Practical Privacy Filters and Odometers with Rényi Differential Privacy and Applications to Differentially Private Deep Learning

03/02/2021
by   Mathias Lecuyer, et al.
0

Differential Privacy (DP) is the leading approach to privacy preserving deep learning. As such, there are multiple efforts to provide drop-in integration of DP into popular frameworks. These efforts, which add noise to each gradient computation to make it DP, rely on composition theorems to bound the total privacy loss incurred over this sequence of DP computations. However, existing composition theorems present a tension between efficiency and flexibility. Most theorems require all computations in the sequence to have a predefined DP parameter, called the privacy budget. This prevents the design of training algorithms that adapt the privacy budget on the fly, or that terminate early to reduce the total privacy loss. Alternatively, the few existing composition results for adaptive privacy budgets provide complex bounds on the privacy loss, with constants too large to be practical. In this paper, we study DP composition under adaptive privacy budgets through the lens of Rényi Differential Privacy, proving a simpler composition theorem with smaller constants, making it practical enough to use in algorithm design. We demonstrate two applications of this theorem for DP deep learning: adapting the noise or batch size online to improve a model's accuracy within a fixed total privacy loss, and stopping early when fine-tuning a model to reduce total privacy loss.

READ FULL TEXT

page 1

page 2

page 3

page 4

research
08/28/2023

Composition in Differential Privacy for General Granularity Notions (Long Version)

The composition theorems of differential privacy (DP) allow data curator...
research
07/18/2022

Concurrent Composition Theorems for Differential Privacy

We study the concurrent composition properties of interactive differenti...
research
05/23/2016

DP-EM: Differentially Private Expectation Maximization

The iterative nature of the expectation maximization (EM) algorithm pres...
research
04/11/2023

Privacy Amplification via Shuffling: Unified, Simplified, and Tightened

In decentralized settings, the shuffle model of differential privacy has...
research
03/10/2022

Differentially Private Learning Needs Hidden State (Or Much Faster Convergence)

Differential privacy analysis of randomized learning algorithms typicall...
research
09/27/2022

On the Choice of Databases in Differential Privacy Composition

Differential privacy (DP) is a widely applied paradigm for releasing dat...
research
03/10/2022

Fully Adaptive Composition in Differential Privacy

Composition is a key feature of differential privacy. Well-known advance...

Please sign up or login with your details

Forgot password? Click here to reset