Accuracy-First Rényi Differential Privacy and Post-Processing Immunity
Ossi Räisä, Antti Koskela, Antti Honkela
Abstract
The accuracy-first perspective of differential privacy addresses an important shortcoming by allowing a data analyst to adaptively adjust the quantitative privacy bound instead of sticking to a predetermined bound. Existing works on the accuracy-first perspective have neglected an important property of differential privacy known as post-processing immunity, which ensures that an adversary is not able to weaken the privacy guarantee by post-processing. We address this gap by determining which existing definitions in the accuracy-first perspective have post-processing immunity, and which do not. The only definition with post-processing immunity, pure ex-post privacy, lacks useful tools for practical problems, such as an ex-post analogue of the Gaussian mechanism, and an algorithm to check if accuracy on separate private validation set is high enough. To address this, we propose a new definition based on Rényi differential privacy that has post-processing immunity, and we develop basic theory and tools needed for practical applications. We demonstrate the practicality of our theory with applications to synthetic data generation and image classifier fine-tuning, where our algorithm successfully adjusts the privacy bound until an accuracy threshold is met on a private validation dataset.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Builds on12
- An Image is Worth 16x16 Words: Transformers for Image Recognition at ScaleAlexey Dosovitskiy, Lucas Beyer, Alexander Kolesnikov, Dirk Weissenborn et al.ICLR 2021 · 21,477 citations
- Deep Learning with Differential PrivacyMartín Abadi, Andy Chu, Ian J. Goodfellow, H. Brendan McMahan et al.CCS 2016 · 7,620 citations
- Individual Privacy Accounting via a Rényi FilterVitaly Feldman, Tijana ZrnicNeurIPS 2021 · 124 citations
- Fully-Adaptive Composition in Differential PrivacyJustin Whitehouse, Aaditya Ramdas, Ryan Rogers, Steven WuICML 2023 · 56 citations
- Improving Sparse Vector Technique with Renyi Differential PrivacyYuqing Zhu, Yu-Xiang WangNeurIPS 2020 · 25 citations
Related papers
- Adaptive Privacy Composition for Accuracy-first MechanismsRyan M. Rogers, Gennady Samorodnitsky, Zhiwei Steven Wu, Aaditya RamdasNeurIPS 2023 · 6 citations
- Private Hyperparameter Tuning with Ex-Post GuaranteeBadih Ghazi, Pritish Kamath, Alexander Knop, Ravi Kumar et al.NeurIPS 2025 · 4 citations
- Bias and Variance of Post-processing in Differential PrivacyKeyu Zhu, Pascal Van Hentenryck, Ferdinando FiorettoAAAI 2021 · 46 citations
- Persuasive PrivacyJoshua J Bon, James Bailie, Judith Rousseau, Christian P RobertICML 2026
- PAC Privacy: Automatic Privacy Measurement and Control of Data ProcessingHanshen Xiao, Srinivas DevadasCRYPTO 2023 · 7 citations
