Privacy Budget Scheduling
Tao Luo, Mingen Pan, Pierre Tholoniat, Asaf Cidon, Roxana Geambasu, Mathias Lécuyer
摘要
Machine learning (ML) models trained on personal data have been shown to leak information about users. Differential privacy (DP) enables model training with a guaranteed bound on this leakage. Each new model trained with DP increases the bound on data leakage and can be seen as consuming part of a global privacy budget that should not be exceeded. This budget is a scarce resource that must be carefully managed to maximize the number of successfully trained models.
We describe PrivateKube, an extension to the popular Kubernetes datacenter orchestrator that adds privacy as a new type of resource to be managed alongside other traditional compute resources, such as CPU, GPU, and memory. The abstractions we design for the privacy resource mirror those defined by Kubernetes for traditional resources, but there are also major differences. For example, traditional compute resources are replenishable while privacy is not: a CPU can be regained after a model finishes execution while privacy budget cannot. This distinction forces a re-design of the scheduler. We present DPF (Dominant Private Block Fairness) -a variant of the popular Dominant Resource Fairness (DRF) algorithm -that is geared toward the non-replenishable privacy resource but enjoys similar theoretical properties as DRF.
We evaluate PrivateKube and DPF on microbenchmarks and an ML workload on Amazon Reviews data. Compared to existing baselines, DPF allows training more models under the same global privacy guarantee. This is especially true for DPF over Rényi DP, a highly composable form of DP.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了最后一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper17
- FederatedScope: A Flexible Federated Learning Platform for HeterogeneityYuexiang Xie, Zhen Wang, Dawei Gao, Daoyuan Chen 等VLDB 2023 · 被引用 120 次
- Multi-resource interleaving for deep learning trainingYihao Zhao, Yuanqiang Liu, Yanghua Peng, Yibo Zhu 等SIGCOMM 2022 · 被引用 78 次
- Karma: Resource Allocation for Dynamic DemandsMidhul Vuppalapati, Giannis Fikioris, Rachit Agarwal, Asaf Cidon 等OSDI 2023 · 被引用 22 次
- Longshot: Indexing Growing Databases using MPC and Differential PrivacyYanping Zhang, Johes Bater, Kartik Nayak, Ashwin MachanavajjhalaVLDB 2023 · 被引用 19 次
- Privacy as a Resource in Differentially Private Federated LearningJinliang Yuan, Shangguang Wang, Shihe Wang, Yuanchun Li 等INFOCOM 2023 · 被引用 15 次
它引用的顶会 Paper7
- Deep Learning with Differential PrivacyMartín Abadi, Andy Chu, Ian J. Goodfellow, H. Brendan McMahan 等CCS 2016 · 被引用 7,620 次
- Membership Inference Attacks Against Machine Learning ModelsReza Shokri, Marco Stronati, Congzheng Song, Vitaly ShmatikovS&P 2017 · 被引用 5,137 次
- The Secret Sharer: Evaluating and Testing Unintended Memorization in Neural NetworksNicholas Carlini, Chang Liu, Úlfar Erlingsson, Jernej Kos 等USENIX Security 2019 · 被引用 1,386 次
- Evaluating Differentially Private Machine Learning in PracticeBargav Jayaraman, David EvansUSENIX Security 2019 · 被引用 586 次
- Differentially Private Model Publishing for Deep LearningLei Yu, Ling Liu, Calton Pu, Mehmet Emre Gursoy 等S&P 2019 · 被引用 294 次
相关 Paper
- DPack: Efficiency-Oriented Privacy Budget SchedulingPierre Tholoniat, Kelly Kostopoulou, Mosharaf Chowdhury, Asaf Cidon 等EuroSys 2025 · 被引用 5 次
- Privacy Budgeting for Growing Machine Learning DatasetsWeiting Li, Liyao Xiang, Zhou Zhou, Feng PengINFOCOM 2021 · 被引用 14 次
- DPBalance: Efficient and Fair Privacy Budget Scheduling for Federated Learning as a ServiceYu Liu, Zibo Wang, Yifei Zhu, Chen ChenINFOCOM 2024 · 被引用 7 次
- Bringing Differential Privacy to HPC: Privacy-Preserving Transformations of HPC TracesAna Luisa Veroneze Solórzano, Rohan Basu Roy, Benjamin Schwaller, Sara Petra Walton 等HPDC 2025
- DiVa: An Accelerator for Differentially Private Machine LearningBeomsik Park, Ranggi Hwang, Dongho Yoon, Yoonhyuk Choi 等MICRO 2022 · 被引用 12 次
