Individual Privacy Accounting via a Rényi Filter
Vitaly Feldman, Tijana Zrnic
Abstract
We consider a sequential setting in which a single dataset of individuals is used to perform adaptively-chosen analyses, while ensuring that the differential privacy loss of each participant does not exceed a pre-specified privacy budget. The standard approach to this problem relies on bounding a worst-case estimate of the privacy loss over all individuals and all possible values of their data, for every single analysis. Yet, in many scenarios this approach is overly conservative, especially for "typical" data points which incur little privacy loss by participation in most of the analyses. In this work, we give a method for tighter privacy loss accounting based on the value of a personalized privacy loss estimate for each individual in each analysis. To implement the accounting method we design a filter for Rényi differential privacy. A filter is a tool that ensures that the privacy parameter of a composed sequence of algorithms with adaptively-chosen privacy parameters does not exceed a pre-specified budget. Our filter is simpler and tighter than the known filter for ( , δ)-differential privacy by Rogers et al. [29]. We apply our results to the analysis of noisy gradient descent and show that personalized accounting can be practical, easy to implement, and can only make the privacy-utility tradeoff tighter.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 0411f23d-368d-44e0-a206-e9a3db91f28aCited by top-tier papers21
- Differentially Private Learning Needs Better Features (or Much More Data)Florian Tramèr, Dan BonehICLR 2021 · 325 citations
- Deep Learning with Label Differential PrivacyBadih Ghazi, Noah Golowich, Ravi Kumar, Pasin Manurangsi et al.NeurIPS 2021 · 193 citations
- Fully-Adaptive Composition in Differential PrivacyJustin Whitehouse, Aaditya Ramdas, Ryan Rogers, Steven WuICML 2023 · 56 citations
- Muffliato: Peer-to-Peer Privacy Amplification for Decentralized Optimization and AveragingEdwige Cyffers, Mathieu Even, Aurélien Bellet, Laurent MassouliéNeurIPS 2022 · 39 citations
- Brownian Noise Reduction: Maximizing Privacy Subject to Accuracy ConstraintsJustin Whitehouse, Aaditya Ramdas, Zhiwei Steven Wu, Ryan M. RogersNeurIPS 2022 · 16 citations
Builds on2
Related papers
- Individual Privacy Accounting with Gaussian Differential PrivacyAntti Koskela, Marlon Tobaben, Antti HonkelaICLR 2023 · 2 citations
- Concurrent Composition for Interactive Differential Privacy with Adaptive Privacy-Loss ParametersSamuel Haney, Michael Shoemate, Grace Tian, Salil P. Vadhan et al.CCS 2023 · 4 citations
- Adaptive Privacy Composition for Accuracy-first MechanismsRyan M. Rogers, Gennady Samorodnitsky, Zhiwei Steven Wu, Aaditya RamdasNeurIPS 2023 · 6 citations
- Private Hyperparameter Tuning with Ex-Post GuaranteeBadih Ghazi, Pritish Kamath, Alexander Knop, Ravi Kumar et al.NeurIPS 2025 · 4 citations
- Privacy Profiles for Private SelectionAntti Koskela, Rachel Redberg, Yu-Xiang WangICML 2024 · 2 citations
