Bypassing the Ambient Dimension: Private SGD with Gradient Subspace Identification
Yingxue Zhou, Steven Wu, Arindam Banerjee
Abstract
Differentially private SGD (DP-SGD) is one of the most popular methods for solving differentially private empirical risk minimization (ERM). Due to its noisy perturbation on each gradient update, the error rate of DP-SGD scales with the ambient dimension p, the number of parameters in the model. Such dependence can be problematic for over-parameterized models where p n, the number of training samples. Existing lower bounds on private ERM show that such dependence on p is inevitable in the worst case. In this paper, we circumvent the dependence on the ambient dimension by leveraging a low-dimensional structure of gradient space in deep networks-that is, the stochastic gradients for deep nets usually stay in a low dimensional subspace in the training process. We propose Projected DP-SGD that performs noise reduction by projecting the noisy gradients to a low-dimensional subspace, which is given by the top gradient eigenspace on a small public dataset. We provide a general sample complexity analysis on the public dataset for the gradient subspace identification problem and demonstrate that under certain low-dimensional assumptions the public sample complexity only grows logarithmically in p. Finally, we provide a theoretical analysis and empirical evaluations to show that our method can substantially improve the accuracy of DP-SGD in the high privacy regime (corresponding to low privacy loss ).
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 484eb93f-3e3e-44ad-b247-2bb05f30ac53Cited by top-tier papers43
- Large Language Models Can Be Strong Differentially Private LearnersXuechen Li, Florian Tramèr, Percy Liang, Tatsunori HashimotoICLR 2022 · 502 citations
- Differentially Private Fine-tuning of Language ModelsDa Yu, Saurabh Naik, Arturs Backurs, Sivakanth Gopi et al.ICLR 2022 · 494 citations
- Differentially Private Learning Needs Better Features (or Much More Data)Florian Tramèr, Dan BonehICLR 2021 · 325 citations
- Do not Let Privacy Overbill Utility: Gradient Embedding Perturbation for Private LearningDa Yu, Huishuai Zhang, Wei Chen, Tie-Yan LiuICLR 2021 · 133 citations
- Large Scale Private Learning via Low-rank ReparametrizationDa Yu, Huishuai Zhang, Wei Chen, Jian Yin et al.ICML 2021 · 122 citations
Builds on6
- Deep Learning with Differential PrivacyMartín Abadi, Andy Chu, Ian J. Goodfellow, H. Brendan McMahan et al.CCS 2016 · 7,620 citations
- Differentially Private Learning Needs Better Features (or Much More Data)Florian Tramèr, Dan BonehICLR 2021 · 325 citations
- Tempered Sigmoid Activations for Deep Learning with Differential PrivacyNicolas Papernot, Abhradeep Thakurta, Shuang Song, Steve Chien et al.AAAI 2021 · 210 citations
- Do not Let Privacy Overbill Utility: Gradient Embedding Perturbation for Private LearningDa Yu, Huishuai Zhang, Wei Chen, Tie-Yan LiuICLR 2021 · 133 citations
- BLENDER: Enabling Local Search with a Hybrid Differential Privacy ModelBrendan Avent, Aleksandra Korolova, David Zeber, Torgeir Hovden et al.USENIX Security 2017 · 101 citations
Related papers
- PE-SGD: Differentially Private Deep Learning via Evolution of Gradient Subspace for TextTianyuan Zou, Zinan Lin, Sivakanth Gopi, Yang Liu et al.ICLR 2026
- DP-PCA: Statistically Optimal and Differentially Private PCAXiyang Liu, Weihao Kong, Prateek Jain, Sewoong OhNeurIPS 2022 · 38 citations
- Privately Learning SubspacesVikrant Singhal, Thomas SteinkeNeurIPS 2021 · 23 citations
- Improved Rates of Differentially Private Nonconvex-Strongly-Concave Minimax OptimizationRuijia Zhang, Mingxi Lei, Meng Ding, Zihang Xiang et al.AAAI 2025 · 7 citations
- An Iterative Algorithm for Differentially Private -PCA with Adaptive NoiseJohanna Düngler, Amartya SanyalNeurIPS 2025 · 3 citations
