USENIX Security2024Top-tier venue
DPAdapter: Improving Differentially Private Deep Learning through Noise Tolerance Pre-training
Zihao Wang, Rui Zhu, Dongruo Zhou, Zhikun Zhang, John Mitchell, Haixu Tang, XiaoFeng Wang
Abstract
Recent developments have underscored the critical role of differential privacy (DP) in safeguarding individual data for training machine learning models. However, integrating DP oftentimes incurs significant model performance degradation due to the perturbation introduced into the training process, presenting a formidable challenge in the differentially private machine learning (DPML) field. To this end, several mitigative efforts have been proposed, typically revolving around formulating new DPML algorithms or relaxing DP definitions to harmonize with distinct contexts. In spite of these initiatives, the diminishment induced by DP on models, particularly large-scale models, remains substantial and thus, necessitates an innovative solution that adeptly circumnavigates the consequential impairment of model utility. In response, we introduce DPAdapter, a pioneering technique designed to amplify the model performance of DPML algorithms by enhancing parameter robustness. The fundamental intuition behind this strategy is that models with robust parameters are inherently more resistant to the noise introduced by DP, thereby retaining better performance despite the perturbations. DPAdapter modifies and enhances the sharpness-aware minimization (SAM) technique, utilizing a two-batch strategy to provide a more accurate perturbation estimate and an efficient gradient descent, thereby improving parameter robustness against noise. Notably, DPAdapter can act as a plug-and-play component and be combined with existing DPML algorithms to further improve their performance. Our experiments show that DPAdapter vastly enhances state-of-the-art DPML algorithms, increasing average accuracy from 72.92% to 77.09% with a privacy budget of .
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext d1577aad-4686-42e2-9524-d766b6235ccdCited by top-tier papers5
- S2NeRF: Privacy-preserving Training Framework for NeRFBokang Zhang, Yanglin Zhang, Zhikun Zhang, Jinglan Yang et al.CCS 2024
- DPQuant: Efficient and Private Model Training via Dynamic Quantization SchedulingYubo Gao, Renbo Tu, Gennady Pekhimenko, Nandita VijaykumarICLR 2026
- Sharpness-Aware Initialization: Improving Differentially Private Machine Learning from First PrinciplesZihao Wang, Rui Zhu, Dongruo Zhou, Zhikun Zhang et al.USENIX Security 2025
- RPGen: Robust and Differentially Private Synthetic Image GenerationZihao Wang, Hao Peng, Wei Dong, Yuecen Wei et al.AAAI 2026
- SoK: Dataset Copyright Auditing in Machine Learning SystemsLinkang Du, Xuanru Zhou, Min Chen, Chusong Zhang et al.S&P 2025
Builds on37
- An Image is Worth 16x16 Words: Transformers for Image Recognition at ScaleAlexey Dosovitskiy, Lucas Beyer, Alexander Kolesnikov, Dirk Weissenborn et al.ICLR 2021 · 21,477 citations
- Deep Learning with Differential PrivacyMartín Abadi, Andy Chu, Ian J. Goodfellow, H. Brendan McMahan et al.CCS 2016 · 7,620 citations
- Extracting Training Data from Large Language ModelsNicholas Carlini, Florian Tramèr, Eric Wallace, Matthew Jagielski et al.USENIX Security 2021 · 2,866 citations
- An Empirical Study of Training Self-Supervised Vision TransformersXinlei Chen, Saining Xie, Kaiming HeICCV 2021 · 2,340 citations
- Sharpness-aware Minimization for Efficiently Improving GeneralizationPierre Foret, Ariel Kleiner, Hossein Mobahi, Behnam NeyshaburICLR 2021 · 1,861 citations
Related papers
- Differentially Private Sharpness-Aware TrainingJinseong Park, Hoki Kim, Yujin Choi, Jaewook LeeICML 2023 · 15 citations
- Make Landscape Flatter in Differentially Private Federated LearningYifan Shi, Yingqi Liu, Kang Wei, Li Shen et al.CVPR 2023
- DiSK: Differentially Private Optimizer with Simplified Kalman Filter for Noise ReductionXinwei Zhang, Zhiqi Bu, Borja Balle, Mingyi Hong et al.ICLR 2025
- An Adaptive and Fast Convergent Approach to Differentially Private Deep LearningZhiying Xu, Shuyu Shi, Alex X. Liu, Jun Zhao et al.INFOCOM 2020 · 51 citations
- DOPPLER: Differentially Private Optimizers with Low-pass Filter for Privacy Noise ReductionXinwei Zhang, Zhiqi Bu, Mingyi Hong, Meisam RazaviyaynNeurIPS 2024 · 10 citations
