首页    期刊浏览 2024年12月01日 星期日
登录注册

文章基本信息

  • 标题:Scaling up Differentially Private Deep Learning with Fast Per-Example Gradient Clipping
  • 本地全文:下载
  • 作者:Jaewoo Lee ; Daniel Kifer
  • 期刊名称:Proceedings on Privacy Enhancing Technologies
  • 电子版ISSN:2299-0984
  • 出版年度:2021
  • 卷号:2021
  • 期号:1
  • 页码:128-144
  • DOI:10.2478/popets-2021-0008
  • 语种:English
  • 出版社:Sciendo
  • 摘要:Recent work on Renyi Differential Privacy has shown the feasibility of applying differential privacy to deep learning tasks. Despite their promise,however, differentially private deep networks often lag far behind their non-private counterparts in accuracy,showing the need for more research in model architectures, optimizers,etc. One of the barriers to this expanded research is the training time — often orders of magnitude larger than training non-private networks. The reason for this slowdown is a crucial privacy-related step called “per-example gradient clipping” whose naive implementation undoes the benefits of batch training with GPUs. By analyzing the back-propagation equations we derive new methods for per-example gradient clipping that are compatible with auto-differeniation (e.g.,in PyTorch and TensorFlow) and provide better GPU utilization. Our implementation in PyTorch showed significant training speed-ups (by factors of 54x - 94x for training various models with batch sizes of 128). These techniques work for a variety of architectural choices including convolutional layers,recurrent networks,attention, residual blocks,etc.
  • 关键词:Differential privacy;Deep learning;Gradient clipping;Gradient perturbation
国家哲学社会科学文献中心版权所有