Neural Collapse meets Differential Privacy: Curious behaviors of NoisyGD with Near-Perfect Representation Learning
Chendi Wang, Yuqing Zhu, Weijie J. Su, Yu-Xiang Wang
摘要
A recent study by De et al. (2022) has reported that large-scale representation learning through pre-training on a public dataset significantly enhances differentially private (DP) learning in downstream tasks, despite the high dimensionality of the feature space. To theoretically explain this phenomenon, we consider the setting of a layer-peeled model in representation learning, which results in interesting phenomena related to learned features in deep learning and transfer learning, known as Neural Collapse (NC). Within the framework of NC, we establish an error bound indicating that the misclassification error is independent of dimension when the distance between actual features and the ideal ones is smaller than a threshold. Additionally, the quality of the features in the last layer is empirically evaluated under different pre-trained models within the framework of NC, showing that a more powerful transformer leads to a better feature representation. Furthermore, we reveal that DP fine-tuning is less robust compared to fine-tuning without DP, particularly in the presence of perturbations. These observations are supported by both theoretical analyses and experimental evaluation. Moreover, to enhance the robustness of DP fine-tuning, we suggest several strategies, such as feature normalization or employing dimension reduction methods like Principal Component Analysis (PCA). Empirically, we demonstrate a significant improvement in testing accuracy by conducting PCA on the last-layer features.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper7
- Linguistic Collapse: Neural Collapse in (Large) Language ModelsRobert Wu, Vardan PapyanNeurIPS 2024 · 被引用 45 次
- Mitigating the Privacy-Utility Trade-off in Decentralized Federated Learning via f-Differential PrivacyXiang Li, Chendi Wang, Buxin Su, Qi Long 等NeurIPS 2025 · 被引用 4 次
- Understanding Private Learning From Feature PerspectiveMeng Ding, Mingxi Lei, Shaopeng Fu, Shaowei Wang 等ICML 2026 · 被引用 2 次
- On Optimal Hyperparameters for Differentially Private Deep Transfer LearningAki Rehn, Linzh Zhao, Mikko A. Heikkilä, Antti HonkelaICLR 2026 · 被引用 2 次
- Adapting to Linear Separable Subsets with Large-Margin in Differentially Private LearningErchi Wang, Yuqing Zhu, Yu-Xiang WangICML 2025
它引用的顶会 Paper21
- Denoising Diffusion Probabilistic ModelsJonathan Ho, Ajay Jain, Pieter AbbeelNeurIPS 2020 · 被引用 35,902 次
- An Image is Worth 16x16 Words: Transformers for Image Recognition at ScaleAlexey Dosovitskiy, Lucas Beyer, Alexander Kolesnikov, Dirk Weissenborn 等ICLR 2021 · 被引用 21,477 次
- Deep Learning with Differential PrivacyMartín Abadi, Andy Chu, Ian J. Goodfellow, H. Brendan McMahan 等CCS 2016 · 被引用 7,620 次
- Large Language Models Can Be Strong Differentially Private LearnersXuechen Li, Florian Tramèr, Percy Liang, Tatsunori HashimotoICLR 2022 · 被引用 502 次
- Differentially Private Fine-tuning of Language ModelsDa Yu, Saurabh Naik, Arturs Backurs, Sivakanth Gopi 等ICLR 2022 · 被引用 494 次
相关 Paper
- The Impact of Geometric Complexity on Neural Collapse in Transfer LearningMichael Munn, Benoit Dherin, Javier GonzalvoNeurIPS 2024 · 被引用 6 次
- On the Benefits of Public Representations for Private Transfer Learning under Distribution ShiftPratiksha Thaker, Amrith Setlur, Steven Z. Wu, Virginia SmithNeurIPS 2024 · 被引用 7 次
- On Transfer of Adversarial Robustness from Pretraining to Downstream TasksLaura Fee Nern, Harsh Raj, Maurice André Georgi, Yash SharmaNeurIPS 2023 · 被引用 9 次
- Memorization-Dilation: Modeling Neural Collapse Under NoiseDuc Anh Nguyen, Ron Levie, Julian Lienen, Eyke Hüllermeier 等ICLR 2023 · 被引用 1 次
- When Does Differentially Private Learning Not Suffer in High Dimensions?Xuechen Li, Daogao Liu, Tatsunori B. Hashimoto, Huseyin A. Inan 等NeurIPS 2022 · 被引用 64 次
