Private Alternating Least Squares: Practical Private Matrix Completion with Tighter Rates
Steve Chien, Prateek Jain, Walid Krichene, Steffen Rendle, Shuang Song, Abhradeep Thakurta, Li Zhang
Abstract
We study the problem of differentially private (DP) matrix completion under user-level privacy. We design a joint differentially private variant of the popular Alternating-Least-Squares (ALS) method that achieves: i) (nearly) optimal sample complexity for matrix completion (in terms of number of items, users), and ii) the best known privacy/utility trade-off both theoretically, as well as on benchmark data sets. In particular, we provide the first global convergence analysis of ALS with noise introduced to ensure DP, and show that, in comparison to the best known alternative (the Private Frank-Wolfe algorithm by Jain et al. ( 2018 )), our error bounds scale significantly better with respect to the number of items and users, which is critical in practical problems. Extensive validation on standard benchmarks demonstrate that the algorithm, in combination with carefully designed sampling procedures, is significantly more accurate than existing techniques, thus promising to be the first practical DP embedding model.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers3
- Homomorphic Matrix CompletionXiao-Yang Liu, Zechu (Steven) Li, Xiaodong WangNeurIPS 2022 · 4 citations
- Multi-Task Differential Privacy Under Distribution SkewWalid Krichene, Prateek Jain, Shuang Song, Mukund Sundararajan et al.ICML 2023 · 3 citations
- Differentially Private Cross-Silo Recommendation from Implicit FeedbackXun Ran, Qingqing Ye, Xin Huang, Jianliang Xu et al.ICML 2026
Builds on6
- Deep Learning with Differential PrivacyMartín Abadi, Andy Chu, Ian J. Goodfellow, H. Brendan McMahan et al.CCS 2016 · 7,620 citations
- Membership Inference Attacks Against Machine Learning ModelsReza Shokri, Marco Stronati, Congzheng Song, Vitaly ShmatikovS&P 2017 · 5,137 citations
- Extracting Training Data from Large Language ModelsNicholas Carlini, Florian Tramèr, Eric Wallace, Matthew Jagielski et al.USENIX Security 2021 · 2,866 citations
- The Secret Sharer: Evaluating and Testing Unintended Memorization in Neural NetworksNicholas Carlini, Chang Liu, Úlfar Erlingsson, Jernej Kos et al.USENIX Security 2019 · 1,386 citations
- Is Interaction Necessary for Distributed Private Learning?Adam D. Smith, Abhradeep Thakurta, Jalaj UpadhyayS&P 2017 · 159 citations
Related papers
- From Noisy Fixed-Point Iterations to Private ADMM for Centralized and Federated LearningEdwige Cyffers, Aurélien Bellet, Debabrota BasuICML 2023 · 6 citations
- Gradient Descent with Linearly Correlated Noise: Theory and Applications to Differential PrivacyAnastasia Koloskova, Ryan McKenna, Zachary Charles, John Keith Rush et al.NeurIPS 2023 · 24 citations
- Private Model Personalization RevisitedConor Snedeker, Xinyu Zhou, Raef BassilyICML 2025
- Differentially Private Model PersonalizationPrateek Jain, John Rush, Adam D. Smith, Shuang Song et al.NeurIPS 2021 · 42 citations
- Learning to Generate Image Embeddings with User-Level Differential PrivacyZheng Xu, Maxwell D. Collins, Yuxiao Wang, Liviu Panait et al.CVPR 2023
