DPack: Efficiency-Oriented Privacy Budget Scheduling
Pierre Tholoniat, Kelly Kostopoulou, Mosharaf Chowdhury, Asaf Cidon, Roxana Geambasu, Mathias Lécuyer, Junfeng Yang
Abstract
Machine learning (ML) models can leak information about users, and differential privacy (DP) provides a rigorous way to bound that leakage under a given budget. This DP budget can be regarded as a new type of computing resource in workloads of multiple ML models training on user data. Once it is used, the DP budget is forever consumed. Therefore, it is crucial to allocate it most efficiently to train as many models as possible. This paper presents a scheduler for the privacy resources that optimizes for efficiency. We formulate privacy scheduling as a new type of multidimensional knapsack problem, called privacy knapsack, which maximizes DP budget efficiency. We show that privacy knapsack is NP-hard, hence practical algorithms are necessarily approximate. We develop an approximation algorithm for privacy knapsack, DPack, and evaluate it on microbenchmarks and on a new, synthetic private-ML workload we developed from the Alibaba ML cluster trace. We show that DPack: (1) often approaches the efficiency-optimal schedule, (2) consistently schedules more tasks compared to a state-of-the-art privacy scheduling algorithm that focused on fairness instead of efficiency (1.3-1.7× in Alibaba, 1.0-2.6X in microbenchmarks), but (3) sacrifices some level of fairness for efficiency. Using DPack, DP ML operators should be able to train more models on the same amount of user data while offering the same privacy guarantee to their users.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 652eaf79-cfbd-4ac2-b079-9004990eb4abCited by top-tier papers2
- DPolicy: Managing Privacy Risks Across Multiple Releases with Differential PrivacyNicolas Küchler, Alexander Viand, Hidde Lycklama, Anwar HithnawiS&P 2025
- Big Bird: Resilient Privacy Budgeting Across Untrusted Web DomainsPierre Tholoniat, Alison Caulfield, Giorgio Cavicchioli, Mark Chen et al.SOSP 2026
Builds on12
- Deep Learning with Differential PrivacyMartín Abadi, Andy Chu, Ian J. Goodfellow, H. Brendan McMahan et al.CCS 2016 · 7,620 citations
- Membership Inference Attacks Against Machine Learning ModelsReza Shokri, Marco Stronati, Congzheng Song, Vitaly ShmatikovS&P 2017 · 5,137 citations
- Extracting Training Data from Large Language ModelsNicholas Carlini, Florian Tramèr, Eric Wallace, Matthew Jagielski et al.USENIX Security 2021 · 2,866 citations
- The Secret Sharer: Evaluating and Testing Unintended Memorization in Neural NetworksNicholas Carlini, Chang Liu, Úlfar Erlingsson, Jernej Kos et al.USENIX Security 2019 · 1,386 citations
- Evaluating Differentially Private Machine Learning in PracticeBargav Jayaraman, David EvansUSENIX Security 2019 · 586 citations
Related papers
- Privacy Budget SchedulingTao Luo, Mingen Pan, Pierre Tholoniat, Asaf Cidon et al.OSDI 2021
- Privacy as a Resource in Differentially Private Federated LearningJinliang Yuan, Shangguang Wang, Shihe Wang, Yuanchun Li et al.INFOCOM 2023 · 15 citations
- DPBalance: Efficient and Fair Privacy Budget Scheduling for Federated Learning as a ServiceYu Liu, Zibo Wang, Yifei Zhu, Chen ChenINFOCOM 2024 · 7 citations
- Privacy Budgeting for Growing Machine Learning DatasetsWeiting Li, Liyao Xiang, Zhou Zhou, Feng PengINFOCOM 2021 · 14 citations
- DiVa: An Accelerator for Differentially Private Machine LearningBeomsik Park, Ranggi Hwang, Dongho Yoon, Yoonhyuk Choi et al.MICRO 2022 · 12 citations
