Pith. sign in

REVIEW 1 cited by

Scalable DP-SGD: Shuffling vs. Poisson Subsampling

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv 2411.04205 v1 pith:LEOKEU2H submitted 2024-11-06 cs.LG cs.CRcs.DS

classification cs.LGcs.CRcs.DS
keywords dp-sgdpoissonprivacysubsamplingablqmodelsshufflingutility
verification ladder T0 review T1 audit T2 compute T3 formal

Signed reviews

No signed human review yet.

0 comments
read the original abstract

We provide new lower bounds on the privacy guarantee of the multi-epoch Adaptive Batch Linear Queries (ABLQ) mechanism with shuffled batch sampling, demonstrating substantial gaps when compared to Poisson subsampling; prior analysis was limited to a single epoch. Since the privacy analysis of Differentially Private Stochastic Gradient Descent (DP-SGD) is obtained by analyzing the ABLQ mechanism, this brings into serious question the common practice of implementing shuffling-based DP-SGD, but reporting privacy parameters as if Poisson subsampling was used. To understand the impact of this gap on the utility of trained machine learning models, we introduce a practical approach to implement Poisson subsampling at scale using massively parallel computation, and efficiently train models with the same. We compare the utility of models trained with Poisson-subsampling-based DP-SGD, and the optimistic estimates of utility when using shuffling, via our new lower bounds on the privacy guarantee of ABLQ with shuffling.

Discussion (0). Continue with ORCID to comment.

Forward citations

Cited by 1 Pith paper

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score. Full citation record

  1. Private Rate-Constrained Optimization with Applications to Fair Learning

    cs.LG 2025-05 conditional novelty 7.0 of 10

    RaCO-DP is a differentially private SGDA algorithm that enforces arbitrary prediction-rate constraints, such as group fairness and false negative rate limits, using a private histogram per mini-batch while retaining n...

Pith tools