Differential Privacy Guarantees of Markov Chain Monte Carlo Algorithms
Andrea Bertazzi, Tim Johnston, Gareth O. Roberts, Alain Oliviero Durmus
Abstract
This paper aims to provide differential privacy (DP) guarantees for Markov chain Monte Carlo (MCMC) algorithms. In a first part, we establish DP guarantees on samples output by MCMC algorithms as well as Monte Carlo estimators associated with these methods under assumptions on the convergence properties of the underlying Markov chain. In particular, our results highlight the critical condition of ensuring the target distribution is differentially private itself. In a second part, we specialise our analysis to the unadjusted Langevin algorithm and stochastic gradient Langevin dynamics and establish guarantees on their (Rényi) DP. To this end, we develop a novel methodology based on Girsanov's theorem combined with a perturbation trick to obtain bounds for an unbounded domain and in a non-convex setting. We establish: (i) uniform in n privacy guarantees when the state of the chain after n iterations is released, (ii) bounds on the privacy of the entire chain trajectory. These findings provide concrete guidelines for privacy-preserving MCMC.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers1
Ask how each one uses itBuilds on5
- Deep Learning with Differential PrivacyMartín Abadi, Andy Chu, Ian J. Goodfellow, H. Brendan McMahan et al.CCS 2016 · 7,620 citations
- Differential Privacy Dynamics of Langevin Diffusion and Noisy Gradient DescentRishav Chourasia, Jiayuan Ye, Reza ShokriNeurIPS 2021 · 95 citations
- Privacy of Noisy Stochastic Gradient Descent: More Iterations without More Privacy LossJason M. Altschuler, Kunal TalwarNeurIPS 2022 · 89 citations
- Differentially Private Learning Needs Hidden State (Or Much Faster Convergence)Jiayuan Ye, Reza ShokriNeurIPS 2022 · 62 citations
- DP-Fast MH: Private, Fast, and Accurate Metropolis-Hastings for Large-Scale Bayesian InferenceWanrong Zhang, Ruqi ZhangICML 2023 · 4 citations
Related papers
- Tractable MCMC for Private Learning with Pure and Gaussian Differential PrivacyYingyu Lin, Yian Ma, Yu-Xiang Wang, Rachel Redberg et al.ICLR 2024 · 4 citations
- Characterizing Membership Privacy in Stochastic Gradient Langevin DynamicsBingzhe Wu, Chaochao Chen, Shiwan Zhao, Cen Chen et al.AAAI 2020 · 23 citations
- Data Augmentation MCMC for Bayesian Inference from Privatized DataNianqiao Ju, Jordan Awan, Ruobin Gong, Vinayak RaoNeurIPS 2022 · 35 citations
- Black-Box Variational Inference as a Parametric Approximation to Langevin DynamicsMatthew D. Hoffman, Yian MaICML 2020 · 16 citations
- Hyperparameter Tuning with Renyi Differential PrivacyNicolas Papernot, Thomas SteinkeICLR 2022 · 157 citations
