Skip to main navigation Skip to search Skip to main content

From Curvature to Privacy: EER-Driven Differential Privacy in Deep Neural Networks

  • Islam Monir
  • , Gabriel Ghinita*
  • , Mohamed Abdallah
  • *Corresponding author for this work
  • Hamad bin Khalifa University
  • University of Massachusetts Boston

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

Abstract

Differentialy-Private Stochastic Gradient Descent (DP-SGD) is the benchmark for protecting sensitive data while training deep neural networks. However, it relies on fixed or heuristic schedules for key parameters such as noise multiplier and clipping threshold, often leading to suboptimal privacy-utility trade-offs. We propose a novel, curvature-aware training framework that dynamically adapts DP-SGD parameters based on the geometry of the loss surface. Leveraging public data, we estimate the local curvature via dominant Hessian eigenvalues and use this signal to compute an expected excess risk (EER) metric. This EER guides real-time adjustments of the DP-SGD mechanism. Our method operates in highly non-convex settings, beyond the limitations of prior EER-based strategies that assume convexity or PL conditions. Experimental results on MNIST, CIFAR-10, and SVHN demonstrate that our approach consistently improves model accuracy and convergence speed under tight privacy constraints, existing baselines.

Original languageEnglish
Title of host publicationASIA CCS 2026 - Proceedings of the 21st ACM ASIA Conference on Computer and Communications Security
PublisherAssociation for Computing Machinery, Inc
Pages1770-1785
Number of pages16
ISBN (Electronic)9798400723568
DOIs
Publication statusPublished - 4 Jun 2026
Event21st ACM Asia Conference on Computer and Communications Security, AsiaCCS 2026 - Bangalore, India
Duration: 1 Jun 20265 Jun 2026

Publication series

NameASIA CCS 2026 - Proceedings of the 21st ACM ASIA Conference on Computer and Communications Security

Conference

Conference21st ACM Asia Conference on Computer and Communications Security, AsiaCCS 2026
Country/TerritoryIndia
CityBangalore
Period1/06/265/06/26

Keywords

  • Differential Privacy
  • Empirical Risk Minimization
  • Expected Excess Risk
  • Machine Learning
  • Neural Networks

Fingerprint

Dive into the research topics of 'From Curvature to Privacy: EER-Driven Differential Privacy in Deep Neural Networks'. Together they form a unique fingerprint.

Cite this