On the Convergence and Calibration of Deep Learning with Differential Privacy
Zhiqi Bu Affiliation: University of Pennsylvania Hua Wang Affiliation: University of Pennsylvania Zongyu Dai Affiliation: University of Pennsylvania Qi Long Affiliation: University of Pennsylvania
Abstract
Differentially private (DP) training preserves the data privacy usually at the cost of slower convergence (and thus lower accuracy), as well as more severe mis-calibration than its non-private counterpart. To analyze the convergence of DP training, we formulate a continuous time analysis through the lens of neural tangent kernel (NTK), which characterizes the per-sample gradient clipping and the noise addition in DP training, for arbitrary network architectures and loss functions. Interestingly, we show that the noise addition only affects the privacy risk but not the convergence or calibration, whereas the per-sample gradient clipping (under both flat and layerwise clipping styles) only affects the convergence and calibration.
原文 arXiv:2106.07830;中英对照 + 大白话阅读 https://aha.fim.ai/paper/2106.07830v6