Geometry of Sensitivity: Twice Sampling and Hybrid Clipping in Differential Privacy with Optimal Gaussian Noise and Application to Deep Learning
Hanshen Xiao, Jun Wan, Srinivas Devadas
摘要
We study the fundamental problem of the construction of optimal randomization in Differential Privacy (DP). Depending on the clipping strategy or additional properties of the processing function, the corresponding sensitivity set theoretically determines the necessary randomization to produce the required security parameters. Towards the optimal utility-privacy tradeoff, finding the minimal perturbation for properly-selected sensitivity sets stands as a central problem in DP research. In practice, 𝑙 2 /𝑙 1 -norm clippings with Gaussian/Laplace noise mechanisms are among the most common setups. However, they also suffer from the curse of dimensionality. For more generic clipping strategies, the understanding of the optimal noise for a high-dimensional sensitivity set remains limited. This raises challenges in mitigating the worst-case dimension dependence in privacy-preserving randomization, especially for deep learning applications. In this paper, we revisit the geometry of high-dimensional sensitivity sets and present a series of results to characterize the nonasymptotically optimal Gaussian noise for Rényi DP (RDP). Our results are both negative and positive: on one hand, we show the curse of dimensionality is tight for a broad class of sensitivity sets satisfying certain symmetry properties; but if, fortunately, the representation of the sensitivity set is asymmetric on some group of orthogonal bases, we show the optimal noise bounds need not be explicitly dependent on either dimension or rank. We also revisit sampling in the high-dimensional scenario, which is the key for both privacy amplification and computation efficiency in largescale data processing. We propose a novel method, termed twice sampling, which implements both sample-wise and coordinate-wise sampling, to enable Gaussian noises to fit the sensitivity geometry more closely. With closed-form RDP analysis, we prove twice sampling produces asymptotic improvement of the privacy amplification given an additional 𝑙 ∞ -norm restriction, especially for small sampling rate. We also provide concrete applications of our results on practical tasks. Through tighter privacy analysis combined with twice sampling, we efficiently train ResNet22 in low sampling rate on CIFAR10, and achieve 69.7% and 81.6% test accuracy with (𝜖 = 2, 𝛿 = 10 -5 ) and (𝜖 = 8, 𝛿 = 10 -5 ) DP guarantee, respectively.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper5
- Formal Privacy Proof of Data Encoding: The Possibility and Impossibility of Learnable EncryptionHanshen Xiao, G. Edward Suh, Srinivas DevadasCCS 2024 · 被引用 2 次
- Trustworthy Machine Learning through Data-Specific IndistinguishabilityHanshen Xiao, Zhen Yang, G. Edward SuhICML 2025
- Unlocking the Power of Differentially Private Zeroth-order Optimization for Fine-tuning LLMsErgute Bao, Yangfan Jiang, Fei Wei, Xiaokui Xiao 等USENIX Security 2025
- One-Sided Bounded Noise: Theory, Optimization Algorithms and ApplicationsHanshen Xiao, Jun Wan, Elaine Shi, Srinivas DevadasCCS 2025
- Sliced Rényi Pufferfish Privacy: Tractable Privatization Mechanism and Private Learning with Gradient ClippingTao Zhang, Yevgeniy VorobeychikUSENIX Security 2026
它引用的顶会 Paper6
- Deep Learning with Differential PrivacyMartín Abadi, Andy Chu, Ian J. Goodfellow, H. Brendan McMahan 等CCS 2016 · 被引用 7,620 次
- Large Scale Private Learning via Low-rank ReparametrizationDa Yu, Huishuai Zhang, Wei Chen, Jian Yin 等ICML 2021 · 被引用 122 次
- Bypassing the Ambient Dimension: Private SGD with Gradient Subspace IdentificationYingxue Zhou, Steven Wu, Arindam BanerjeeICLR 2021 · 被引用 118 次
- When Does Differentially Private Learning Not Suffer in High Dimensions?Xuechen Li, Daogao Liu, Tatsunori B. Hashimoto, Huseyin A. Inan 等NeurIPS 2022 · 被引用 64 次
- A Theory to Instruct Differentially-Private Learning via Clipping Bias ReductionHanshen Xiao, Zihang Xiang, Di Wang, Srinivas DevadasS&P 2023
相关 Paper
- Privacy Loss of Noise Perturbation via Concentration Analysis of A Product MeasureShuainan Liu, Tianxi Ji, Zhongshuo Fang, Lu Wei 等SIGMOD 2026 · 被引用 2 次
- Analyzing and Optimizing Perturbation of DP-SGD GeometricallyJiawei Duan, Haibo Hu, Qingqing Ye, Xinyue SunICDE 2025 · 被引用 3 次
- The Adverse Effects of Omitting Records in Differential Privacy: How Sampling and Suppression Degrade the Privacy–Utility TradeoffÀlex Miranda-Pascual, Javier Parra-Arnau, Thorsten StrufeUSENIX Security 2026
- Approximate Differential Privacy of the ℓ2 MechanismMatthew Joseph, Alex Kulesza, Alexander YuICML 2025
- A Central Limit Theorem for Differentially Private Query AnsweringJinshuo Dong, Weijie J. Su, Linjun ZhangNeurIPS 2021 · 被引用 21 次
