Sharpness-Aware Initialization: Improving Differentially Private Machine Learning from First Principles
Zihao Wang, Rui Zhu, Dongruo Zhou, Zhikun Zhang, XiaoFeng Wang, Haixu Tang
摘要
Recent advances in privacy-preserving machine learning underscore the critical role of differential privacy (DP) in protecting individual data. However, the noise introduced during DP training often leads to significant performance degradation, creating a major challenge for differentially private machine learning (DPML).
In this work, we address this challenge by controlling the detrimental effects of DP noise. Specifically, we focus on enhancing a model's robustness to random perturbations, thereby mitigating their negative impact on convergence-a central factor in maintaining high utility under DP. To this end, we propose sharpness-aware initialization (SAI), a method for improving the accuracy of DPML algorithms by achieving a flatter loss landscape. Our approach employs a two-phase training framework: SAI followed by standard Differentially Private Stochastic Gradient Descent (DPSGD). This strategy capitalizes on the observation that loss-landscape flatness converges more rapidly than the training loss, enabling an early stop on flatness optimization to limit divergence risk, followed by a phase dedicated to training-loss optimization. Moreover, splitting the training into two distinct phases allows for different privacy budgets in each phase, aligning their respective optimization objectives and tolerance to DP noise, which further mitigates performance degradation. Our experimental results show that SAI substantially improves the accuracy of state-of-the-art DPML algorithms across a range of datasets and model architectures, achieving gains of over 6% on CIFAR-10 under ε = 1.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper1
问问它们各自怎么用它它引用的顶会 Paper35
- An Image is Worth 16x16 Words: Transformers for Image Recognition at ScaleAlexey Dosovitskiy, Lucas Beyer, Alexander Kolesnikov, Dirk Weissenborn 等ICLR 2021 · 被引用 21,477 次
- Deep Learning with Differential PrivacyMartín Abadi, Andy Chu, Ian J. Goodfellow, H. Brendan McMahan 等CCS 2016 · 被引用 7,620 次
- Membership Inference Attacks Against Machine Learning ModelsReza Shokri, Marco Stronati, Congzheng Song, Vitaly ShmatikovS&P 2017 · 被引用 5,137 次
- CrossViT: Cross-Attention Multi-Scale Vision Transformer for Image ClassificationChun-Fu (Richard) Chen, Quanfu Fan, Rameswar PandaICCV 2021 · 被引用 2,072 次
- Sharpness-aware Minimization for Efficiently Improving GeneralizationPierre Foret, Ariel Kleiner, Hossein Mobahi, Behnam NeyshaburICLR 2021 · 被引用 1,861 次
相关 Paper
- DPAdapter: Improving Differentially Private Deep Learning through Noise Tolerance Pre-trainingZihao Wang, Rui Zhu, Dongruo Zhou, Zhikun Zhang 等USENIX Security 2024 · 被引用 9 次
- Differentially Private Sharpness-Aware TrainingJinseong Park, Hoki Kim, Yujin Choi, Jaewook LeeICML 2023 · 被引用 15 次
- Make Landscape Flatter in Differentially Private Federated LearningYifan Shi, Yingqi Liu, Kang Wei, Li Shen 等CVPR 2023
- DOPPLER: Differentially Private Optimizers with Low-pass Filter for Privacy Noise ReductionXinwei Zhang, Zhiqi Bu, Mingyi Hong, Meisam RazaviyaynNeurIPS 2024 · 被引用 10 次
- Attack-Aware Noise Calibration for Differential PrivacyBogdan Kulynych, Juan Felipe Gómez, Georgios Kaissis, Flávio P. Calmon 等NeurIPS 2024 · 被引用 23 次
