Pith. sign in

REVIEW 1 cited by

Fine-Tuning with Differential Privacy Necessitates an Additional Hyperparameter Search

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv 2210.02156 v1 pith:62KQZNJC submitted 2022-10-05 cs.LG cs.CR

classification cs.LGcs.CR
keywords privacyfine-tuningaccuracydifferentiallylearningmodelpretrainedprivate
verification ladder T0 review T1 audit T2 compute T3 formal
0 comments
abstract

Models need to be trained with privacy-preserving learning algorithms to prevent leakage of possibly sensitive information contained in their training data. However, canonical algorithms like differentially private stochastic gradient descent (DP-SGD) do not benefit from model scale in the same way as non-private learning. This manifests itself in the form of unappealing tradeoffs between privacy and utility (accuracy) when using DP-SGD on complex tasks. To remediate this tension, a paradigm is emerging: fine-tuning with differential privacy from a model pretrained on public (i.e., non-sensitive) training data. In this work, we identify an oversight of existing approaches for differentially private fine tuning. They do not tailor the fine-tuning approach to the specifics of learning with privacy. Our main result is to show how carefully selecting the layers being fine-tuned in the pretrained neural network allows us to establish new state-of-the-art tradeoffs between privacy and accuracy. For instance, we achieve 77.9% accuracy for $(\varepsilon, \delta)=(2, 10^{-5})$ on CIFAR-100 for a model pretrained on ImageNet. Our work calls for additional hyperparameter search to configure the differentially private fine-tuning procedure itself.

Discussion (0). Continue with ORCID to comment.

Forward citations

Cited by 1 Pith paper

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score. Full citation record

  1. Hyperparameters in Score-Based Membership Inference Attacks

    cs.LG 2025-02 accept novelty 6.0 of 10

    A new shadow-model hyperparameter selection method (KL-LiRA) makes membership inference attacks nearly as effective without knowing target hyperparameters, and training-data-based hyperparameter tuning shows no detect...

Pith tools