Improving the Privacy and Practicality of Objective Perturbation for Differentially Private Linear Learners
Rachel Redberg, Antti Koskela, Yu-Xiang Wang
Abstract
In the arena of privacy-preserving machine learning, differentially private stochastic gradient descent (DP-SGD) has outstripped the objective perturbation mechanism in popularity and interest. Though unrivaled in versatility, DP-SGD requires a non-trivial privacy overhead (for privately tuning the model's hyperparameters) and a computational complexity which might be extravagant for simple models such as linear and logistic regression. This paper revamps the objective perturbation mechanism with tighter privacy analyses and new computational tools that boost it to perform competitively with DP-SGD on unconstrained convex generalized linear problems. Preliminaries Differential Privacy Differential privacy (DP) (Dwork et al., 2006) offers provable privacy protection by restricting how much the output of a randomized algorithm can leak information about a single data point. DP requires a notion of how to measure similarity between datasets. We say that datasets Z and Z ′ are neighboring datasets (denoted Z ≃ Z ′ ) if they differ by exactly one datapoint z, i.e. Z ′ = Z ∪z or Z ′ = Z z for some data entry z. Definition 2.1 (Differential privacy). A mechanism M : Z → R satisfies (ϵ, δ)-differential privacy if for all neighboring datasets Z, Z ′ ∈ Z and output sets S ⊆ R, When δ > 0, M satisfies approximate DP. When δ = 0, M satisfies the stronger notion of pure DP. We say that M is tightly (ϵ, δ)-DP if there is no δ ′ < δ for which M would be (ϵ, δ ′ )-DP. In what follows, we overview two different styles of achieving DP guarantees: one via hockey-stick divergence, and the other via Rényi divergence. DP via hockey-stick divergence Definition 2.2 (Hockey-stick divergence). Denote [x] + = max0, x for x ∈ R. For α > 0 the hockey-stick divergence H α from a distribution P to a distribution Q is defined as Now (with some abuse of notation) we will discuss how to bound the hockey-stick divergence between distributions M(Z) and M(Z ′ ) via the concept of privacy profiles. Definition 2.3 (Privacy profiles Balle et al., 2018). The privacy profile δ M (ϵ) of a mechanism M is defined as Tight (ϵ, δ)-DP bounds can then be obtained as follows. Lemma 2. 4 (Zhu et al., 2022, Lemma 5) Dominating pairs of distributions are useful for bounding the hockey-stick divergence H e ϵ M(Z)||M(Z ′ ) accurately and, in particular, for obtaining tight bounds for compositions. Definition 2.5 (Zhu et al. 2022) . A pair of distributions (P, Q) is a dominating pair of distributions for mechanism M : Z → R if for all neighboring datasets Z and Z ′ and for all α > 0, H α (M(Z)||M(Z ′ )) ≤ H α (P ||Q).
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext dd6273a0-6d70-4fd1-9ff7-1cf6afcb2dc6Cited by top-tier papers9
- Privacy-Preserving Instructions for Aligning Large Language ModelsDa Yu, Peter Kairouz, Sewoong Oh, Zheng XuICML 2024 · 41 citations
- Purifying Approximate Differential Privacy with Randomized Post-processingYingyu Lin, Erchi Wang, Yian Ma, Yu-Xiang WangNeurIPS 2025 · 4 citations
- Tractable MCMC for Private Learning with Pure and Gaussian Differential PrivacyYingyu Lin, Yian Ma, Yu-Xiang Wang, Rachel Redberg et al.ICLR 2024 · 4 citations
- Convex Approximation of Two-Layer ReLU Networks for Hidden State Differential PrivacyRob Romijnders, Antti KoskelaNeurIPS 2025 · 2 citations
- Differentially Private Two-Stage Gradient Descent for Instrumental Variable RegressionHaodong Liang, Yanhao Jin, Krishna Balasubramanian, Lifeng LaiICLR 2026
Builds on9
- Deep Learning with Differential PrivacyMartín Abadi, Andy Chu, Ian J. Goodfellow, H. Brendan McMahan et al.CCS 2016 · 7,620 citations
- The Discrete Gaussian for Differential PrivacyClément L. Canonne, Gautam Kamath, Thomas SteinkeNeurIPS 2020 · 355 citations
- Numerical Composition of Differential PrivacySivakanth Gopi, Yin Tat Lee, Lukas WutschitzNeurIPS 2021 · 259 citations
- Practical and Private (Deep) Learning Without Sampling or ShufflingPeter Kairouz, Brendan McMahan, Shuang Song, Om Thakkar et al.ICML 2021 · 239 citations
- Towards Practical Differentially Private Convex OptimizationRoger Iyengar, Joseph P. Near, Dawn Song, Om Thakkar et al.S&P 2019 · 201 citations
Related papers
- Unified Enhancement of Privacy Bounds for Mixture Mechanisms via f-Differential PrivacyChendi Wang, Buxin Su, Jiayuan Ye, Reza Shokri et al.NeurIPS 2023 · 22 citations
- Exploiting Hidden Symmetry to Improve Objective Perturbation for DP Linear Learners with a Nonsmooth L1-NormDu Chen, Geoffrey A. ChuaICLR 2025
- Shifted Interpolation for Differential PrivacyJinho Bok, Weijie J. Su, Jason M. AltschulerICML 2024 · 12 citations
- Oracle Efficient Private Non-Convex OptimizationSeth Neel, Aaron Roth, Giuseppe Vietri, Zhiwei Steven WuICML 2020 · 9 citations
- Differentially Private Stochastic Convex Optimization under a Quantile Loss FunctionDu Chen, Geoffrey A. ChuaICML 2023 · 1 citation
