Escaping Silent Failure: Auditable Adaptive Clipping under Client-Level Local Differential Privacy
Abstract
Client-level local differential privacy (LDP) trusts no party: each client noises its own update before transmission. At over rounds without amplification, the released update carries Gaussian noise of norm with , so the clipping radius sets the noise scale outright. We show that recent local-model designs fail silently, and how to build one whose failure modes are auditable. For the released-norm rules we analyse (scalar per-client statistics of noised released norms) the three natural routes fail: a capped statistic saturates and the radius follows a data-independent schedule (the plug-in map freezes it at a constant); an uncapped one is pinned at the largest admissible radius; uncapped debiased squared-norm estimation has prohibitive variance at our calibration. Their closed-form target omits the model dimension and, relative to the error bound, is too large by . We derive three design laws for auditable scale tracking: pay for a privatized pre-noise statistic; set its cap at the tracked update scale, not at a small multiple of the radius; keep cohort size times averaging window above an explicit threshold. A reference algorithm meets all three at radius-independent Rényi-DP cost. Every prediction was fixed before its run and the failed ones are reported; the failure modes occur in real training (saturation on two architectures). The design settles above in every CNN and MLP run at . Under one accounting, the released-norm plug-in rule diverges in every cell (6.9–12.4% final accuracy against 19.9–38.5%), and the design leads a budget-matched randomized-response quantile tracker and a DP-FedPUAC port in every cell when paired ( to points, none significant after Holm correction at five seeds). Because the regime is fully clipped, the radius matters only to an order of magnitude: three statistic-only releases before training shed an over-estimated prior in the tested range, and continued tracking adds only and points over freezing the calibrated radius. In-budget sweeps cost 4–14 points; an offline oracle sweep the threat model does not grant is 1–5.3 points ahead. We distill the results into deployment checks and audit signals computable from released messages alone.
est. 32% chance this paper gets accepted at ICLR 2027.
What do you think this paper will get?
All positions stay anonymous.