Removing Disparate Impact on Model Accuracy in Differentially Private Stochastic Gradient Descent
Depeng Xu, Wei Du, Xintao Wu
摘要
In differentially private stochastic gradient descent (DPSGD), gradient clipping and random noise addition disproportionately affect underrepresented and complex classes and subgroups. As a consequence, DPSGD has disparate impact: the accuracy of a model trained using DPSGD tends to decrease more on these classes and subgroups vs. the original, non-private model. If the original model is unfair in the sense that its accuracy is not the same across all subgroups, DPSGD exacerbates this unfairness. In this work, we study the inequality in utility loss due to differential privacy, which compares the changes in prediction accuracy w.r.t. each group between the private model and the non-private model. We analyze the cost of privacy w.r.t. each group and explain how the group sample size along with other factors is related to the privacy impact on group accuracy. Furthermore, we propose a modified DPSGD algorithm, called DPSGD-F, to achieve differential privacy, equal costs of differential privacy, and good utility. DPSGD-F adaptively adjusts the contribution of samples in a group depending on the group clipping bias such that differential privacy has no disparate impact on group accuracy. Our experimental evaluation shows the effectiveness of our removal algorithm on achieving equal costs of differential privacy with satisfactory utility.
问问这篇 Paper
问问你的智能体。
Lune 读过与它相关的顶会 Paper,每个回答都会注明依据哪几篇。
引用它的顶会 Paper5
- Functional Renyi Differential Privacy for Generative ModelingDihong Jiang, Sun Sun, Yaoliang YuNeurIPS 2023 · 被引用 17 次
- What You See is What You Get: Principled Deep Learning via Distributional GeneralizationBogdan Kulynych, Yao-Yuan Yang, Yaodong Yu, Jaroslaw Blasiok 等NeurIPS 2022 · 被引用 13 次
- Multi-Task Differential Privacy Under Distribution SkewWalid Krichene, Prateek Jain, Shuang Song, Mukund Sundararajan 等ICML 2023 · 被引用 3 次
- PrivateFL: Accurate, Differentially Private Federated Learning via Personalized Data TransformationYuchen Yang, Bo Hui, Haolin Yuan, Neil Zhenqiang Gong 等USENIX Security 2023
- INO-SGD: Addressing Utility Imbalance under Individualized Differential PrivacyXiao Tian, Jue Fan, Rachael Hwee Ling Sim, Bryan Kian Hsiang LowICLR 2026
相关 Paper
- Disparate Impact in Differential Privacy from Gradient MisalignmentMaria S. Esipova, Atiyeh Ashari Ghomi, Yaqiao Luo, Jesse C. CresswellICLR 2023 · 被引用 7 次
- Differentially Private Empirical Risk Minimization under the Fairness LensCuong Tran, My H. Dinh, Ferdinando FiorettoNeurIPS 2021 · 被引用 61 次
- Robin Hood and Matthew Effects: Differential Privacy Has Disparate Impact on Synthetic DataGeorgi Ganev, Bristena Oprisanu, Emiliano De CristofaroICML 2022 · 被引用 78 次
- Improved Convergence of Differential Private SGD with Gradient ClippingHuang Fang, Xiaoyun Li, Chenglin Fan, Ping LiICLR 2023
- Differentially Private SGD Without Clipping Bias: An Error-Feedback ApproachXinwei Zhang, Zhiqi Bu, Steven Wu, Mingyi HongICLR 2024 · 被引用 15 次
