Skip to main content
QUICK REVIEW

[论文解读] Differentially Private Empirical Risk Minimization with Sparsity-Inducing Norms

K.S. Kumar, Marc Peter Deisenroth|arXiv (Cornell University)|May 13, 2019
Privacy-Preserving Technologies in Data参考文献 21被引用 4
一句话总结

本论文提出了一类使用稀疏性诱导范数的差分隐私经验风险最小化(ERM)算法,聚焦于非光滑正则化器所诱导的结构化稀疏性。论文提出了一种用于对偶ERM问题的私有Frank-Wolfe算法,并推导出依赖于对偶范数单位球的高斯宽度的过剩风险界,建立了原始空间中的目标扰动与对偶空间中的输出扰动之间的等价性。

ABSTRACT

Differential privacy is concerned about the prediction quality while measuring the privacy impact on individuals whose information is contained in the data. We consider differentially private risk minimization problems with regularizers that induce structured sparsity. These regularizers are known to be convex but they are often non-differentiable. We analyze the standard differentially private algorithms, such as output perturbation, Frank-Wolfe and objective perturbation. Output perturbation is a differentially private algorithm that is known to perform well for minimizing risks that are strongly convex. Previous works have derived excess risk bounds that are independent of the dimensionality. In this paper, we assume a particular class of convex but non-smooth regularizers that induce structured sparsity and loss functions for generalized linear models. We also consider differentially private Frank-Wolfe algorithms to optimize the dual of the risk minimization problem. We derive excess risk bounds for both these algorithms. Both the bounds depend on the Gaussian width of the unit ball of the dual norm. We also show that objective perturbation of the risk minimization problems is equivalent to the output perturbation of a dual optimization problem. This is the first work that analyzes the dual optimization problems of risk minimization problems in the context of differential privacy.

研究动机与目标

  • 解决在具有非光滑、结构化稀疏性诱导正则化器的ERM中实现差分隐私的挑战。
  • 分析在非光滑正则化器背景下输出扰动与Frank-Wolfe算法的效用。
  • 提供依赖于对偶范数单位球高斯宽度的理论过剩风险界。
  • 建立原始优化问题中目标扰动与对偶优化问题中输出扰动之间的新颖等价性。
  • 为分析非光滑ERM设置下基于镜像下降与梯度扰动的私有算法开辟道路。

提出的方法

  • 对具有非光滑正则化器的原始ERM问题应用输出扰动,通过向模型参数添加噪声以确保差分隐私。
  • 开发一种用于优化ERM问题对偶的私有Frank-Wolfe算法,利用对偶空间的结构。
  • 通过分析对偶范数单位球的高斯宽度,推导出输出扰动与私有Frank-Wolfe的过剩风险界。
  • 利用Fenchel对偶性将原始空间中的目标扰动重新表述为对偶空间中的输出扰动,证明其等价性。
  • 利用强对偶性与Fenchel共轭,将扰动后的原始问题转化为对偶优化问题。
  • 利用子模函数作为正则化器以诱导结构化稀疏性,从而在对偶空间中使用多面体集。

实验结果

研究问题

  • RQ1如何有效将输出扰动应用于具有非光滑、稀疏性诱导正则化器的ERM问题?
  • RQ2应用于具有结构化稀疏性的ERM问题对偶的私有Frank-Wolfe算法的过剩风险界是什么?
  • RQ3原始ERM问题中的目标扰动能否等价地解释为对偶问题中的输出扰动?
  • RQ4对偶范数单位球的高斯宽度如何影响差分隐私ERM中的过剩风险?
  • RQ5对偶范数的哪些结构性质可被利用以改善具有非光滑正则化器的私有ERM中的效用界?

主要发现

  • 输出扰动的过剩风险界依赖于对偶范数单位球的高斯宽度,提供了与维度无关的效用保障。
  • 用于对偶ERM的私有Frank-Wolfe算法所达到的过剩风险界同样由对偶范数单位球的高斯宽度所决定。
  • 原始ERM问题中的目标扰动在数学上等价于对偶优化问题中的输出扰动。
  • 作者首次对差分隐私背景下ERM的对偶优化问题进行了理论分析。
  • 研究结果通过表明当诱导结构化稀疏性时,此类风险界可独立于输入维度,扩展了先前关于过剩风险界的工作。
  • 该框架为分析非光滑ERM设置下基于镜像下降与梯度扰动的私有算法开辟了新途径。

更好的研究,从现在开始

从阅读论文到最终审阅,大幅缩短您的研究时间。

无需绑定信用卡

本解读由 AI 生成,并经人工编辑审核。