DP-FTRL and matrix factorization mechanism (III)

In this series of blog posts, I plan to write down some of my personal understanding (of course shaped by many wonderful papers) of DP-FTRL and matrix factorization mechanism.

As motivated at the end of the previous post, in this post, our goal is to give a general way to compute the total noise (error) in prefix sum for any factorization A=BC. As a result, one can then optimize this error (objective) under privacy constraints to search for an even better mechanism than the tree-based algorithm (i.e., better pair (B,C)). From this, we will see that one needs to be careful in choosing C and B to balance the (i) sensitivity (hence the variance for each noise, determined by C) and (ii) the total number of accumulated noise (determined by B). The key behind tree-based algorithm is that its pair of (C,B) guarantees that both (i) and (ii) are on the log order, which is in sharp contrast to Simple I and II.

The calculation for the error in the matrix factorization mechanism is standard ( e.g.,[LMHMR15]). Here, we first slightly deviate from existing works by explicitly focusing on the task of prefix sum and aiming to bound the maximal error with high probability rather than expectation. Another difference is that for clarity, we explicitly consider the fact that the input data G is a T×d matrix rather than T×1 vector in standard previous works. Later, we will turn to the general way to bound the expected error.

To start with, we can easily see that the max error across T prefix outputs (here A=BC is the all-ones lower triangular matrix) is given by

Max-Error(B,C):=maxi[T]B[i,:]Z2,

where B[i,:] is the i-th row of B and each element of Z is i.i.d sampled from N(0,σ2), which is used to provide (ϵ,δ)-DP. To this end, σ=σϵ,δsens(C) (assume 2 norm of gt is bounded by 1 again) with σϵ,δ:=O(log(1/δ)ϵ) and sens(C) is the 2-sensitivity of CG (here it is Frobenious norm since CG is a matrix) 1. Let us first compute the high-probability max-error for a general σ and then plug in the proper value of it for privacy. For each i[T], we have each element of the d-dimensional row vector B[i,:]Z is distributed according to N(0,B[i,:]22). Hence, by the standard concentration of Gaussian vector and union bound over all i, we have with high probability

(3.1)Max-Error(B,C)maxi[T]O(σdB[i,:]2).

It remains to determine the value of σ, i.e., sens(C). To this end, we can write CG as a linear combination of the columns in C

CG=C[:,1]g1++C[:,j]gj++C[:,T]gT,

where C[:,j] is the j-th column of C and gjR1×d. Thus, considering an arbitrary neighboring sequence of {gj}j, the maximal Frobenious norm change is given by maxj[T]C[:j](gjgj)F. By the fact that the Frobenious norm is sub-multiplicative, we have

sens(C)maxj[T]C[:j]FgjgjF=maxj[T]C[:j]2gjgj22maxj[T]C[:j]2,

where in the last step we use the bounded norm of gradients. Combining the above with (3.1) and the fact σ=σϵ,δsens(C) together, we conclude that for (ϵ,δ)-DP under (B,C) for the task of prefix sum, the max-error across all T noisy prefix sum is upper bounded by the following with high probability

(3.2)Max-Error(B,C)maxi[T]O(σϵ,δmaxj[T]C[:j]2dB[i,:]2).

Remark 3.1: From the above bound, one can now see that a good choice of (B,C) such that A=BC is the one that minimizes the norm of columns in C and the norm of rows in B, simultaneously. Moreover, for any factorization, one can simply plug the bound in (3.2) into (1.2) to obtain the performance of DP-FTRL with the corresponding mechanism instead of the tree-based algorithm.

We now turn to a general task A (instead of prefix sum task above) and discuss the standard optimization objective in the matrix factorization mechanism. In particular, the standard goal in the literature is to minimize the expected error given by

(3.3)Lnormalize(B,C):=1TE[BZF],

where one can think of E[BZ]F as the total expected error in all T outputs and hence normalized by 1/T to have the same unit as the maximal expected error. In most existing works, the bound for (3.3) is used directly in the regret of DP-FTRL (i.e., (1.2)). However, in this case, one can at most get an expected regret and hence an expected population excess risk. Let us first put this aside and focus on how to bound the term in (3.3).

For (ϵ,δ)-DP, the value of σ for Z is the same, i.e., σσϵ,δsens(C)=σϵ,δmaxj[T]C[:j]2. To bound the error, we have

E[BZF]E[BZF2]=dσ2BF2.

With this, we have that under (ϵ,δ)-DP

Lnormalize,DP(B,C)O(dσϵ,δTsens(C)BF).

Hence, in most works, the objective is to optimize the following objective

minB,CBF2 such that BC=A and sens(C)=1

This problem is well-studied and can be solved using numerical optimization algorithms (e.g.,[YYZH16], [MMHM18]).

Remark 3.2: One may wonder if we can get a high probability bound on BZF. It turns out that with some use of concentration inequality, one can get it done. One straightforward way is to apply the (high-dimensional) Hanson-Wright inequality (since Z is a matrix rather than vector), see Exercise 6.2.7 in [Ver18].

Summary. Let us summarize what we have covered so far in this series: In (I), we introduce DP-FTRL, tree-based algorithm and general DP-FTRL regret bound as a function of the maximal error in prefix sum (i.e., (1.2)). Then, in (II), we view existing private mechanisms for prefix sum as special cases of matrix factorization mechanism, which motivates us to find better pair (B,C). Hence, in this post, we derive optimization problems over (B,C) to minimize the total error under privacy guarantee. As a result, we can now substitute the best error into (1.2) to obtain better regret upper bound.

But, as hinted by Q2 in the end of (I), it is still unclear whether minimizing the maximal error in prefix sum leads to tight final actual regret guarantee. This leads us to the topic of the next post:)

THE END

Now, it’s time to take a break by appreciating the masterpiece of Monet.

Monet

Water Lilies

courtesy of https://www.wikiart.org/

  1. One subtlety here is that gradients in G in model training is adaptive rather than fixed. However, as shown in [DMRSG22], for the Gaussian mechanism, it suffices to consider the non-adaptive one. ↩︎