USENIX Security2024Top-tier venue
Less is More: Revisiting the Gaussian Mechanism for Differential Privacy
Tianxi Ji, Pan Li
Abstract
In this paper, we identify that the classic Gaussian mechanism and its variants for differential privacy all suffer from the curse of full-rank covariance matrices, and hence the expected accuracy losses of these mechanisms applied to high dimensional query results, e.g., in , all increase linearly with . To lift this curse, we design a Rank-1 Singular Multivariate Gaussian Mechanism (R1SMG). It achieves -DP on query results in by perturbing the results with noise following a singular multivariate Gaussian distribution, whose covariance matrix is a randomly generated rank-1 positive semi-definite matrix. In contrast, the classic Gaussian mechanism and its variants all consider deterministic full-rank covariance matrices. Our idea is motivated by a clue from Dwork et al.'s work on Gaussian mechanism that has been ignored in the literature: when projecting multivariate Gaussian noise with a full-rank covariance matrix onto a set of orthonormal basis in , only the coefficient of a single basis can contribute to the privacy guarantee. This paper makes the following technical contributions. (i) R1SMG achieves -DP guarantee on query results in , while the magnitude of the additive noise decreases with . Therefore, less is more, i.e., less amount of noise is able to sanitize higher dimensional query results. When , the expected accuracy loss converges to , where is the sensitivity of the query function . (ii) Compared with other mechanisms, R1SMG is less likely to generate noise with large magnitude that overwhelms the query results, because the kurtosis and skewness of the nondeterministic accuracy loss introduced by R1SMG is larger than that introduced by other mechanisms.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 466dafc5-3daa-4f43-bd01-073130b1c8cfCited by top-tier papers3
- Privacy Loss of Noise Perturbation via Concentration Analysis of A Product MeasureShuainan Liu, Tianxi Ji, Zhongshuo Fang, Lu Wei et al.SIGMOD 2026 · 2 citations
- Asymptotic Optimality of the High-Dimensional Gaussian Mechanism and Improved Low-Dimensional Mechanisms for Differential PrivacyAlexander Bienstock, Antigoni Polychroniadou, Yu WeiICML 2026
- How Researchers De-Identify Data in PracticeWentao Guo, Paige Pepitone, Adam J. Aviv, Michelle L. MazurekUSENIX Security 2025
Builds on4
- Deep Learning with Differential PrivacyMartín Abadi, Andy Chu, Ian J. Goodfellow, H. Brendan McMahan et al.CCS 2016 · 7,620 citations
- The Discrete Gaussian for Differential PrivacyClément L. Canonne, Gautam Kamath, Thomas SteinkeNeurIPS 2020 · 355 citations
- Dependence Makes You Vulnberable: Differential Privacy Under Dependent TuplesChangchang Liu, Supriyo Chakraborty, Prateek MittalNDSS 2016 · 210 citations
- MVG Mechanism: Differential Privacy under Matrix-Valued QueryThee Chanyaswad, Alex Dytso, H. Vincent Poor, Prateek MittalCCS 2018 · 55 citations
Related papers
- Mind the Gap: Mixtures of Gaussians in Approximate Differential PrivacyHuikang Liu, Aras Selvi, Wolfram WiesemannICML 2026
- Approximate Differential Privacy of the ℓ2 MechanismMatthew Joseph, Alex Kulesza, Alexander YuICML 2025
- A Central Limit Theorem for Differentially Private Query AnsweringJinshuo Dong, Weijie J. Su, Linjun ZhangNeurIPS 2021 · 21 citations
- Re-Analyze Gauss: Bounds for Private Matrix Approximation via Dyson Brownian MotionOren Mangoubi, Nisheeth K. VishnoiNeurIPS 2022 · 15 citations
- Private Query Release via the Johnson-Lindenstrauss TransformAleksandar NikolovSODA 2023 · 1 citation
