首次为隐私保护的零阶优化建立可收敛的隐私放大理论。
Privacy Amplification in Differentially Private Zeroth-Order Optimization with Hidden States
- 提出混合噪声机制与耦合分析,突破传统方法局限
- 实现零阶优化中隐私预算的可迭代收敛控制
- 适用于大模型微调中的隐私保护场景
零阶优化在差分隐私(DP)和内存约束下微调大语言模型方面展现出巨大潜力。尽管一阶方法可通过迭代隐私放大(PABI)获得收敛的隐私界,但零阶方法尚无此类理论保障。一阶PABI依赖梯度注入各向同性噪声,使隐私界可通过平移的Rényi散度递推追踪;而零阶方法沿随机方向注入标量噪声以保持效用,导致更新具有各向异性,破坏了标准平移散度框架,全局Lipschitz性质不再几乎必然成立。本文首次通过提出混合噪声机制和新型耦合分析,建立零阶优化的隐藏状态差分隐私(DP)收敛边界。通过构建辅助耦合过程,绕过全局Lipschitz障碍,实现隐私边界的可收敛追踪。此外,本结果推动了此前文献未见的更优零阶隐私算法设计。
原文摘要 · Abstract (English)
Zeroth-order optimization has emerged as a promising approach for fine-tuning large language models under differential privacy (DP) and memory constraints. While privacy amplification by iteration (PABI) provides convergent DP bounds for first-order methods, establishing similar guarantees for zeroth-order methods remains an open problem. First-order PABI analysis relies on the fact that gradients are perturbed with isotropic noise, allowing privacy bounds to be iteratively tracked via shifted Rényi divergence. In contrast, DP zeroth-order methods inject scalar noise along random update directions to maintain utility. This anisotropic update fails standard shifted divergence frameworks, as the global Lipschitz property no longer holds almost surely. We provide the first convergent hidden-state DP bound for zeroth-order optimization by proposing a hybrid noise mechanism and a novel coupling analysis. We bypass the purely shifted-divergence approach by constructing a coupled auxiliary process, which circumvents the global Lipschitz barrier and yields a convergent privacy bound. Furthermore, our results induce better DP zeroth-order algorithmic designs that are previously unknown to the literature.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。