Lune

ICML2024Top-tier venue

Rethinking DP-SGD in Discrete Domain: Exploring Logistic Distribution in the Realm of signSGD

Jonggyu Jang, Seongjin Hwang, Hyun Jong Yang

2024Year
4Citations
2Top-tier citations

Abstract

Deep neural networks (DNNs) have a risk of remembering sensitive data from their training datasets, inadvertently leading to substantial information leakage through privacy attacks like membership inference attacks. DP-SGD is a simple yet effective defense method that incorporates Gaussian noise into gradient updates to safeguard sensitive information. With the prevalence of large neural networks, DP-SIGNSGD, a variant of DP-SGD, has emerged, aiming to curtail communication load while maintaining security. However, it is noteworthy that most DP-SIGNSGD algorithms default to Gaussian noise, suitable only for DP-SGD, without scant discussion of its appropriateness for SIGNSGD. Our study delves into an intriguing question: "Can we find a more efficient substitute for Gaussian noise to secure privacy in DP-SIGNSGD?" We propose an answer with a Logistic mechanism, which conforms to SIGNSGD principles and is interestingly evolved from an exponential mechanism. In this paper, we provide both theoretical and experimental evidence showing that our method surpasses DP-SIGNSGD.

Ask about this paper

Your agent reads all of it.

Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.

Questions to start from

Your agent calls

Luneget_paper_fulltext

Ask in Lune

Free to start. No credit card required.

lune papers fulltext 0d1fdd34-8978-47db-ba9a-5d38abcdc778

Cited by top-tier papers2

Ask how each one uses it

Builds on9

Related papers

Dusk over the sea between two cliffs drawn in fine vertical lines