arXiv:2602.03872cs.LGcs.AI2026-02

首次理论解析私有训练对长尾数据的遗忘问题

Understanding the Impact of Differentially Private Training on Memorization of Long-Tailed Data

  • 从特征学习视角构建私有训练理论框架
  • 长尾子群体测试误差显著高于整体误差
  • 适合关注隐私与数据不平衡的研究者

近期研究发现,现代深度学习模型通过记忆训练样本实现高预测精度,引发隐私担忧,推动了差分隐私训练(如DP-SGD)的广泛应用。然而,大量实证研究表明,DP-SGD在长尾数据上常导致泛化性能下降,尤其对罕见或异常样本表现不佳。尽管如此,该现象的理论机制尚不清晰,且现有差分隐私分析难以扩展至非凸、非光滑的神经网络。本文首次从特征学习角度建立DP-SGD在长尾数据上的理论分析框架,证明其在长尾子群体上的测试误差显著高于全数据集整体误差。分析进一步揭示梯度裁剪与噪声注入共同抑制了模型对信息丰富但低频样本的记忆能力。最后,通过在合成与真实数据集上的广泛实验验证了理论结论。

原文摘要 · Abstract (English)

Recent research shows that modern deep learning models achieve high predictive accuracy partly by memorizing individual training samples. Such memorization raises serious privacy concerns, motivating the widespread adoption of differentially private training algorithms such as DP-SGD. However, a growing body of empirical work shows that DP-SGD often leads to suboptimal generalization performance, particularly on long-tailed data that contain a large number of rare or atypical samples. Despite these observations, a theoretical understanding of this phenomenon remains largely unexplored, and existing differential privacy analysis are difficult to extend to the nonconvex and nonsmooth neural networks commonly used in practice. In this work, we develop the first theoretical framework for analyzing DP-SGD on long-tailed data from a feature learning perspective. We show that the test error of DP-SGD-trained models on the long-tailed subpopulation is significantly larger than the overall test error over the entire dataset. Our analysis further characterizes the training dynamics of DP-SGD, demonstrating how gradient clipping and noise injection jointly adversely affect the model's ability to memorize informative but underrepresented samples. Finally, we validate our theoretical findings through extensive experiments on both synthetic and real-world datasets.

差分隐私长尾数据模型记忆理论分析

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。