Leveraging Randomness in Model and Data Partitioning for Privacy Amplification
Andy Dong, Wei-Ning Chen, Ayfer Özgür
摘要
We study how inherent randomness in the training process-where each sample (or client in federated learning) contributes to only a randomly selected portion of training-can be leveraged for privacy amplification. This includes (1) model partitioning, where a sample updates only a subset of the model parameters, and (2) data partitioning, where a sample participates in only a subset of training iterations. We apply our framework to model parallelism in federated learning, where each client updates a randomly selected subnetwork to reduce memory and computational overhead, and show that existing methods, e.g. model splitting or dropout, provide a significant privacy amplification gain not captured by previous privacy analysis techniques. Additionally, we introduce Balanced Iteration Subsampling, a new data partitioning method where each sample (or client) participates in a fixed number of training iterations. We show that this method yields similar or stronger privacy amplification than Poisson (i.i.d.) sampling of data (or clients). Our results demonstrate that randomness in the training process, which is structured rather than i.i.d. and interacts with data in complex ways, can be systematically leveraged for significant privacy amplification.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper4
- Privacy amplification by random allocationMoshe Shenfeld, Vitaly FeldmanNeurIPS 2025 · 被引用 18 次
- Efficient privacy loss accounting for subsampling and random allocationVitaly Feldman, Moshe ShenfeldICML 2026 · 被引用 5 次
- Fundamental Limitations of Favorable Privacy–Utility Guarantees for DP-SGDMurat Bilgehan Ertan), Marten van Dijk)CCS 2026 · 被引用 3 次
- PREAMBLE: Private and Efficient Aggregation via Block Sparse VectorsHilal Asi, Vitaly Feldman, Hannah Keller, Guy N. Rothblum 等NeurIPS 2025 · 被引用 1 次
它引用的顶会 Paper8
- Deep Learning with Differential PrivacyMartín Abadi, Andy Chu, Ian J. Goodfellow, H. Brendan McMahan 等CCS 2016 · 被引用 7,620 次
- The Discrete Gaussian for Differential PrivacyClément L. Canonne, Gautam Kamath, Thomas SteinkeNeurIPS 2020 · 被引用 355 次
- Privacy Amplification via Random Check-InsBorja Balle, Peter Kairouz, Brendan McMahan, Om Dipakbhai Thakkar 等NeurIPS 2020 · 被引用 86 次
- Hiding Among the Clones: A Simple and Nearly Optimal Analysis of Privacy Amplification by ShufflingVitaly Feldman, Audra McMillan, Kunal TalwarFOCS 2021 · 被引用 76 次
- Privacy Amplification via Compression: Achieving the Optimal Privacy-Accuracy-Communication Trade-off in Distributed Mean EstimationWei-Ning Chen, Dan Song, Ayfer Özgür, Peter KairouzNeurIPS 2023 · 被引用 42 次
相关 Paper
- Renyi Differential Privacy of The Subsampled Shuffle Model In Distributed LearningAntonious M. Girgis, Deepesh Data, Suhas N. DiggaviNeurIPS 2021 · 被引用 28 次
- FLAME: Differentially Private Federated Learning in the Shuffle ModelRuixuan Liu, Yang Cao, Hong Chen, Ruoyang Guo 等AAAI 2021 · 被引用 117 次
- Clustered Sampling: Low-Variance and Improved Representativity for Clients Selection in Federated LearningYann Fraboni, Richard Vidal, Laetitia Kameni, Marco LorenziICML 2021 · 被引用 249 次
- Echo of Neighbors: Privacy Amplification for Personalized Private Federated Learning with Shuffle ModelYixuan Liu, Suyun Zhao, Li Xiong, Yuhan Liu 等AAAI 2023 · 被引用 18 次
- Practical and Private (Deep) Learning Without Sampling or ShufflingPeter Kairouz, Brendan McMahan, Shuang Song, Om Thakkar 等ICML 2021 · 被引用 239 次
