Researchers have developed a new closed-form formula to calibrate noise levels for DP-SGD, a method used to protect training data by adding noise to gradients. This formula specifically applies to DP-SGD with random allocation, where each record is used once per epoch at a random step. The derived formula provides an upper bound on the accuracy of membership inference attacks (MIAs) against models trained with this method, offering a more efficient way to determine the necessary noise multiplier compared to traditional numerical privacy accountants. AI
IMPACT Provides a more efficient method for calibrating noise in DP-SGD, potentially leading to better privacy-utility trade-offs in machine learning models.
RANK_REASON The cluster contains a research paper detailing a new mathematical formula for privacy-preserving machine learning. [lever_c_demoted from research: ic=1 ai=1.0]
- arXiv
- DP SGD
- Gaussian mixture model
- Gaussian noise
- gradients
- Hugging Face
- membership inference attack
- Murat Bilgehan Ertan
- Gaussian distribution
- chi-squared divergence
AI-generated summary · Google Gemini · from 1 sources. How we write summaries →