Skip to main content
QUICK REVIEW

[論文レビュー] Circulant Matrices and Differential Privacy.

Jalaj Upadhyay|arXiv (Cornell University)|Jan 1, 2014
Privacy-Preserving Technologies in Data参考文献 50被引用数 3
ひとこと要約

本論文は、n 個のガウス分布からのサンプルとn 個のベルヌーイ試行のみを要する、広範なクラスの巡回ランダム射影行列が、微分プライバシーを保ちつつジョンソン=リンデンストロームのユーティリティを維持することを証明することで、未解決の問題を解決している。行列-ベクトル乗算の実行時間は O(n log n) であり、カットクエリでは従来の手法より O(n^o(1)) 要因、共分散クエリでは O(n^0.38) 要因改善されており、グラフスパースフィケーションに依存せずに実現されている。

ABSTRACT

This paper resolves an open problem raised by Blocki et al. (FOCS 2012), i.e., whether other variants of the Johnson-Lindenstrauss transform preserves differential privacy or not? We prove that a general class of random projection matrices that satisfies the Johnson-Lindenstrauss lemma also preserves dif-ferential privacy. This class of random projection matrices requires only n Gaussian samples and n Bernoulli trials and allows matrix-vector multiplication in O(n log n) time. In this respect, this work un-conditionally improves the run time of Blocki et al. (FOCS 2012) without using the graph sparsification trick of Upadhyay (ASIACRYPT 2013). For the metric of measuring randomness, we stick to the norm used by earlier researchers who studied variants of the Johnson-Lindenstrauss transform and its applica-tions, i.e., count the number of random samples made. In concise, we improve the sampling complexity by quadratic factor, and the run time of cut queries by an O(no(1)) factor and that of covariance queries by an O(n0.38) factor. Our proof for both the privacy and utility guarantee uses several new ideas. In order to improve the dimension bound, we use some known results from the domain of statistical model selection. This makes our proof short and elegant, relying just on one basic concentration inequality. For the privacy proof, even though our mechanism closely resembles that of Blocki et al. (FOCS 2012) and Upadhyay (ASIACRYPT 2013), we cannot use their proof idea. This is because the projection matrices we are inter-ested in introduces non-trivial correlations between any two rows of the published matrix, and, therefore, we cannot invoke the composition theorem of Dwork, Rothblum and Vadhan (STOC 2009). We argue that the published matrix is not r-multivariate distribution; rather one matrix-variate distribution. We compute the distribution of the published matrix and then prove it preserves differential privacy.

研究の動機と目的

  • ジョンソン=リンデンストロームの変種が微分プライバシーを保持するかどうかという、ブロックィら(FOCS 2012)が提起した未解決問題を解決すること。
  • ジョンソン=リンデンストロームの補題に従って、微分プライバシーとユーティリティの両方を維持するランダム射影行列のクラスを設計すること。
  • カットクエリや共分散クエリのようなプライバシー保護型クエリのための、サンプリング複雑性の低減と実行時間の向上を図ること。
  • 射影行列の行間に非自明な相関関係が存在するため、従来の合成定理に依存せずに、新しいプライバシー証明を提供すること。
  • 集中不等式と行列変数分布解析を用いて、プライバシーとユーティリティの保証を統合すること。

提案手法

  • n 個のガウス分布からのサンプルとn 個のベルヌーイ試行を用いて、巡回ランダム射影行列のクラスを構築する。
  • 統計的モデル選択の既知の結果を活用し、ジョンソン=リンデンストローム補題における次元の上限を厳密化する。
  • 単一の基本的な集中不等式を用いてユーティリティを証明することで、先行研究と比較して解析を簡略化する。
  • 行の相関関係があるため、多変量分布ではなく、行列変数分布として公開された行列をモデル化する。
  • 公開された行列の正確な分布を計算することで、合成定理に依存せずに微分プライバシーを確立する。
  • 行間の依存関係を考慮する独自のプライバシー証明戦略を用い、先行手法で用いられる仮定を回避する。

実験結果

リサーチクエスチョン

  • RQ1巡回ランダム射影行列は、ジョンソン=リンデンストローム補題を満たす一方で、微分プライバシーを保持できるか?
  • RQ2標準的な合成定理が、このクラスの射影行列に対してなぜ機能しないのか、そして代替的にどのようにプライバシーを証明できるか?
  • RQ3グラフスパースフィケーションを用いずに、微分プライバシー保護型次元削減のためのサンプリング複雑性と実行時間を改善できるか?
  • RQ4公開された行列の行列変数的性質は、i.i.d. 行モデルと比較して、プライバシー解析にどのように影響を与えるか?
  • RQ5このアプローチを用いることで、カットクエリと共分散クエリの実行時間に、定量的にどの程度の向上が得られるか?

主な発見

  • 提案手法は、先行研究と比較して、サンプリング複雑性を二乗の要因で低減している。
  • 行列-ベクトル乗算は O(n log n) 時間で実行可能であり、従来の手法を上回る。
  • カットクエリの実行時間は O(n^o(1)) 要因改善され、共分散クエリでは O(n^0.38) 要因改善されている。
  • 非自明な行相関関係があるにもかかわらず、標準的な合成定理が無効であるにもかかわらず、プライバシー証明が有効である。
  • 証明は単一の集中不等式に依存しており、証明が短く洗練されている。
  • メカニズムは、公開された行列を行列変数分布としてモデル化することで、微分プライバシーを達成しており、正確な分布計算が可能になっている。

より良い研究を、今すぐ始めましょう

論文の読解から最終レビューまで、研究時間を劇的に削減しましょう。

クレジットカード登録不要

このレビューはAIが作成し、人間の編集者が確認しました。