acceptodds
Under review as a conference paper at ICLR 2027

Escaping Silent Failure: Auditable Adaptive Clipping under Client-Level Local Differential Privacy

Abstract

Client-level local differential privacy (LDP) trusts no party: each client noises its own update before transmission. At over rounds without amplification, the released update carries Gaussian noise of norm with , so the clipping radius sets the noise scale outright. We show that recent local-model designs fail silently, and how to build one whose failure modes are auditable. For the released-norm rules we analyse (scalar per-client statistics of noised released norms) the three natural routes fail: a capped statistic saturates and the radius follows a data-independent schedule (the plug-in map freezes it at a constant); an uncapped one is pinned at the largest admissible radius; uncapped debiased squared-norm estimation has prohibitive variance at our calibration. Their closed-form target omits the model dimension and, relative to the error bound, is too large by . We derive three design laws for auditable scale tracking: pay for a privatized pre-noise statistic; set its cap at the tracked update scale, not at a small multiple of the radius; keep cohort size times averaging window above an explicit threshold. A reference algorithm meets all three at radius-independent Rényi-DP cost. Every prediction was fixed before its run and the failed ones are reported; the failure modes occur in real training (saturation on two architectures). The design settles above in every CNN and MLP run at . Under one accounting, the released-norm plug-in rule diverges in every cell (6.9–12.4% final accuracy against 19.9–38.5%), and the design leads a budget-matched randomized-response quantile tracker and a DP-FedPUAC port in every cell when paired ( to points, none significant after Holm correction at five seeds). Because the regime is fully clipped, the radius matters only to an order of magnitude: three statistic-only releases before training shed an over-estimated prior in the tested range, and continued tracking adds only and points over freezing the calibrated radius. In-budget sweeps cost 4–14 points; an offline oracle sweep the threat model does not grant is 1–5.3 points ahead. We distill the results into deployment checks and audit signals computable from released messages alone.

open until 14 Dec 2026

est. 32% chance this paper gets accepted at ICLR 2027.

Reject 68%Accept 32%

What do you think this paper will get?

All positions stay anonymous.

Related papers

Loading the map…

Discussion (0)

Sign in to comment.