공개 특징 조건부 프라이빗 학습
Private Learning with Public Feature Conditioning
본 연구에서는 각 데이터 샘플이 공개적이고 민감하지 않은 특징을 포함하는 환경에서 차등 프라이버시(DP) 회귀 문제를 다룹니다. 이러한 형태의 문제 (예: 추천 시스템 및 광고 시스템)는 주로 분류 분야에서 연구되어 왔지만, 회귀 분야에서의 효과적인 접근 방식은 아직 충분히 탐구되지 않았습니다. 본 논문에서는 DPSGD의 변형인 Cond-DP를 제안하며, 이는 공개 특징 행렬의 구조를 활용하여 프라이버시 제약 조건 하에서 최적화를 개선합니다. 공개 특징들이 종종 빠르게 감소하는 스펙트럼을 갖는다는 관찰 결과를 바탕으로, Cond-DP는 데이터 기반 컨디셔닝 행렬을 도입하여 최적화 환경을 재구성하고 수렴 속도를 가속화합니다. 본 논문에서는 볼록, 강하게 볼록, 그리고 비볼록 설정에 대한 수렴 보장을 제공하며, 컨디셔닝 행렬이 단위 행렬인 경우 표준 DPSGD로 귀결됨을 보여줍니다. 또한, 공개 특징으로부터 효과적인 컨디셔닝 행렬을 구성하는 방법을 제시하여, 추가적인 프라이버시 비용 없이 프라이빗 선형 회귀에서 DPSGD보다 검증 가능한 빠른 수렴 속도를 달성할 수 있음을 입증합니다. 실험 결과, 제안하는 Cond-DP 방법은 공개 특징 기반 컨디셔닝 행렬과 함께 다양한 데이터셋 및 모델 아키텍처에 대해 최첨단 기준 성능을 꾸준히 능가하며, 실제 환경에서 강력하고 견고한 성능을 보였습니다.
We study differentially private (DP) regression in settings where each data sample includes public, non-sensitive features -- common in applications such as recommendation and advertising systems. While such label-DP or semi-sensitive-feature settings have been primarily explored in the context of classification, effective approaches for regression remain underexplored. We introduce Cond-DP, a conditioned variant of DPSGD that leverages the structure of public feature matrices to improve optimization under privacy constraints. Motivated by the observation that these public features often exhibit rapidly decaying spectra, Cond-DP incorporates a data-driven conditioning matrix to reshape the optimization landscape and accelerate convergence. We provide convergence guarantees for convex, strongly convex, and non-convex settings, and recover standard DPSGD as a special case when the conditioning matrix is the identity. We show how to construct an effective conditioning matrix for Cond-DP directly from public features, enabling provably faster convergence than DPSGD in private linear regression without incurring additional privacy cost. Empirically, Cond-DP with this conditioning matrix consistently outperforms state-of-the-art baselines across a wide range of datasets and model architectures under label DP, demonstrating strong and robust performance in practice.
No Analysis Report Yet
This paper hasn't been analyzed by Gemini yet.
Log in to request an AI analysis.