arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

DP-ES:用于提示优化的差分隐私进化策略

DP-ES: Differentially Private Evolution Strategies for Prompt Optimization

Ziniu Liu, Aiping Li, Yue Han, Han Yu, Junjian Zhang, Dong Zhu, Changjian Li, Shiqiang Zhang

arXiv 2610.06236首次发表:更新:

发表机构

National University of Defense Technology; CRRC Zhuzhou Electric Locomotive Research Institute Co., Ltd.; China Academy of Railway Sciences(国防科技大学; 中车株洲电力机车研究所有限公司; 中国铁道科学研究院)

机构由 AI 辅助整理,请以论文原文为准。

AI 中文总结

针对DP提示优化在严格隐私预算下的不稳定性,提出DP-ES方法,通过种群进化和仅对评估加噪,在GSM8K等基准上显著提升准确率并降低方差,且更高效。

AI 中文摘要

令牌级差分隐私(DP)提示优化方法(如DP-OPT)在严格的隐私预算下可能变得不稳定:在GSM8K上,DP-OPT在30次运行中获得49.5±28.5%的准确率,且记录的搜索轨迹揭示了提示模板漂移和对噪声敏感不可逆的选择。我们将这些诊断为在私有聚合计数上进行贪心逐令牌构建的结构性后果。我们随后提出DP-ES(差分隐私进化策略),一种结构上更清晰的替代方案,它维护完整提示的种群,通过从不访问私有数据集的LLM调用进行变异,并且仅在采样高斯评估上花费隐私;确定性或Gumbel平滑选择是后处理。在保守的(ε≤1.0,δ=10⁻⁵)保证下,DP-ES在GSM8K上达到88.1%(比DP-OPT提高38.6个百分点,标准差约低9倍),在MedQA上达到99.7%,在BANKING77上达到73.5%,在Alpaca上达到86.8%。它在墙钟时间上也快2.5倍,并且记录的私有数据调用组比DP-OPT少3.3倍。选择和种群消融、实现级噪声检查以及200个配置的精确匹配记忆压力测试补充了形式保证。范围:我们的实验确立了在DP噪声下的优化鲁棒性,特别是在提示结构关键的情况下;对真正敏感、非饱和部署数据的端到端验证仍是未来工作。

英文摘要

Token-level differentially private (DP) prompt optimization methods such as DP-OPT can become unstable under tight privacy budgets: on GSM8K, DP-OPT obtains $49.5\pm28.5\%$ across 30 runs, and a logged search trajectory reveals prompt-template drift and noise-sensitive irreversible choices. We diagnose these as structural consequences of greedy token-by-token construction over privately aggregated counts. We then propose DP-ES (Differentially Private Evolution Strategies), a structurally cleaner alternative that maintains a population of full prompts, mutates them via LLM calls that never access the private dataset, and spends privacy only on sampled-Gaussian evaluation; deterministic or Gumbel-smoothed selection is post-processing. Under a conservative $(\varepsilon\leq1.0,δ=10^{-5})$ guarantee, DP-ES achieves 88.1% on GSM8K (+38.6 pp over DP-OPT, approximately 9 times lower standard deviation), 99.7% on MedQA, 73.5% on BANKING77, and 86.8% on Alpaca. It is also 2.5 times faster in wall-clock time and uses 3.3 times fewer logged private-data call groups than DP-OPT. Selection and population ablations, implementation-level noise checks, and a 200-profile exact-match memorization stress test complement the formal guarantee. Scope: Our experiments establish optimization robustness under DP noise, especially where prompt structure is critical; end-to-end validation on genuinely sensitive, non-saturated deployment data remains future work.

CommentsAccepted at EMNLP 2026 (Main Conference). Code: https://github.com/StephCpa/dp-es

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑