Pith. sign in

REVIEW 4 cited by

Large Scale Transfer Learning for Differentially Private Image Classification

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv 2205.02973 v2 pith:Z5GNBTCY submitted 2022-05-06 cs.LG cs.CRcs.CV

classification cs.LGcs.CRcs.CV
keywords modelsnon-privateprivatetrainingdp-sgdlargelearningprivacy
verification ladder T0 review T1 audit T2 compute T3 formal
0 comments
abstract

Differential Privacy (DP) provides a formal framework for training machine learning models with individual example level privacy. In the field of deep learning, Differentially Private Stochastic Gradient Descent (DP-SGD) has emerged as a popular private training algorithm. Unfortunately, the computational cost of training large-scale models with DP-SGD is substantially higher than non-private training. This is further exacerbated by the fact that increasing the number of parameters leads to larger degradation in utility with DP. In this work, we zoom in on the ImageNet dataset and demonstrate that, similar to the non-private case, pre-training over-parameterized models on a large public dataset can lead to substantial gains when the model is finetuned privately. Moreover, by systematically comparing private and non-private models across a range of large batch sizes, we find that similar to non-private setting, choice of optimizer can further improve performance substantially with DP. By using LAMB optimizer with DP-SGD we saw improvement of up to 20$\%$ points (absolute). Finally, we show that finetuning just the last layer for a \emph{single step} in the full batch setting, combined with extremely small-scale (near-zero) initialization leads to both SOTA results of 81.7 $\%$ under a wide privacy budget range of $\epsilon \in [4, 10]$ and $\delta$ = $10^{-6}$ while minimizing the computational overhead substantially.

Discussion (0). Continue with ORCID to comment.

Forward citations

Cited by 4 Pith papers

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score. Full citation record

  1. StraightDP: Geometry-Aware Differential Privacy for Rectified-Flow Transformers

    cs.LG 2026-07 conditional novelty 6.0 of 10

    StraightDP releases a few DP class-conditioned moments to define the noise-end velocity of a rectified flow, then uses DP-SGD only on the sample-specific part, improving strong-privacy generation accuracy.

  2. Lower Bounds for Public-Private Learning under Distribution Shift

    cs.LG 2025-07 reject novelty 6.0 of 10

    For Gaussian mean estimation and linear regression with distribution shift, the paper claims that public data never provides complementary value: either public data alone suffices, or (for large shifts) private data a...

  3. Deeper Inside Deep ViT

    cs.CV 2025-08 conditional novelty 5.0 of 10

    Small-scale ViT-22B models outperform standard ViT under matched parameter counts on CIFAR, and a proposed ViTUnet runs image-to-image translation, though without strong quantitative validation.

  4. Survey of different Large Language Model Architectures: Trends, Benchmarks, and Challenges

    cs.LG 2024-12 conditional

    A broad but error-prone survey of LLM and MLLM architectures, training methods, benchmarks, and challenges.

Pith tools