Revisiting the Moment Accountant Method for DP-SGD
In order to provide differential privacy, Gaussian noise with standard deviation is added to local SGD updates after performing a clipping operation in Differential Private SGD (DP-SGD). By non-trivially improving the account method we prove a simple and easy to evaluate closed form -DP guarantee: DP-SGD is -DP if and is at least , where is the total number of rounds, and is the total number of gradient computations where measures in number of epochs of size of the local data set. We prove that our expression is close to tight in that if is more than a constant factor smaller than the lower bound , then the -DP guarantee is violated. Choosing the smallest possible value not only leads to a close to tight DP guarantee, but also minimizes the total number of communicated updates and this means that the least amount of noise is aggregated into the global model and accuracy is optimized as confirmed by simulations. In addition this minimizes round communication.
View on arXiv