Évènements passés
lun
mar
mer
jeu
ven
sam
dim
l
m
m
j
v
s
d
25
26
27
28
29
30
1
3
4
5
6
7
8
10
11
2:00 PM - Multi task averaging in high dimension
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
1
2
3
4
5
Room 02.124, Building 5, St Priest campus
Machine Learning in Montpellier, Theory & Practice
In this talk, we introduce privacy auditing and explore the privacy guarantees of machine learning models trained with Differentially Private Stochastic Gradient Descent (DP-SGD), focusing on the hidden state threat model, in which an adversary only has access to the final training model. We employ simple adversaries for privacy auditing models in the hidden state, outperforming previous methods. We show that if a user contributes to each DP-SGD step, releasing only the final model does not amplify privacy, compared to the standard case where all intermediary models are released. The problem is more complex when the crafted gradient is not inserted at every step: our auditing lower bound matches the privacy upper bound only for an adversarially-chosen loss landscape and a sufficiently large batch size. This suggests that existing privacy upper bounds can be improved in certain regimes
Machine Learning in Montpellier, Theory & Practice
Room 02.124, Building 5, St Priest campus
Machine Learning in Montpellier, Theory & Practice
In this talk, we present some technical details of privacy accounting for differentially private mechanisms. We focus on privacy accounting for Differentially Private Stochastic Gradient Descent (DP-SGD). First, we introduce various techniques used to analyze the privacy guarantees of DP-SGD. Then, we discuss two different batch generation methods. Most privacy accounting techniques assume that batches for DP-SGD are generated using Poisson subsampling. However, Poisson subsampling is often not feasible in practice when training models on large datasets. We can instead implement a different technique such as sampling without replacement. The choice of sampling scheme has typically been regarded as a minor technical detail. We demonstrate that the sampling scheme significantly impacts the privacy guarantees for some (realistic) DP-SGD hyperparameters.
Machine Learning in Montpellier, Theory & Practice
Room 02.124, Building 5, St Priest campus
Machine Learning in Montpellier, Theory & Practice
Machine Learning in Montpellier, Theory & Practice
Room 02.124, Building 5, St Priest campus
Machine Learning in Montpellier, Theory & Practice
,,
Machine Learning in Montpellier, Theory & Practice