Beyond the Calibration Point: Mechanism Comparison in Differential Privacy
Georgios Kaissis, Stefan Kolek, Borja Balle, Jamie Hayes, Daniel Rueckert
Abstract
In differentially private (DP) machine learning, the privacy guarantees of DP mechanisms are often reported and compared on the basis of a single -pair. This practice overlooks that DP guarantees can vary substantially even between mechanisms sharing a given , and potentially introduces privacy vulnerabilities which can remain undetected. This motivates the need for robust, rigorous methods for comparing DP guarantees in such cases. Here, we introduce the -divergence between mechanisms which quantifies the worst-case excess privacy vulnerability of choosing one mechanism over another in terms of , -DP and in terms of a newly presented Bayesian interpretation. Moreover, as a generalisation of the Blackwell theorem, it is endowed with strong decision-theoretic foundations. Through application examples, we show that our techniques can facilitate informed decision-making and reveal gaps in the current understanding of privacy risks, as current practices in DP-SGD often result in choosing mechanisms with high excess privacy vulnerabilities.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers5
- Unifying Re-Identification, Attribute Inference, and Data Reconstruction Risks in Differential PrivacyBogdan Kulynych, Juan Felipe Gómez, Georgios Kaissis, Jamie Hayes et al.NeurIPS 2025 · 15 citations
- Optimal conversion from Rényi Differential Privacy to -Differential PrivacyAnneliese Riess, Felipe Gomez, Flavio Calmon, Julia Schnabel et al.ICML 2026 · 1 citation
- Scaling Laws for Differentially Private Language ModelsRyan McKenna, Yangsibo Huang, Amer Sinha, Borja Balle et al.ICML 2025
- Empirical Privacy VarianceYuzheng Hu, Fan Wu, Ruicheng Xian, Yuhang Liu et al.ICML 2025
- Rethinking the Security of DP-SGD: A Corrected Analysis of Differentially Private Machine LearningWenhao Wang, Shujie Cui, Hui Cui, Xingliang YuanCCS 2026
Builds on8
- Deep Learning with Differential PrivacyMartín Abadi, Andy Chu, Ian J. Goodfellow, H. Brendan McMahan et al.CCS 2016 · 7,620 citations
- Membership Inference Attacks From First PrinciplesNicholas Carlini, Steve Chien, Milad Nasr, Shuang Song et al.S&P 2022 · 1,049 citations
- Numerical Composition of Differential PrivacySivakanth Gopi, Yin Tat Lee, Lukas WutschitzNeurIPS 2021 · 259 citations
- Reconstructing Training Data with Informed AdversariesBorja Balle, Giovanni Cherubin, Jamie HayesS&P 2022 · 214 citations
- Tempered Sigmoid Activations for Deep Learning with Differential PrivacyNicolas Papernot, Abhradeep Thakurta, Shuang Song, Steve Chien et al.AAAI 2021 · 210 citations
Related papers
- Sequentially Auditing Differential PrivacyTomás González Lara, Mateo Dulce-Rubio, Aaditya Ramdas, Mónica RiberoNeurIPS 2025 · 6 citations
- Mind the Gap: Mixtures of Gaussians in Approximate Differential PrivacyHuikang Liu, Aras Selvi, Wolfram WiesemannICML 2026
- Balancing Privacy and Utility in Correlated Data: A Study of Bayesian Differential PrivacyMartin Lange, Patricia Guerra-Balboa, Javier Parra-Arnau, Thorsten StrufeVLDB 2025 · 2 citations
- Shifted Interpolation for Differential PrivacyJinho Bok, Weijie J. Su, Jason M. AltschulerICML 2024 · 12 citations
- Exactly Minimax-Optimal Locally Differentially Private SamplingHyun-Young Park, Shahab Asoodeh, Si-Hyeon LeeNeurIPS 2024 · 7 citations
