Rethinking DP-SGD in Discrete Domain: Exploring Logistic Distribution in the Realm of signSGD
Jonggyu Jang, Seongjin Hwang, Hyun Jong Yang
Abstract
Deep neural networks (DNNs) have a risk of remembering sensitive data from their training datasets, inadvertently leading to substantial information leakage through privacy attacks like membership inference attacks. DP-SGD is a simple yet effective defense method that incorporates Gaussian noise into gradient updates to safeguard sensitive information. With the prevalence of large neural networks, DP-SIGNSGD, a variant of DP-SGD, has emerged, aiming to curtail communication load while maintaining security. However, it is noteworthy that most DP-SIGNSGD algorithms default to Gaussian noise, suitable only for DP-SGD, without scant discussion of its appropriateness for SIGNSGD. Our study delves into an intriguing question: "Can we find a more efficient substitute for Gaussian noise to secure privacy in DP-SIGNSGD?" We propose an answer with a Logistic mechanism, which conforms to SIGNSGD principles and is interestingly evolved from an exponential mechanism. In this paper, we provide both theoretical and experimental evidence showing that our method surpasses DP-SIGNSGD.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 0d1fdd34-8978-47db-ba9a-5d38abcdc778Cited by top-tier papers2
- Noisy SIGNSGD Is More Differentially Private Than You (Might) ThinkRicheng Jin, Huaiyu DaiICML 2025
- PLRV-O: Advancing Differentially Private Deep Learning via Privacy Loss Random Variable OptimizationQin Yang, Nicholas Stout, Meisam Mohammady, Han Wang et al.CCS 2025
Builds on9
- An Image is Worth 16x16 Words: Transformers for Image Recognition at ScaleAlexey Dosovitskiy, Lucas Beyer, Alexander Kolesnikov, Dirk Weissenborn et al.ICLR 2021 · 21,477 citations
- Deep Learning with Differential PrivacyMartín Abadi, Andy Chu, Ian J. Goodfellow, H. Brendan McMahan et al.CCS 2016 · 7,620 citations
- What Neural Networks Memorize and Why: Discovering the Long Tail via Influence EstimationVitaly Feldman, Chiyuan ZhangNeurIPS 2020 · 674 citations
- Machine Learning Models that Remember Too MuchCongzheng Song, Thomas Ristenpart, Vitaly ShmatikovCCS 2017 · 582 citations
- Auditing Differentially Private Machine Learning: How Private is Private SGD?Matthew Jagielski, Jonathan R. Ullman, Alina OpreaNeurIPS 2020 · 354 citations
Related papers
- Bounding training data reconstruction in DP-SGDJamie Hayes, Borja Balle, Saeed MahloujifarNeurIPS 2023 · 73 citations
- DP-Forward: Fine-tuning and Inference on Language Models with Differential Privacy in Forward PassMinxin Du, Xiang Yue, Sherman S. M. Chow, Tianhao Wang et al.CCS 2023 · 35 citations
- Closed-Form Bounds for DP-SGD against Record-level InferenceGiovanni Cherubin, Boris Köpf, Andrew Paverd, Shruti Tople et al.USENIX Security 2024 · 2 citations
- Characterizing Membership Privacy in Stochastic Gradient Langevin DynamicsBingzhe Wu, Chaochao Chen, Shiwan Zhao, Cen Chen et al.AAAI 2020 · 23 citations
- DPSUR: Accelerating Differentially Private Stochastic Gradient Descent Using Selective Update and ReleaseJie Fu, Qingqing Ye, Haibo Hu, Zhili Chen et al.VLDB 2024 · 34 citations
