DiVa: An Accelerator for Differentially Private Machine Learning
Beomsik Park, Ranggi Hwang, Dongho Yoon, Yoonhyuk Choi, Minsoo Rhu
Abstract
The widespread deployment of machine learning (ML) is raising serious concerns on protecting the privacy of users who contributed to the collection of training data. Differential privacy (DP) is rapidly gaining momentum in the industry as a practical standard for privacy protection. Despite DP’s importance, however, little has been explored within the computer systems community regarding the implication of this emerging ML algorithm on system designs. In this work, we conduct a detailed workload characterization on a state-of-the-art differentially private ML training algorithm named DPSGD. We uncover several unique properties of DP-SGD (e.g., its high memory capacity and computation requirements vs. non-private ML), root-causing its key bottlenecks. Based on our analysis, we propose an accelerator for differentially private ML named DiVa, which provides a significant improvement in compute utilization, leading to 2.6× higher energy-efficiency vs. conventional systolic arrays.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 6c995f67-8d02-45da-a9ff-c05c1cc19d99Cited by top-tier papers5
- SecureLoop: Design Space Exploration of Secure DNN AcceleratorsKyungmi Lee, Mengjia Yan, Joel S. Emer, Anantha P. ChandrakasanMICRO 2023 · 4 citations
- LazyDP: Co-Designing Algorithm-Software for Scalable Training of Differentially Private Recommendation ModelsJuntaek Lim, Youngeun Kwon, Ranggi Hwang, Kiwan Maeng et al.ASPLOS 2024 · 3 citations
- Debunking the CUDA Myth Towards GPU-based AI Systems: Evaluation of the Performance and Programmability of Intel's Gaudi NPU for AI Model ServingYunjae Lee, Juntaek Lim, Jehyeon Bang, Eunyeong Cho et al.ISCA 2025 · 2 citations
- Cocoon: A System Architecture for Differentially Private Training with Correlated NoisesDonghwan Kim, Xin Gu, Jinho Baek, Timothy Lo et al.OSDI 2026 · 1 citation
- Empowering Vector Architectures for ML: The CAMP Architecture for Matrix MultiplicationMohammadreza Esmali Nojehdeh, Hossein Mokhtarnia, Julian Pavon, Narcís Rodas et al.MICRO 2025 · 1 citation
Builds on19
- Language Models are Few-Shot LearnersTom B. Brown, Benjamin Mann, Nick Ryder, Melanie Subbiah et al.NeurIPS 2020 · 64,255 citations
- Deep Learning with Differential PrivacyMartín Abadi, Andy Chu, Ian J. Goodfellow, H. Brendan McMahan et al.CCS 2016 · 7,620 citations
- Membership Inference Attacks Against Machine Learning ModelsReza Shokri, Marco Stronati, Congzheng Song, Vitaly ShmatikovS&P 2017 · 5,137 citations
- Extracting Training Data from Large Language ModelsNicholas Carlini, Florian Tramèr, Eric Wallace, Matthew Jagielski et al.USENIX Security 2021 · 2,866 citations
- Comprehensive Privacy Analysis of Deep Learning: Passive and Active White-box Inference Attacks against Centralized and Federated LearningMilad Nasr, Reza Shokri, Amir HoumansadrS&P 2019 · 1,778 citations
Related papers
- DPack: Efficiency-Oriented Privacy Budget SchedulingPierre Tholoniat, Kelly Kostopoulou, Mosharaf Chowdhury, Asaf Cidon et al.EuroSys 2025 · 5 citations
- Adversary Instantiation: Lower Bounds for Differentially Private Machine LearningMilad Nasr, Shuang Song, Abhradeep Thakurta, Nicolas Papernot et al.S&P 2021 · 288 citations
- DPIS: An Enhanced Mechanism for Differentially Private SGD with Importance SamplingJianxin Wei, Ergute Bao, Xiaokui Xiao, Yin YangCCS 2022 · 16 citations
- DPSUR: Accelerating Differentially Private Stochastic Gradient Descent Using Selective Update and ReleaseJie Fu, Qingqing Ye, Haibo Hu, Zhili Chen et al.VLDB 2024 · 34 citations
- INO-SGD: Addressing Utility Imbalance under Individualized Differential PrivacyXiao Tian, Jue Fan, Rachael Hwee Ling Sim, Bryan Kian Hsiang LowICLR 2026
