acceptodds
Under review as a conference paper at ICLR 2027

Can Variable Noise Be Data-Independent? Differentially Private Bimodal SGD

Abstract

DP-SGD serves as the de facto baseline for private deep learning, yet its constant noise scale imposes an unfavorable dilemma: small noise rapidly depletes privacy budgets, while large noise degrades gradient signals. While adaptive noise mitigates this issue, its data dependence violates essential data independence, risking leakage. We propose Differentially Private Bimodal SGD (DP-BiSGD), a strictly data-independent baseline that stochastically alternates between high-probability small perturbations for local exploitation and low-probability large perturbations for global exploration. To translate this concept into a viable baseline, we address two challenges inherent in this bimodal formulation. Specifically, we develop a bypass-scaled update scheme that shields the momentum buffer from extreme-variance corruption, coupled with a dynamic GMM-PLD accountant to overcome loose standard accounting and ensure tight privacy bounds. Extensive experiments demonstrate that DP-BiSGD consistently outperforms DP-SGD in model utility under identical privacy guarantees, preserves strong resilience against inference attacks, and serves as a seamless drop-in replacement.

open until 14 Dec 2026

est. 32% chance this paper gets accepted at ICLR 2027.

Reject 68%Accept 32%

What do you think this paper will get?

All positions stay anonymous.

Related papers

Loading the map…

Discussion (0)

Sign in to comment.