[论文解读] Privacy Amplification by Subsampling: Tight Analyses via Couplings and Divergences
本文提出一个统一框架,使用 α-散度、耦合和隐私概况来推导多种子采样方案与相邻关系的紧致隐私放大界,并通过下界证明紧致性。
Differential privacy comes equipped with multiple analytical tools for the design of private data analyses. One important tool is the so-called "privacy amplification by subsampling" principle, which ensures that a differentially private mechanism run on a random subsample of a population provides higher privacy guarantees than when run on the entire population. Several instances of this principle have been studied for different random subsampling methods, each with an ad-hoc analysis. In this paper we present a general method that recovers and improves prior analyses, yields lower bounds and derives new instances of privacy amplification by subsampling. Our method leverages a characterization of differential privacy as a divergence which emerged in the program verification community. Furthermore, it introduces new tools, including advanced joint convexity and privacy profiles, which might be of independent interest.
研究动机与目标
- 开发一个通用且紧凑的框架,用于分析在不同子采样方案和相邻关系下的隐私放大。
- 统一现有结果并通过以散度为特征的 DP 描述推导新的放大界。
- 引入高级联合凸性和隐私概况,以界定由子采样产生的混合输出。
- 通过下界和基于耦合的证明建立界限的紧致性。
提出的方法
- 通过 α-散度和隐私概况(D_α)建模差分隐私,以捕捉紧致的 DP 保证。
- 利用高级联合凸性在子采样产生的重叠混合之间界定 D_{e^{ε′}}。
- 应用最大耦合来联系子采样分布并通过 ε′ = log(1 + η(e^{ε}-1)) 推导依赖于 η 的放大 ε′。
- 用分组隐私概况和基于耦合的分解来界定右侧散度。
- 提供一个通用框架,能够恢复现有结果并为各种子采样方案给出新的紧致界。
实验结果
研究问题
- RQ1在任意子采样方案下,如何推导紧致、普遍的 DP 放大界?
- RQ2α-散度表征结合耦合,是否能产生统一且最优的隐私放大结果?
- RQ3高级联合凸性和隐私概况如何帮助处理来自子采样的混合输出?
- RQ4在不同相邻关系下,常见子采样方法(Poisson、WOR、WR)的紧致界是什么?
- RQ5通过跨机制的下界,得到的界是否可证明地紧致?
主要发现
- 建立了一种统一的方法来推导隐私放大界,能够恢复所有已知结果并产生新界。
- 引入 α-散度的高级联合凸性以界定子采样的混合输出。
- 定义隐私概况和分组隐私概况,以量化跨 ε 和 δ 的 DP 保证。
- 推导了在移除/添加一个(R)和替换一个(S)相邻性下,Poisson、WOR 和 WR 子采样的紧致放大界。
- 提供了一个框架,通过通用下界和耦合证明紧致性。
- 表1总结了在常见子采样方案和相邻关系下的放大界。
更好的研究,从现在开始
从阅读论文到最终审阅,大幅缩短您的研究时间。
无需绑定信用卡
本解读由 AI 生成,并经人工编辑审核。