Rényi Pufferfish Privacy: General Additive Noise Mechanisms and Privacy Amplification by Iteration via Shift Reduction Lemmas
Clément Pierquin, Aurélien Bellet, Marc Tommasi, Matthieu Boussard
Abstract
Pufferfish privacy is a flexible generalization of differential privacy that allows to model arbitrary secrets and adversary's prior knowledge about the data. Unfortunately, designing general and tractable Pufferfish mechanisms that do not compromise utility is challenging. Furthermore, this framework does not provide the composition guarantees needed for a direct use in iterative machine learning algorithms. To mitigate these issues, we introduce a Rényi divergence-based variant of Pufferfish and show that it allows us to extend the applicability of the Pufferfish framework. We first generalize the Wasserstein mechanism to cover a wide range of noise distributions and introduce several ways to improve its utility. We also derive stronger guarantees against out-of-distribution adversaries. Finally, as an alternative to composition, we prove privacy amplification results for contractive noisy iterations and showcase the first use of Pufferfish in private convex optimization. A common ingredient underlying our results is the use and extension of shift reduction lemmas.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 3545efce-b60b-415d-b3c3-de5f45fff616Cited by top-tier papers4
- Residual-PAC Privacy: Automatic Privacy Control Beyond the Gaussian BarrierTao Zhang, Yevgeniy VorobeychikUSENIX Security 2026 · 4 citations
- Composition for Pufferfish PrivacyJiamu Bai, Guanlin He, Xin Gu, Daniel Kifer et al.VLDB 2026 · 1 citation
- On the Private Estimation of Smooth Transport MapsClément Lalanne, Franck Iutzeler, Jean-Michel Loubes, Julien ChhorICML 2025
- Sliced Rényi Pufferfish Privacy: Tractable Privatization Mechanism and Private Learning with Gradient ClippingTao Zhang, Yevgeniy VorobeychikUSENIX Security 2026
Builds on5
- Deep Learning with Differential PrivacyMartín Abadi, Andy Chu, Ian J. Goodfellow, H. Brendan McMahan et al.CCS 2016 · 7,620 citations
- Hyperparameter Tuning with Renyi Differential PrivacyNicolas Papernot, Thomas SteinkeICLR 2022 · 157 citations
- On the Loss Landscape of Adversarial Training: Identifying Challenges and How to Overcome ThemChen Liu, Mathieu Salzmann, Tao Lin, Ryota Tomioka et al.NeurIPS 2020 · 103 citations
- Privacy of Noisy Stochastic Gradient Descent: More Iterations without More Privacy LossJason M. Altschuler, Kunal TalwarNeurIPS 2022 · 89 citations
- Faster high-accuracy log-concave sampling via algorithmic warm startsJason M. Altschuler, Sinho ChewiFOCS 2023 · 6 citations
Related papers
- Shifted Interpolation for Differential PrivacyJinho Bok, Weijie J. Su, Jason M. AltschulerICML 2024 · 12 citations
- Convergent Privacy Loss of Noisy-SGD without Convexity and SmoothnessEli Chien, Pan LiICLR 2025
- Differential Privacy Dynamics of Langevin Diffusion and Noisy Gradient DescentRishav Chourasia, Jiayuan Ye, Reza ShokriNeurIPS 2021 · 95 citations
- From Noisy Fixed-Point Iterations to Private ADMM for Centralized and Federated LearningEdwige Cyffers, Aurélien Bellet, Debabrota BasuICML 2023 · 6 citations
- Unified Enhancement of Privacy Bounds for Mixture Mechanisms via f-Differential PrivacyChendi Wang, Buxin Su, Jiayuan Ye, Reza Shokri et al.NeurIPS 2023 · 22 citations
