Correlated Noise Provably Beats Independent Noise for Differentially Private Learning
Christopher A. Choquette-Choo, Krishnamurthy Dj Dvijotham, Krishna Pillutla, Arun Ganesh, Thomas Steinke, Abhradeep Guha Thakurta
Abstract
Differentially private (DP) learning algorithms inject noise into the learning process. While the most common private learning algorithm, DP-SGD, adds independent Gaussian noise in each iteration, recent work on matrix factorization mechanisms has shown empirically that introducing correlations in the noise can greatly improve their utility. We characterize the asymptotic learning utility for any choice of the correlation function, giving precise analytical bounds for linear regression and as the solution to a convex program for general convex functions. We show, using these bounds, how correlated noise provably improves upon vanilla DP-SGD as a function of problem parameters such as the effective dimension and condition number. Moreover, our analytical expression for the near-optimal correlation function circumvents the cubic complexity of the semi-definite program used to optimize the noise correlation matrix in previous work. We validate our theory with experiments on private deep learning. Our work matches or outperforms prior work while being efficient both in terms of compute and memory.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext ea6c9fd4-ac7f-410e-9d55-2abd76fbcd81Cited by top-tier papers19
- Differentially Private Image Classification by Learning Priors from Random ProcessesXinyu Tang, Ashwinee Panda, Vikash Sehwag, Prateek MittalNeurIPS 2023 · 34 citations
- Banded Square Root Matrix Factorization for Differentially Private Model TrainingNikita P. Kalinin, Christoph H. LampertNeurIPS 2024 · 18 citations
- User Inference Attacks on Large Language ModelsNikhil Kandpal, Krishna Pillutla, Alina Oprea, Peter Kairouz et al.EMNLP 2024 · 14 citations
- Shifted Interpolation for Differential PrivacyJinho Bok, Weijie J. Su, Jason M. AltschulerICML 2024 · 12 citations
- Label Robust and Differentially Private Linear Regression: Computational and Statistical EfficiencyXiyang Liu, Prateek Jain, Weihao Kong, Sewoong Oh et al.NeurIPS 2023 · 10 citations
Builds on15
- Deep Learning with Differential PrivacyMartín Abadi, Andy Chu, Ian J. Goodfellow, H. Brendan McMahan et al.CCS 2016 · 7,620 citations
- Extracting Training Data from Large Language ModelsNicholas Carlini, Florian Tramèr, Eric Wallace, Matthew Jagielski et al.USENIX Security 2021 · 2,866 citations
- Adaptive Federated OptimizationSashank J. Reddi, Zachary Charles, Manzil Zaheer, Zachary Garrett et al.ICLR 2021 · 1,917 citations
- The Secret Sharer: Evaluating and Testing Unintended Memorization in Neural NetworksNicholas Carlini, Chang Liu, Úlfar Erlingsson, Jernej Kos et al.USENIX Security 2019 · 1,386 citations
- Practical and Private (Deep) Learning Without Sampling or ShufflingPeter Kairouz, Brendan McMahan, Shuang Song, Om Thakkar et al.ICML 2021 · 239 citations
Related papers
- Gradient Descent with Linearly Correlated Noise: Theory and Applications to Differential PrivacyAnastasia Koloskova, Ryan McKenna, Zachary Charles, John Keith Rush et al.NeurIPS 2023 · 24 citations
- Privacy Amplification for Matrix MechanismsChristopher A. Choquette-Choo, Arun Ganesh, Thomas Steinke, Abhradeep Guha ThakurtaICLR 2024 · 18 citations
- Scaling up the Banded Matrix Factorization Mechanism for Large Scale Differentially Private MLRyan McKennaICLR 2025
- Near-Exact Privacy Amplification for Matrix MechanismsChristopher A. Choquette-Choo, Arun Ganesh, Saminul Haque, Thomas Steinke et al.ICLR 2025
- Understanding Private Learning From Feature PerspectiveMeng Ding, Mingxi Lei, Shaopeng Fu, Shaowei Wang et al.ICML 2026 · 2 citations
