arXiv:2511.18006cs.LG2025-11被引 2

从特征视角解析私有学习,揭示噪声对泛化的影响

Understanding Private Learning From Feature Perspective

  • 区分特征信号与噪声,构建私有学习理论框架
  • 私有训练需更高信噪比,噪声记忆导致泛化差
  • 适合关注隐私机器学习机制的研究者

差分隐私随机梯度下降(DP-SGD)已成为敏感领域隐私保护机器学习的核心方法。尽管已有研究通过引入非私有预训练模型的特征来提升DP-SGD性能,但私有学习中特征动态的理论理解仍不充分。本文首次提出从特征学习角度分析私有训练的理论框架。基于先前工作的多块数据结构,我们区分了依赖标签的特征信号与独立标签的噪声,这一关键点被现有DP分析所忽略。采用带多项式ReLU激活的两层CNN,我们通过含噪梯度下降,理论上刻画了私有训练中的特征信号学习与数据噪声记忆。结果表明:(1) 私有信号学习需比非私有训练更高的信噪比;(2) 当非私有学习中存在数据噪声记忆时,私有学习同样会发生,导致尽管训练损失小但泛化性能差。研究揭示了私有学习的挑战,并证明特征增强可有效提升信噪比。合成与真实数据集上的实验验证了理论发现。

原文摘要 · Abstract (English)

Differentially private Stochastic Gradient Descent (DP-SGD) has become integral to privacy-preserving machine learning, ensuring robust privacy guarantees in sensitive domains. Despite notable empirical advances leveraging features from non-private, pre-trained models to enhance DP-SGD training, a theoretical understanding of feature dynamics in private learning remains underexplored. This paper presents the first theoretical framework to analyze private training through a feature learning perspective. Building on the multi-patch data structure from prior work, our analysis distinguishes between label-dependent feature signals and label-independent noise, a critical aspect overlooked by existing analyses in the DP community. Employing a two-layer CNN with polynomial ReLU activation, we theoretically characterize both feature signal learning and data noise memorization in private training via noisy gradient descent. Our findings reveal that (1) Effective private signal learning requires a higher signal-to-noise ratio (SNR) compared to non-private training, and (2) When data noise memorization occurs in non-private learning, it will also occur in private learning, leading to poor generalization despite small training loss. Our findings highlight the challenges of private learning and prove the benefit of feature enhancement to improve SNR. Experiments on synthetic and real-world datasets also validate our theoretical findings.

隐私学习特征分析信噪比泛化

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。