AIセキュリティポータル K Program
Revisiting Differentially Private Hyper-parameter Tuning
Share
Abstract
We study the application of differential privacy in hyper-parameter tuning, a crucial process in machine learning involving selecting the best hyper-parameter from several candidates. Unlike many private learning algorithms, including the prevalent DP-SGD, the privacy implications of tuning remain insufficiently understood or often totally ignored. Recent works propose a generic private selection solution for the tuning process, yet a fundamental question persists: is this privacy bound tight? This paper provides an in-depth examination of this question. Initially, we provide studies affirming the current privacy analysis for private selection is indeed tight in general. However, when we specifically study the hyper-parameter tuning problem in a white-box setting, such tightness no longer holds. This is first demonstrated by applying privacy audit on the tuning process. Our findings underscore a substantial gap between current theoretical privacy bound and the empirical bound derived even under strong audit setups. This gap motivates our subsequent investigations. Our further study provides improved privacy results for private hyper-parameter tuning due to its distinct properties. Our results demonstrate broader applicability compared to prior analyses, which are limited to specific parameter configurations.
Deep learning with differential privacy
Martin Abadi, Andy Chu, Ian Goodfellow, H Brendan McMahan, Ilya Mironov, Kunal Talwar, Li Zhang
Published: 2016
"what do you want from theory alone?" experimenting with tight auditing of differentially private synthetic data generation
Meenatchi Sundaram Muthu Selva Annamalai, Georgi Ganev, Emiliano De Cristofaro
Published: 2024
Improving the gaussian mechanism for differential privacy: Analytical calibration and optimal denoising
Borja Balle, Yu-Xiang Wang
Published: 2018
Private empirical risk minimization: Efficient algorithms and tight error bounds
R. Bassily, A. Smith, A. Thakurta
Published: 2014
Dp-finder: Finding differential privacy violations by sampling and optimization
Benjamin Bichsel, Timon Gehr, Dana Drachsler-Cohen, Petar Tsankov, Martin Vechev
Published: 2018
Dp-sniper: Black-box discovery of differential privacy violations using classifiers
Benjamin Bichsel, Samuel Steffen, Ilija Bogunovic, Martin Vechev
Published: 2021
A stability-based validation procedure for differentially private machine learning
K. Chaudhuri, S. A. Vinterbo
Published: 2013
The use of confidence or fiducial limits illustrated in the case of the binomial
C. J. Clopper, E. S. Pearson
Published: 1934
Elements of information theory (2. ed.)
Thomas M. Cover, Joy A. Thomas
Published: 2006
Differential privacy as a mutual information constraint
Paul Cuff, Lanqing Yu
Published: 2016
Order statistics
Herbert A David, Haikady N Nagaraja
Published: 2004
Unlocking High-Accuracy Differentially Private Image Classification through Scale
Soham De, Leonard Berrada, Jamie Hayes, Samuel L. Smith, Borja Balle
Published: 2022.4.29
Detecting violations of differential privacy
Zeyu Ding, Yuxin Wang, Guanhong Wang, Danfeng Zhang, Daniel Kifer
Published: 2018
Gaussian differential privacy
Jinshuo Dong, Aaron Roth, Weijie Su
Published: 2021
Calibrating noise to sensitivity in private data analysis
Cynthia Dwork, Frank McSherry, Kobbi Nissim, Adam Smith
Published: 2006
On the complexity of differentially private data release: efficient algorithms and hardness results
Cynthia Dwork, Moni Naor, Omer Reingold, Guy N. Rothblum, Salil P. Vadhan
Published: 2009
On the mathematical foundations of theoretical statistics
Ronald A Fisher
Published: 1922
Deep residual learning for image recognition
Kaiming He, Xiangyu Zhang, Shaoqing Ren, Jian Sun
Published: 2016
The composition theorem for differential privacy
Peter Kairouz, Sewoong Oh, Pramod Viswanath
Published: 2015
Learning multiple layers of features from tiny images
Alex Krizhevsky, Geoffrey Hinton
Published: 2009
Imagenet classification with deep convolutional neural networks
A. Krizhevsky, I. Sutskever, G. E. Hinton
Published: 2017
Gradient-based learning applied to document recognition
Y. LeCun, L. Bottou, Y. Bengio, P. Haffner
Published: 1998
Membership privacy: A unifying framework for privacy definitions
Li, N., Qardaji, W., Su, D., Wu, Y., Yang, W.
Published: 2013
Mechanism design via differential privacy
Frank McSherry, Kunal Talwar
Published: 2007
Rényi differential privacy
Ilya Mironov
Published: 2017
Rényi differential privacy
Ilya Mironov
Published: 2017
Tight auditing of differentially private machine learning
Milad Nasr, Jamie Hayes, Thomas Steinke, Borja Balle, Florian Tramèr, Matthew Jagielski, Nicholas Carlini, Andreas Terzis
Published: 2023
Comprehensive Privacy Analysis of Deep Learning: Passive and Active White-box Inference Attacks against Centralized and Federated Learning
Milad Nasr, Reza Shokri, Amir Houmansadr
Published: 2018.12.4
Adversary instantiation: Lower bounds for differentially private machine learning
Milad Nasr, Shuang Songi, Abhradeep Thakurta, Nicolas Papernot, Nicholas Carlini
Published: 2021
Reading digits in natural images with unsupervised feature learning
Yuval Netzer, Tao Wang, Adam Coates, Alessandro Bissacco, Bo Wu, Andrew Y Ng
Published: 2011
Ix. on the problem of the most efficient tests of statistical hypotheses
Jerzy Neyman, Egon Sharpe Pearson
Published: 1933
Enhanced Membership Inference Attacks against Machine Learning Models
Jiayuan Ye, Aadyaa Maddi, Sasi Kumar Murakonda, Vincent Bindschaedler, Reza Shokri
Published: 2021.11.18
Stochastic gradient descent with differentially private updates
S. Song, K. Chaudhuri, A. D. Sarwate
Published: 2013
Privacy auditing with one (1) training run
Thomas Steinke, Milad Nasr, Matthew Jagielski
Published: 2023
Sok: Differential privacy as a causal property
Michael Carl Tschantz, Shayak Sen, Anupam Datta
Published: 2020
Rényi Divergence and Kullback-Leibler Divergence
T. V. Erven, P. Harremoës
Published: 2014
Attention is all you need
Ashish Vaswani, Noam Shazeer, Niki Parmar, Jakob Uszkoreit, Llion Jones, Aidan N Gomez, Łukasz Kaiser, Illia Polosukhin
Published: 2017
Checkdp: An automated and integrated approach for proving differential privacy or finding precise counterexamples
Yuxin Wang, Zeyu Ding, Daniel Kifer, Danfeng Zhang
Published: 2020
A statistical framework for differential privacy
Larry Wasserman, Shuheng Zhou
Published: 2010
Fashion-mnist: a novel image dataset for benchmarking machine learning algorithms
H. Xiao, K. Rasul, R. Vollgraf
Published: 2017
A theory to instruct differentially-private learning via clipping bias reduction
Hanshen Xiao, Zihang Xiang, Di Wang, Srinivas Devadas
Published: 2023
Bayesian estimation of differential privacy
Santiago Zanella-Béguelin, Lukas Wutschitz, Shruti Tople, Ahmed Salem, Victor Rühle, Andrew Paverd, Mohammad Naseri, Boris Köpf, Daniel Jones
Published: 2023
Share