2022:YPQ2E7RJ5RE2HNTBK2FVEAUSIL","short_pith_number":"pith:YPQ2E7RJ","schema_version":"1.0","canonical_sha256":"c3e1a27e29ec49a3b661568b52029242fb8eb12d3b3d4ec821d4f059e01370a4","source":{"kind":"arxiv","id":"2206.13033","version":1},"attestation_state":"computed","paper":{"title":"Normalized/Clipped SGD with Perturbation for Differentially Private Non-Convex Optimization","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.IT","math.IT","stat.ML"],"primary_cat":"cs.LG","authors_text":"Huishuai Zhang, Tie-Yan Liu, Wei Chen, Xiaodong Yang","submitted_at":"2022-06-27T03:45:02Z","abstract_excerpt":"By ensuring differential privacy in the learning algorithms, one can rigorously mitigate the risk of large models memorizing sensitive training data. In this paper, we study two algorithms for this purpose, i.e., DP-SGD and DP-NSGD, which first clip or normalize \\textit{per-sample} gradients to bound the sensitivity and then add noise to obfuscate the exact information. We analyze the convergence behavior of these two algorithms in the non-convex optimization setting with two common assumptions and achieve a rate $\\mathcal{O}\\left(\\sqrt[4]{\\frac{d\\log(1/\\delta)}{N^2\\epsilon^2}}\\right)$ of the "},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"2206.13033","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2022-06-27T03:45:02Z","cross_cats_sorted":["cs.IT","math.IT","stat.ML"],"title_canon_sha256":"4bb086b7500d093369cd825191ef6f2971369346ad3131edb0b06e6b7dc645f0","abstract_canon_sha256":"141f2cf56b9dd84a5a2b2c6ba322ee0053c145b7ed5a2fcec5bcdc0441a61618"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-07-05T04:35:01.832021Z","signature_b64":"vXI7Of2N7CxD0akiDvjbeEuEZfHPU5zMDQMpz6iFKUIYKC9+v032sJuLFomRQQ0ePKGdrYNYVH8OMa2Dcu4rDw==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"c3e1a27e29ec49a3b661568b52029242fb8eb12d3b3d4ec821d4f059e01370a4","last_reissued_at":"2026-07-05T04:35:01.831586Z","signature_status":"signed_v1","first_computed_at":"2026-07-05T04:35:01.831586Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"Normalized/Clipped SGD with Perturbation for Differentially Private Non-Convex Optimization","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.IT","math.IT","stat.ML"],"primary_cat":"cs.LG","authors_text":"Huishuai Zhang, Tie-Yan Liu, Wei Chen, Xiaodong Yang","submitted_at":"2022-06-27T03:45:02Z","abstract_excerpt":"By ensuring differential privacy in the learning algorithms, one can rigorously mitigate the risk of large models memorizing sensitive training data. In this paper, we study two algorithms for this purpose, i.e., DP-SGD and DP-NSGD, which first clip or normalize \\textit{per-sample} gradients to bound the sensitivity and then add noise to obfuscate the exact information. We analyze the convergence behavior of these two algorithms in the non-convex optimization setting with two common assumptions and achieve a rate $\\mathcal{O}\\left(\\sqrt[4]{\\frac{d\\log(1/\\delta)}{N^2\\epsilon^2}}\\right)$ of the "},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2206.13033","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2206.13033/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"2206.13033","created_at":"2026-07-05T04:35:01.831643+00:00"},{"alias_kind":"arxiv_version","alias_value":"2206.13033v1","created_at":"2026-07-05T04:35:01.831643+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2206.13033","created_at":"2026-07-05T04:35:01.831643+00:00"},{"alias_kind":"pith_short_12","alias_value":"YPQ2E7RJ5RE2","created_at":"2026-07-05T04:35:01.831643+00:00"},{"alias_kind":"pith_short_16","alias_value":"YPQ2E7RJ5RE2HNTB","created_at":"2026-07-05T04:35:01.831643+00:00"},{"alias_kind":"pith_short_8","alias_value":"YPQ2E7RJ","created_at":"2026-07-05T04:35:01.831643+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":3,"internal_anchor_count":0,"sample":[{"citing_arxiv_id":"2606.04384","citing_title":"Revisiting Privacy Amplification by Subsampling in Selective Release DPSGD","ref_index":42,"is_internal_anchor":false},{"citing_arxiv_id":"2606.21763","citing_title":"From Gradient Clipping to Structural Refinement: Improving DPSGD for Medical Image Segmentation","ref_index":26,"is_internal_anchor":false},{"citing_arxiv_id":"2602.22611","citing_title":"Mitigating Membership Inference in Intermediate Representations with Differentially Private Training","ref_index":12,"is_internal_anchor":false}]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/YPQ2E7RJ5RE2HNTBK2FVEAUSIL","json":"https://pith.science/pith/YPQ2E7RJ5RE2HNTBK2FVEAUSIL.json","graph_json":"https://pith.science/api/pith-number/YPQ2E7RJ5RE2HNTBK2FVEAUSIL/graph.json","events_json":"https://pith.science/api/pith-number/YPQ2E7RJ5RE2HNTBK2FVEAUSIL/events.json","paper":"https://pith.science/paper/YPQ2E7RJ"},"agent_actions":{"view_html":"https://pith.science/pith/YPQ2E7RJ5RE2HNTBK2FVEAUSIL","download_json":"https://pith.science/pith/YPQ2E7RJ5RE2HNTBK2FVEAUSIL.json","view_paper":"https://pith.science/paper/YPQ2E7RJ","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=2206.13033&json=true","fetch_graph":"https://pith.science/api/pith-number/YPQ2E7RJ5RE2HNTBK2FVEAUSIL/graph.json","fetch_events":"https://pith.science/api/pith-number/YPQ2E7RJ5RE2HNTBK2FVEAUSIL/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/YPQ2E7RJ5RE2HNTBK2FVEAUSIL/action/timestamp_anchor","attest_storage":"https://pith.science/pith/YPQ2E7RJ5RE2HNTBK2FVEAUSIL/action/storage_attestation","attest_author":"https://pith.science/pith/YPQ2E7RJ5RE2HNTBK2FVEAUSIL/action/author_attestation","sign_citation":"https://pith.science/pith/YPQ2E7RJ5RE2HNTBK2FVEAUSIL/action/citation_signature","submit_replication":"https://pith.science/pith/YPQ2E7RJ5RE2HNTBK2FVEAUSIL/action/replication_record"}},"created_at":"2026-07-05T04:35:01.831643+00:00","updated_at":"2026-07-05T04:35:01.831643+00:00"}