Task-level Differentially Private Meta Learning
Xinyu Zhou, Raef Bassily
Abstract
We study the problem of meta-learning with task-level differential privacy. Meta-learning has received increasing attention recently because of its ability to enable fast generalization to new task with small number of data points. However, the training process of meta learning likely involves exchange of task specific information, which may pose privacy risk especially in some privacy-sensitive applications. Therefore, it is important to provide strong privacy guarantees such that the learning process will not reveal any task sensitive information. To this end, existing works have proposed meta learning algorithms with record-level differential privacy, which is not sufficient in many scenarios since it does not protect the aggregated statistics based on the task dataset as a whole. Moreover, the utility guarantees in the prior work are based on assuming the loss function satisfies both smoothness and quadratic growth conditions, which do not necessarily hold in practice. To address these issues, we propose meta learning algorithms with task-level differential privacy; that is, our algorithms protect the entire dataset for each task. In the case when a single meta model is trained, we give both privacy and utility guarantees assuming only that the loss is convex and Lipschitz. Moreover, we propose a new private clustering-based meta-learning algorithm that enables private meta learning of multiple meta models. This can provide significant accuracy gains over the single meta model paradigm, especially when the tasks distribution cannot be well represented by a single meta model. Finally, we conduct several experiments demonstrating the effectiveness of our proposed algorithms.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 46032af1-5a2d-49b5-8788-9173e9f311e0Cited by top-tier papers3
- On the Stability and Generalization of Meta-LearningYunjuan Wang, Raman AroraNeurIPS 2024 · 12 citations
- Noise-Aware Differentially Private Regression via Meta-LearningOssi Räisä, Stratis Markou, Matthew Ashman, Wessel P. Bruinsma et al.NeurIPS 2024 · 3 citations
- FedMeNF: Privacy-Preserving Federated Meta-Learning for Neural FieldsJunhyeog Yun, Minui Hong, Gunhee KimICCV 2025
Builds on8
- Practical and Private (Deep) Learning Without Sampling or ShufflingPeter Kairouz, Brendan McMahan, Shuang Song, Om Thakkar et al.ICML 2021 · 239 citations
- Hyperparameter Tuning with Renyi Differential PrivacyNicolas Papernot, Thomas SteinkeICLR 2022 · 157 citations
- Differentially Private Meta-LearningJeffrey Li, Mikhail Khodak, Sebastian Caldas, Ameet TalwalkarICLR 2020 · 125 citations
- Learning with User-Level PrivacyDaniel Levy, Ziteng Sun, Kareem Amin, Satyen Kale et al.NeurIPS 2021 · 113 citations
- Personalization Improves Privacy-Accuracy Tradeoffs in Federated LearningAlberto Bietti, Chen-Yu Wei, Miroslav Dudík, John Langford et al.ICML 2022 · 67 citations
Related papers
- Locally Differentially Private Decentralized Stochastic Bilevel Optimization with Guaranteed Convergence AccuracyZiqin Chen, Yongqiang WangICML 2024 · 5 citations
- Uldp-FL: Federated Learning with Across Silo User-Level Differential PrivacyFumiyuki Kato, Li Xiong, Shun Takagi, Yang Cao et al.VLDB 2024 · 14 citations
- Improved Regret Bounds for Non-Convex Online-Within-Online Meta LearningJiechao Guan, Hui XiongICLR 2024
- Differentially Private Bilevel Optimization: Efficient Algorithms with Near-Optimal RatesAndrew Lowy, Daogao LiuNeurIPS 2025 · 3 citations
- Robust and differentially private mean estimationXiyang Liu, Weihao Kong, Sham M. Kakade, Sewoong OhNeurIPS 2021 · 87 citations
