首页 > AI前沿 > Differential Privacy of Gradient Descent on Perturbed Objectives

Differential Privacy of Gradient Descent on Perturbed Objectives

arXiv机器学习 2026-10-02 10:52 5 阅读 查看原文

Objective perturbation adds a random linear term to a regularized empirical risk and releases the exact perturbed minimizer.

We study the finite computation obtained by releasing the $N$-th iterate of deterministic gradient descent on $w\mapsto F(w;S)+\langle z,w\rangle$, where $z\sim\mathcal N(0,σ^2I_d)$ is drawn once before optimization.

Results for Strongly Convex and Smooth Objectives

For strongly convex and smooth objectives with Lipschitz Hessian, we prove an explicit condition under which the map $z\mapsto w_N$ is a $C^1$-diffeomorphism on the bounded domains used in the privacy argument, with a quantitative lower bound on the smallest singular value of its Jacobian.

This permits a direct change-of-variables analysis of the finite iterate.

Privacy Profile Bound for Generalized Linear Models

For generalized linear models, the resulting privacy-profile bound has no explicit ambient-dimension factor once the iteration condition holds, and its finite-iteration correction decreases geometrically.

By letting the free truncation parameter grow slowly with $N$, we recover the corresponding exact-minimizer certificate in the limit.

Expected Excess Empirical Risk Bound

We also bound the expected excess empirical risk by $dσ^2/(2μ)$ plus a geometrically decreasing optimization term, and transfer the result to population risk without an additional multiplicative condition-number factor in the leading statistical terms.