Lune

SIGMOD2026Top-tier venue

Privacy Loss of Noise Perturbation via Concentration Analysis of A Product Measure

Shuainan Liu, Tianxi Ji, Zhongshuo Fang, Lu Wei, Pan Li

2026Year
2Citations

Abstract

Noise perturbation is one of the most fundamental approaches for achieving (๐œ–, ๐›ฟ)-differential privacy (DP) guarantees when releasing the result of a query or function ๐‘“ (โ€ข) โˆˆ R ๐‘€ evaluated on a sensitive dataset ๐’™. In this approach, calibrated noise n โˆˆ R ๐‘€ is used to obscure the difference vector ๐‘“ (๐’™) -๐‘“ (๐’™ โ€ฒ ), where ๐’™ โ€ฒ is known as a neighboring dataset. A DP guarantee is obtained by studying the tail probability bound of a privacy loss random variable (PLRV), defined as the Radon-Nikodym derivative between two distributions. When n follows a multivariate Gaussian distribution, the PLRV is characterized as a specific univariate Gaussian. In this paper, we propose a novel scheme to generate n by leveraging the fact that the perturbation noise is typically spherically symmetric (i.e., the distribution is rotationally invariant around the origin). The new noise generation scheme allows us to investigate the privacy loss from a geometric perspective and express the resulting PLRV using a product measure, ๐‘Š ร— ๐‘ˆ ; measure ๐‘Š is related to a radius random variable controlling the magnitude of n, while measure ๐‘ˆ involves a directional random variable governing the angle between n and the difference ๐‘“ (๐’™) -๐‘“ (๐’™ โ€ฒ ). We derive a closed-form moment bound on the product measure to prove (๐œ–, ๐›ฟ)-DP. Under the same (๐œ–, ๐›ฟ)-DP guarantee, our mechanism yields a smaller expected noise magnitude than the classic Gaussian noise in high dimensions, thereby significantly improving the utility of the noisy result ๐‘“ (๐’™) + n. To validate this, we consider privacypreserving convex and non-convex empirical risk minimization (ERM) problems in high dimensional space. We propose leveraging our developed noise in output perturbation, objective perturbation, and gradient perturbation to establish DP guarantees when solving ERMs. Experiments on multiple datasets show that our method achieves significant utility improvements for convex ERM models (e.g., regression and SVM) under the same privacy guarantees. For non-convex models (e.g., neural networks), it provides substantially stronger privacy guarantees under comparable utility. 1

โ€ข Theory of computation โ†’ Randomness, geometry and discrete structures; โ€ข Security and privacy โ†’ Data anonymization and sanitization.

Ask about this paper

Your agent reads all of it.

Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.

Questions to start from

Your agent calls

Luneget_paper_fulltext

Ask in Lune

Free to start. No credit card required.

lune papers fulltext 4eb19f0c-3077-42da-90a1-3ac8e52f2202

Builds on10

Related papers

Dusk over the sea between two cliffs drawn in fine vertical lines