不同微调配置下,同隐私预算模型的隐私表现差异显著。
Empirical Privacy Variance
- 用记忆度量化不同超参配置下的实际隐私水平
- 发现优化性能常牺牲实际隐私,存在无免费午餐权衡
- 提出新调参策略,兼顾实用性和隐私精度
我们提出经验隐私方差的概念,并在语言模型的差分隐私微调背景下进行研究。具体而言,我们发现:使用相同 $(\varepsilon, δ)$-DP 保证、但不同超参数配置的 DP-SGD 模型,在实际隐私表现上存在显著差异,这种差异通过记忆程度进行量化。我们在多个维度上探究了该现象的普遍性,并讨论其出人意料且重要的意义。通过回归分析,我们考察了单个与组合超参数对经验隐私的影响。结果揭示了一种无免费午餐的权衡:当前在固定隐私预算下优化模型效用的超参数调优实践,往往以牺牲经验隐私为代价。为此,我们提出了更精细的超参数选择启发式方法,显式考虑经验隐私,证明其兼具精确性与实用性。最后,我们初步探索经验隐私方差,提出两个假设,指出现有隐私审计技术的局限性,并勾勒出未来研究的开放问题。
原文摘要 · Abstract (English)
We propose the notion of empirical privacy variance and study it in the context of differentially private fine-tuning of language models. Specifically, we show that models calibrated to the same $(\varepsilon, δ)$-DP guarantee using DP-SGD with different hyperparameter configurations can exhibit significant variations in empirical privacy, which we quantify through the lens of memorization. We investigate the generality of this phenomenon across multiple dimensions and discuss why it is surprising and relevant. Through regression analysis, we examine how individual and composite hyperparameters influence empirical privacy. The results reveal a no-free-lunch trade-off: existing practices of hyperparameter tuning in DP-SGD, which focus on optimizing utility under a fixed privacy budget, often come at the expense of empirical privacy. To address this, we propose refined heuristics for hyperparameter selection that explicitly account for empirical privacy, showing that they are both precise and practically useful. Finally, we take preliminary steps to understand empirical privacy variance. We propose two hypotheses, identify limitations in existing techniques like privacy auditing, and outline open questions for future research.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。