Trade-off Functions for DP-SGD with Subsampling based on Random Shuffling: Tight Upper and Lower Bounds
Abstract
We derive a tight analysis of the trade-off function for Differentially Private Stochastic Gradient Descent (DP-SGD) with subsampling based on random shuffling within the -DP framework. Our analysis covers the regime , where is the noise multiplier and is the number of rounds within a single epoch. Unlike -DP analyses for Poisson subsampling, which yield non-closed implicit formulas that can be machine computed but are non-transparent, random shuffling admits a tight analysis yielding transparent and interpretable closed-form bounds. Our concrete bounds, derived via the Berry-Esseen theorem, are tight up to constant factors within the proof framework. We demonstrate worked parameter settings for a single epoch () with a corresponding trade-off function , that is, only below the ideal random guessing diagonal : For and , roughly rounds and training samples suffice to achieve meaningful differential privacy. This is in contrast to recent negative results for the regime . Our concrete bounds can be composed over multiple epochs leading to having a linear in dependency, which restricts . To go beyond Berry--Esseen, we introduce a new proof technique based on a generalization of the law of large numbers that yields an asymptotic random guessing diagonal-limit result: if with , then the -fold composed trade-off function satisfies uniformly in with having only an dependency. We compare this asymptotic regime with the corresponding Poisson subsampling asymptotic, and highlight the characterization of explicit convergence rates as an open question.
Cite
@article{arxiv.2605.06259,
title = {Trade-off Functions for DP-SGD with Subsampling based on Random Shuffling: Tight Upper and Lower Bounds},
author = {Marten van Dijk and Murat Bilgehan Ertan},
journal= {arXiv preprint arXiv:2605.06259},
year = {2026}
}