Leveraging Randomness in Model and Data Partitioning for Privacy Amplification
Andy Dong, Wei-Ning Chen, Ayfer Özgür
Abstract
We study how inherent randomness in the training process-where each sample (or client in federated learning) contributes to only a randomly selected portion of training-can be leveraged for privacy amplification. This includes (1) model partitioning, where a sample updates only a subset of the model parameters, and (2) data partitioning, where a sample participates in only a subset of training iterations. We apply our framework to model parallelism in federated learning, where each client updates a randomly selected subnetwork to reduce memory and computational overhead, and show that existing methods, e.g. model splitting or dropout, provide a significant privacy amplification gain not captured by previous privacy analysis techniques. Additionally, we introduce Balanced Iteration Subsampling, a new data partitioning method where each sample (or client) participates in a fixed number of training iterations. We show that this method yields similar or stronger privacy amplification than Poisson (i.i.d.) sampling of data (or clients). Our results demonstrate that randomness in the training process, which is structured rather than i.i.d. and interacts with data in complex ways, can be systematically leveraged for significant privacy amplification.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 04ebc7a1-dc08-4158-9846-c431f68f3ceeCited by top-tier papers4
- Privacy amplification by random allocationMoshe Shenfeld, Vitaly FeldmanNeurIPS 2025 · 18 citations
- Efficient privacy loss accounting for subsampling and random allocationVitaly Feldman, Moshe ShenfeldICML 2026 · 5 citations
- Fundamental Limitations of Favorable Privacy–Utility Guarantees for DP-SGDMurat Bilgehan Ertan), Marten van Dijk)CCS 2026 · 3 citations
- PREAMBLE: Private and Efficient Aggregation via Block Sparse VectorsHilal Asi, Vitaly Feldman, Hannah Keller, Guy N. Rothblum et al.NeurIPS 2025 · 1 citation
Builds on8
- Deep Learning with Differential PrivacyMartín Abadi, Andy Chu, Ian J. Goodfellow, H. Brendan McMahan et al.CCS 2016 · 7,620 citations
- The Discrete Gaussian for Differential PrivacyClément L. Canonne, Gautam Kamath, Thomas SteinkeNeurIPS 2020 · 355 citations
- Privacy Amplification via Random Check-InsBorja Balle, Peter Kairouz, Brendan McMahan, Om Dipakbhai Thakkar et al.NeurIPS 2020 · 86 citations
- Hiding Among the Clones: A Simple and Nearly Optimal Analysis of Privacy Amplification by ShufflingVitaly Feldman, Audra McMillan, Kunal TalwarFOCS 2021 · 76 citations
- Privacy Amplification via Compression: Achieving the Optimal Privacy-Accuracy-Communication Trade-off in Distributed Mean EstimationWei-Ning Chen, Dan Song, Ayfer Özgür, Peter KairouzNeurIPS 2023 · 42 citations
Related papers
- Renyi Differential Privacy of The Subsampled Shuffle Model In Distributed LearningAntonious M. Girgis, Deepesh Data, Suhas N. DiggaviNeurIPS 2021 · 28 citations
- FLAME: Differentially Private Federated Learning in the Shuffle ModelRuixuan Liu, Yang Cao, Hong Chen, Ruoyang Guo et al.AAAI 2021 · 117 citations
- Clustered Sampling: Low-Variance and Improved Representativity for Clients Selection in Federated LearningYann Fraboni, Richard Vidal, Laetitia Kameni, Marco LorenziICML 2021 · 249 citations
- Echo of Neighbors: Privacy Amplification for Personalized Private Federated Learning with Shuffle ModelYixuan Liu, Suyun Zhao, Li Xiong, Yuhan Liu et al.AAAI 2023 · 18 citations
- Practical and Private (Deep) Learning Without Sampling or ShufflingPeter Kairouz, Brendan McMahan, Shuang Song, Om Thakkar et al.ICML 2021 · 239 citations
