A Generalized Shuffle Framework for Privacy Amplification: Strengthening Privacy Guarantees and Enhancing Utility
E. Chen, Yang Cao, Yifei Ge
Abstract
The shuffle model of local differential privacy is an advanced method of privacy amplification designed to enhance privacy protection with high utility. It achieves this by randomly shuffling sensitive data, making linking individual data points to specific individuals more challenging. However, most existing studies have focused on the shuffle model based on (ϵ0, 0)-Locally Differentially Private (LDP) randomizers, with limited consideration for complex scenarios such as (ϵ0, δ0)-LDP or personalized LDP (PLDP). This hinders a comprehensive understanding of the shuffle model's potential and limits its application in various settings. To bridge this research gap, we propose a generalized shuffle framework that can be applied to any (ϵi, δi)-PLDP setting with personalized privacy parameters. This generalization allows for a broader exploration of the privacy-utility trade-off and facilitates the design of privacy-preserving analyses in diverse contexts. We prove that shuffled (ϵi, δi)-PLDP process approximately preserves µ-Gaussian Differential Privacy with µ = . This approach allows us to avoid the limitations and potential inaccuracies associated with inequality estimations. To strengthen the privacy guarantee, we improve the lower bound by utilizing hypothesis testing instead of relying on rough estimations like the Chernoff bound or Hoeffding's inequality. Furthermore, extensive comparative evaluations clearly show that our approach outperforms existing methods in achieving strong central privacy guarantees while preserving the utility of the global model. We have also carefully designed corresponding algorithms for average function, frequency estimation, and stochastic gradient descent.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 2f32bc03-dabf-4b52-b631-92c4d844017bCited by top-tier papers4
- Decomposition-Based Optimal Bounds for Privacy Amplification via ShufflingPengcheng Su, Haibo Cheng, Ping WangS&P 2026 · 4 citations
- RESFL: An Uncertainty-Aware Framework for Responsible Federated Learning by Balancing Privacy, Fairness and UtilityDawood Wasif, Terrence J Moore, Jin-Hee ChoICLR 2026 · 3 citations
- Factor Graph-based Interpretable Neural NetworksYicong Li, Kuanjiu Zhou, Shuo Yu, Qiang Zhang et al.ICLR 2025
- Doppio: Communication-Efficient and Secure Multi-Party Shuffle Differential PrivacyWentao Dong, Yang Cao, Cong Wang, Wei-Bin LeeVLDB 2026
Builds on3
- Deep Learning with Differential PrivacyMartín Abadi, Andy Chu, Ian J. Goodfellow, H. Brendan McMahan et al.CCS 2016 · 7,620 citations
- FLAME: Differentially Private Federated Learning in the Shuffle ModelRuixuan Liu, Yang Cao, Hong Chen, Ruoyang Guo et al.AAAI 2021 · 117 citations
- Hiding Among the Clones: A Simple and Nearly Optimal Analysis of Privacy Amplification by ShufflingVitaly Feldman, Audra McMillan, Kunal TalwarFOCS 2021 · 76 citations
Related papers
- Echo of Neighbors: Privacy Amplification for Personalized Private Federated Learning with Shuffle ModelYixuan Liu, Suyun Zhao, Li Xiong, Yuhan Liu et al.AAAI 2023 · 18 citations
- Stronger Privacy Amplification by Shuffling for Renyi and Approximate Differential PrivacyVitaly Feldman, Audra McMillan, Kunal TalwarSODA 2023 · 23 citations
- Shuffle Private Linear Contextual BanditsSayak Ray Chowdhury, Xingyu ZhouICML 2022 · 29 citations
- Shuffling-Aware Optimization for Private Vector Mean EstimationShun Takagi, Seng Pei LiewICML 2026 · 2 citations
- Augmented Shuffle Protocols for Accurate and Robust Frequency Estimation Under Differential PrivacyTakao Murakami, Yuichi Sei, Reo EriguchiS&P 2025
