TY - GEN
T1 - From Curvature to Privacy
T2 - 21st ACM Asia Conference on Computer and Communications Security, AsiaCCS 2026
AU - Monir, Islam
AU - Ghinita, Gabriel
AU - Abdallah, Mohamed
N1 - Publisher Copyright:
© 2026 Copyright held by the owner/author(s).
PY - 2026/6/4
Y1 - 2026/6/4
N2 - Differentialy-Private Stochastic Gradient Descent (DP-SGD) is the benchmark for protecting sensitive data while training deep neural networks. However, it relies on fixed or heuristic schedules for key parameters such as noise multiplier and clipping threshold, often leading to suboptimal privacy-utility trade-offs. We propose a novel, curvature-aware training framework that dynamically adapts DP-SGD parameters based on the geometry of the loss surface. Leveraging public data, we estimate the local curvature via dominant Hessian eigenvalues and use this signal to compute an expected excess risk (EER) metric. This EER guides real-time adjustments of the DP-SGD mechanism. Our method operates in highly non-convex settings, beyond the limitations of prior EER-based strategies that assume convexity or PL conditions. Experimental results on MNIST, CIFAR-10, and SVHN demonstrate that our approach consistently improves model accuracy and convergence speed under tight privacy constraints, existing baselines.
AB - Differentialy-Private Stochastic Gradient Descent (DP-SGD) is the benchmark for protecting sensitive data while training deep neural networks. However, it relies on fixed or heuristic schedules for key parameters such as noise multiplier and clipping threshold, often leading to suboptimal privacy-utility trade-offs. We propose a novel, curvature-aware training framework that dynamically adapts DP-SGD parameters based on the geometry of the loss surface. Leveraging public data, we estimate the local curvature via dominant Hessian eigenvalues and use this signal to compute an expected excess risk (EER) metric. This EER guides real-time adjustments of the DP-SGD mechanism. Our method operates in highly non-convex settings, beyond the limitations of prior EER-based strategies that assume convexity or PL conditions. Experimental results on MNIST, CIFAR-10, and SVHN demonstrate that our approach consistently improves model accuracy and convergence speed under tight privacy constraints, existing baselines.
KW - Differential Privacy
KW - Empirical Risk Minimization
KW - Expected Excess Risk
KW - Machine Learning
KW - Neural Networks
UR - https://www.scopus.com/pages/publications/105042492368
U2 - 10.1145/3779208.3805970
DO - 10.1145/3779208.3805970
M3 - Conference contribution
AN - SCOPUS:105042492368
T3 - ASIA CCS 2026 - Proceedings of the 21st ACM ASIA Conference on Computer and Communications Security
SP - 1770
EP - 1785
BT - ASIA CCS 2026 - Proceedings of the 21st ACM ASIA Conference on Computer and Communications Security
PB - Association for Computing Machinery, Inc
Y2 - 1 June 2026 through 5 June 2026
ER -