Privacy Budget Scheduling
Tao Luo, Mingen Pan, Pierre Tholoniat, Asaf Cidon, Roxana Geambasu, Mathias Lécuyer
Abstract
Machine learning (ML) models trained on personal data have been shown to leak information about users. Differential privacy (DP) enables model training with a guaranteed bound on this leakage. Each new model trained with DP increases the bound on data leakage and can be seen as consuming part of a global privacy budget that should not be exceeded. This budget is a scarce resource that must be carefully managed to maximize the number of successfully trained models.
We describe PrivateKube, an extension to the popular Kubernetes datacenter orchestrator that adds privacy as a new type of resource to be managed alongside other traditional compute resources, such as CPU, GPU, and memory. The abstractions we design for the privacy resource mirror those defined by Kubernetes for traditional resources, but there are also major differences. For example, traditional compute resources are replenishable while privacy is not: a CPU can be regained after a model finishes execution while privacy budget cannot. This distinction forces a re-design of the scheduler. We present DPF (Dominant Private Block Fairness) -a variant of the popular Dominant Resource Fairness (DRF) algorithm -that is geared toward the non-replenishable privacy resource but enjoys similar theoretical properties as DRF.
We evaluate PrivateKube and DPF on microbenchmarks and an ML workload on Amazon Reviews data. Compared to existing baselines, DPF allows training more models under the same global privacy guarantee. This is especially true for DPF over Rényi DP, a highly composable form of DP.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext c3f3db09-c122-4d2b-b1ba-223172cd5d81Cited by top-tier papers17
- FederatedScope: A Flexible Federated Learning Platform for HeterogeneityYuexiang Xie, Zhen Wang, Dawei Gao, Daoyuan Chen et al.VLDB 2023 · 120 citations
- Multi-resource interleaving for deep learning trainingYihao Zhao, Yuanqiang Liu, Yanghua Peng, Yibo Zhu et al.SIGCOMM 2022 · 78 citations
- Karma: Resource Allocation for Dynamic DemandsMidhul Vuppalapati, Giannis Fikioris, Rachit Agarwal, Asaf Cidon et al.OSDI 2023 · 22 citations
- Longshot: Indexing Growing Databases using MPC and Differential PrivacyYanping Zhang, Johes Bater, Kartik Nayak, Ashwin MachanavajjhalaVLDB 2023 · 19 citations
- Privacy as a Resource in Differentially Private Federated LearningJinliang Yuan, Shangguang Wang, Shihe Wang, Yuanchun Li et al.INFOCOM 2023 · 15 citations
Builds on7
- Deep Learning with Differential PrivacyMartín Abadi, Andy Chu, Ian J. Goodfellow, H. Brendan McMahan et al.CCS 2016 · 7,620 citations
- Membership Inference Attacks Against Machine Learning ModelsReza Shokri, Marco Stronati, Congzheng Song, Vitaly ShmatikovS&P 2017 · 5,137 citations
- The Secret Sharer: Evaluating and Testing Unintended Memorization in Neural NetworksNicholas Carlini, Chang Liu, Úlfar Erlingsson, Jernej Kos et al.USENIX Security 2019 · 1,386 citations
- Evaluating Differentially Private Machine Learning in PracticeBargav Jayaraman, David EvansUSENIX Security 2019 · 586 citations
- Differentially Private Model Publishing for Deep LearningLei Yu, Ling Liu, Calton Pu, Mehmet Emre Gursoy et al.S&P 2019 · 294 citations
Related papers
- DPack: Efficiency-Oriented Privacy Budget SchedulingPierre Tholoniat, Kelly Kostopoulou, Mosharaf Chowdhury, Asaf Cidon et al.EuroSys 2025 · 5 citations
- Privacy Budgeting for Growing Machine Learning DatasetsWeiting Li, Liyao Xiang, Zhou Zhou, Feng PengINFOCOM 2021 · 14 citations
- DPBalance: Efficient and Fair Privacy Budget Scheduling for Federated Learning as a ServiceYu Liu, Zibo Wang, Yifei Zhu, Chen ChenINFOCOM 2024 · 7 citations
- Bringing Differential Privacy to HPC: Privacy-Preserving Transformations of HPC TracesAna Luisa Veroneze Solórzano, Rohan Basu Roy, Benjamin Schwaller, Sara Petra Walton et al.HPDC 2025
- DiVa: An Accelerator for Differentially Private Machine LearningBeomsik Park, Ranggi Hwang, Dongho Yoon, Yoonhyuk Choi et al.MICRO 2022 · 12 citations
