Removing Disparate Impact on Model Accuracy in Differentially Private Stochastic Gradient Descent
Depeng Xu, Wei Du, Xintao Wu
Abstract
In differentially private stochastic gradient descent (DPSGD), gradient clipping and random noise addition disproportionately affect underrepresented and complex classes and subgroups. As a consequence, DPSGD has disparate impact: the accuracy of a model trained using DPSGD tends to decrease more on these classes and subgroups vs. the original, non-private model. If the original model is unfair in the sense that its accuracy is not the same across all subgroups, DPSGD exacerbates this unfairness. In this work, we study the inequality in utility loss due to differential privacy, which compares the changes in prediction accuracy w.r.t. each group between the private model and the non-private model. We analyze the cost of privacy w.r.t. each group and explain how the group sample size along with other factors is related to the privacy impact on group accuracy. Furthermore, we propose a modified DPSGD algorithm, called DPSGD-F, to achieve differential privacy, equal costs of differential privacy, and good utility. DPSGD-F adaptively adjusts the contribution of samples in a group depending on the group clipping bias such that differential privacy has no disparate impact on group accuracy. Our experimental evaluation shows the effectiveness of our removal algorithm on achieving equal costs of differential privacy with satisfactory utility.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Cited by top-tier papers5
- Functional Renyi Differential Privacy for Generative ModelingDihong Jiang, Sun Sun, Yaoliang YuNeurIPS 2023 · 17 citations
- What You See is What You Get: Principled Deep Learning via Distributional GeneralizationBogdan Kulynych, Yao-Yuan Yang, Yaodong Yu, Jaroslaw Blasiok et al.NeurIPS 2022 · 13 citations
- Multi-Task Differential Privacy Under Distribution SkewWalid Krichene, Prateek Jain, Shuang Song, Mukund Sundararajan et al.ICML 2023 · 3 citations
- PrivateFL: Accurate, Differentially Private Federated Learning via Personalized Data TransformationYuchen Yang, Bo Hui, Haolin Yuan, Neil Zhenqiang Gong et al.USENIX Security 2023
- INO-SGD: Addressing Utility Imbalance under Individualized Differential PrivacyXiao Tian, Jue Fan, Rachael Hwee Ling Sim, Bryan Kian Hsiang LowICLR 2026
Related papers
- Disparate Impact in Differential Privacy from Gradient MisalignmentMaria S. Esipova, Atiyeh Ashari Ghomi, Yaqiao Luo, Jesse C. CresswellICLR 2023 · 7 citations
- Differentially Private Empirical Risk Minimization under the Fairness LensCuong Tran, My H. Dinh, Ferdinando FiorettoNeurIPS 2021 · 61 citations
- Robin Hood and Matthew Effects: Differential Privacy Has Disparate Impact on Synthetic DataGeorgi Ganev, Bristena Oprisanu, Emiliano De CristofaroICML 2022 · 78 citations
- Improved Convergence of Differential Private SGD with Gradient ClippingHuang Fang, Xiaoyun Li, Chenglin Fan, Ping LiICLR 2023
- Differentially Private SGD Without Clipping Bias: An Error-Feedback ApproachXinwei Zhang, Zhiqi Bu, Steven Wu, Mingyi HongICLR 2024 · 15 citations
