Skip to main content

PrivateHyperparameterOptimizer

Struct PrivateHyperparameterOptimizer 

Source
pub struct PrivateHyperparameterOptimizer<T: Float + Debug + Send + Sync + 'static> { /* private fields */ }
Expand description

Privacy-preserving hyperparameter optimizer

Implementations§

Source§

impl<T: Float + Debug + Send + Sync + 'static> PrivateHyperparameterOptimizer<T>

Source

pub fn new( config: PrivateHPOConfig<T>, parameterspace: ParameterSpace<T>, ) -> Result<Self>

Create new private hyperparameter optimizer.

The objective’s global sensitivity must be declared in config.sensitivity_bounds (under "objective", or as the only entry). Every evaluation releases its objective under a differentially private noise mechanism whose scale is sensitivity / epsilon, so an undeclared sensitivity has no safe default: substituting 1.0 silently rescales the noise, and every epsilon reported afterwards would describe a guarantee the run did not deliver. Construction therefore fails instead of guessing, whether or not private_model_selection is set.

Source

pub fn seed_for_tests(&mut self, seed: u64)

Seed every stochastic component deterministically (tests only).

The sub-seeds are domain-separated. Seeding the objective’s noise mechanism and the selection mechanism from the same seed makes both draw the same underlying uniform stream, so the evaluation that receives the largest objective noise also receives the largest selection noise – the private selection then reproduces the exact argmax and looks deterministic when it is not. That correlation is an artefact of the test harness, not of the mechanisms, and this is where it is avoided.

Source

pub fn total_privacy_cost(&self) -> PrivacyBudget

The epsilon spent so far across every objective release and the private selection.

This used to be privacy_accountant() -> &MomentsAccountant. That accountant was constructed from base_privacyconfig’s DP-SGD parameters (noise_multiplier, batch_size, dataset_size) and then never stepped, so it reported the spend of a training run that had not happened while the hyperparameter search’s real, pure-epsilon spend was tracked entirely by HPOBudgetManager. A moments accountant models subsampled-Gaussian composition and is the wrong primitive for the Laplace / exponential releases this optimizer performs, so it is gone rather than fed fabricated (sigma, q) pairs. Read the real ledger here or in PrivateHPOResults::total_privacy_cost.

Source

pub fn budget_manager(&self) -> &HPOBudgetManager

The budget manager.

Source

pub fn private_objective(&self) -> &PrivateObjective<T>

The private objective, including the noise mechanism and the scale it last used.

Source

pub fn optimize( &mut self, objective_fn: ObjectiveFn<T>, ) -> Result<PrivateHPOResults<T>>

Optimize hyperparameters with differential privacy.

The final configuration is chosen by the configured private selection mechanism when private_model_selection is set. When it is not, the exact argmax is returned and PrivateHPOResults::selection records was_private: false so the caller cannot mistake it for a private choice.

Auto Trait Implementations§

Blanket Implementations§

Source§

impl<T> Any for T
where T: 'static + ?Sized,

Source§

fn type_id(&self) -> TypeId

Gets the TypeId of self. Read more
Source§

impl<T> Borrow<T> for T
where T: ?Sized,

Source§

fn borrow(&self) -> &T

Immutably borrows from an owned value. Read more
Source§

impl<T> BorrowMut<T> for T
where T: ?Sized,

Source§

fn borrow_mut(&mut self) -> &mut T

Mutably borrows from an owned value. Read more
Source§

impl<ST, DT> CastableFrom<ST, Initialized, Initialized> for DT
where ST: ?Sized, DT: ?Sized,

Source§

impl<ST, DT> CastableFrom<ST, Uninit, Uninit> for DT
where ST: ?Sized, DT: ?Sized,

Source§

impl<T> From<T> for T

Source§

fn from(t: T) -> T

Returns the argument unchanged.

Source§

impl<T, U> Into<U> for T
where U: From<T>,

Source§

fn into(self) -> U

Calls U::from(self).

That is, this conversion is whatever the implementation of From<T> for U chooses to do.

Source§

impl<T> IntoEither for T

Source§

fn into_either(self, into_left: bool) -> Either<Self, Self>

Converts self into a Left variant of Either<Self, Self> if into_left is true. Converts self into a Right variant of Either<Self, Self> otherwise. Read more
Source§

fn into_either_with<F>(self, into_left: F) -> Either<Self, Self>
where F: FnOnce(&Self) -> bool,

Converts self into a Left variant of Either<Self, Self> if into_left(&self) returns true. Converts self into a Right variant of Either<Self, Self> otherwise. Read more
Source§

impl<T> Pointable for T

Source§

const ALIGN: usize

The alignment of pointer.
Source§

type Init = T

The type for initializers.
Source§

unsafe fn init(init: <T as Pointable>::Init) -> usize

Initializes a with the given initializer. Read more
Source§

unsafe fn deref<'a>(ptr: usize) -> &'a T

Dereferences the given pointer. Read more
Source§

unsafe fn deref_mut<'a>(ptr: usize) -> &'a mut T

Mutably dereferences the given pointer. Read more
Source§

unsafe fn drop(ptr: usize)

Drops the object pointed to by the given pointer. Read more
Source§

impl<T> Read<Exclusive, BecauseExclusive> for T
where T: ?Sized,

Source§

impl<T> Same for T

Source§

type Output = T

Should always be Self
Source§

impl<SS, SP> SupersetOf<SS> for SP
where SS: SubsetOf<SP>,

Source§

fn to_subset(&self) -> Option<SS>

The inverse inclusion map: attempts to construct self from the equivalent element of its superset. Read more
Source§

fn is_in_subset(&self) -> bool

Checks if self is actually part of its subset T (and can be converted to it).
Source§

fn to_subset_unchecked(&self) -> SS

Use with care! Same as self.to_subset but without any property checks. Always succeeds.
Source§

fn from_subset(element: &SS) -> SP

The inclusion map: converts self to the equivalent element of its superset.
Source§

impl<T, U> TryFrom<U> for T
where U: Into<T>,

Source§

type Error = Infallible

The type returned in the event of a conversion error.
Source§

fn try_from(value: U) -> Result<T, <T as TryFrom<U>>::Error>

Performs the conversion.
Source§

impl<T, U> TryInto<U> for T
where U: TryFrom<T>,

Source§

type Error = <U as TryFrom<T>>::Error

The type returned in the event of a conversion error.
Source§

fn try_into(self) -> Result<U, <U as TryFrom<T>>::Error>

Performs the conversion.
Source§

impl<V, T> VZip<V> for T
where V: MultiLane<T>,

Source§

fn vzip(self) -> V