[论文解读] Optimal Noise Adding Mechanisms for Approximate Differential Privacy
本文表征了在高隐私制度($\epsilon,\delta \to 0$)下,针对整数值查询和类似直方图的查询,$(\epsilon,\delta)$-差分隐私的最优噪声添加机制。结果表明,离散拉普拉斯分布和均匀噪声机制在$\ell^1$与$\ell^2$代价函数下近乎最优,其最优噪声幅度和功率分别按$\Theta(\min(1/\epsilon, 1/\delta))$和$\Theta(\min(1/\epsilon^2, 1/\delta^2))$缩放,表明在此设定下,$(\epsilon,\delta)$-DP相较于$(\epsilon,0)$-或$(0,\delta)$-DP并无显著优势。
We study the (nearly) optimal mechanisms in $(ε,δ)$-approximate differential privacy for integer-valued query functions and vector-valued (histogram-like) query functions under a utility-maximization/cost-minimization framework. We characterize the tradeoff between $ε$ and $δ$ in utility and privacy analysis for histogram-like query functions ($\ell^1$ sensitivity), and show that the $(ε,δ)$-differential privacy is a framework not much more general than the $(ε,0)$-differential privacy and $(0,δ)$-differential privacy in the context of $\ell^1$ and $\ell^2$ cost functions, i.e., minimum expected noise magnitude and noise power. In the same context of $\ell^1$ and $\ell^2$ cost functions, we show the near-optimality of uniform noise mechanism and discrete Laplacian mechanism in the high privacy regime (as $(ε,δ) o (0,0)$). We conclude that in $(ε,δ)$-differential privacy, the optimal noise magnitude and noise power are $Θ(\min(\frac{1}ε,\frac{1}δ))$ and $Θ(\min(\frac{1}{ε^2},\frac{1}{δ^2}))$, respectively, in the high privacy regime.
研究动机与目标
- 识别整数值和向量值(类似直方图)查询函数在$(\epsilon,\delta)$-差分隐私下的近似最优噪声添加机制。
- 分析$\ell^1$敏感查询函数在隐私与效用之间关于$\epsilon$与$\delta$的权衡。
- 评估$(\epsilon,\delta)$-差分隐私在噪声幅度与方差方面相较于$(\epsilon,0)$与$(0,\delta)$-DP特殊情形是否具有显著优势。
- 在高隐私制度($\epsilon,\delta \to 0$)下,建立最小可实现代价(噪声幅度与功率)的渐近界。
提出的方法
- 为$\ell^1$敏感度的查询函数,在$(\epsilon,\delta)$-差分隐私约束下建立一个代价最小化框架。
- 利用线性规划中的对偶性,推导出$\ell^2$代价函数最优代价的下界$V'_{LB}$。
- 构造对偶线性规划的候选解,参数为$\alpha = 3/2$,$\beta = \max(\epsilon,\delta)$,$k = \log \alpha / \beta$。
- 推导对偶变量$y_i^{(m)}$的解析表达式,并在$\beta \to 0$时渐近评估目标函数。
- 将推导出的下界与离散拉普拉斯分布和均匀噪声机制所实现的代价进行比较,以确立近似最优性。
- 使用泰勒展开和主导项提取进行渐近分析,推导出高隐私制度下代价的主导行为。
实验结果
研究问题
- RQ1在$\ell^1$敏感查询的噪声效率方面,$(\epsilon,\delta)$-差分隐私是否显著优于$(\epsilon,0)$-或$(0,\delta)$-DP?
- RQ2当$\epsilon,\delta \to 0$时,$(\epsilon,\delta)$-DP下最小可实现噪声幅度与噪声功率的渐近缩放关系为何?
- RQ3在高隐私制度下,离散拉普拉斯分布与均匀噪声机制是否对$\ell^1$与$\ell^2$代价函数近乎最优?
- RQ4$(\epsilon,\delta)$-DP下的最优代价能否被下界界定,其与已知机制的代价相比如何?
主要发现
- 在高隐私制度($\epsilon,\delta \to 0$)下,$(\epsilon,\delta)$-DP的最优噪声幅度按$\Theta(\min(1/\epsilon, 1/\delta))$缩放。
- 在高隐私制度下,最优噪声功率按$\Theta(\min(1/\epsilon^2, 1/\delta^2))$缩放。
- 离散拉普拉斯机制对$(\epsilon,0)$-DP近乎最优,并在$(\epsilon,\delta)$-DP设定下实现的代价与最优代价相差一个常数因子。
- 均匀噪声机制对$(0,\delta)$-DP近乎最优,并在$(\epsilon,\delta)$-DP设定下实现的代价与最优代价相差一个常数因子。
- 对于$\ell^2$代价函数,最优代价的下界为$\Omega(\frac{d\Delta^2}{\beta^2})$,其中$\beta = \max(\epsilon,\delta)$,常数至少为$0.0177$。
- 对于$\ell^1$代价函数,最优代价的下界为$\Omega(\frac{d\Delta}{\beta})$,常数至少为$\log(9/8) \approx 0.1178$。
更好的研究,从现在开始
从阅读论文到最终审阅,大幅缩短您的研究时间。
无需绑定信用卡
本解读由 AI 生成,并经人工编辑审核。