DP-PQD: Privately Detecting Per-Query Gaps In Synthetic Data Generated By Black-Box Mechanisms
Shweta Patwa, Danyu Sun, Amir Gilad, Ashwin Machanavajjhala, Sudeepa Roy
Abstract
Synthetic data generation methods, and in particular, private synthetic data generation methods, are gaining popularity as a means to make copies of sensitive databases that can be shared widely for research and data analysis. Some of the fundamental operations in data analysis include analyzing aggregated statistics, e.g., count, sum, or median, on a subset of data satisfying some conditions. When synthetic data is generated, users may be interested in knowing if their aggregated queries generating such statistics can be reliably answered on the synthetic data, for instance, to decide if the synthetic data is suitable for specific tasks. However, the standard data generation systems do not provide "per-query" quality guarantees on the synthetic data, and the users have no way of knowing how much the aggregated statistics on the synthetic data can be trusted. To address this problem, we present a novel framework named DP-PQD (differentially-private per-query decider) to detect if the query answers on the private and synthetic datasets are within a user-specified threshold of each other while guaranteeing differential privacy. We give a suite of private algorithms for per-query deciders for count, sum, and median queries, analyze their properties, and evaluate them experimentally. Differential Privacy We use Differential Privacy (DP) [11] as the measure of privacy. We say that two databases ๐ท and ๐ท โฒ are neighbors if they differ by a single tuple. This is denoted by ๐ท โ ๐ท โฒ . Definition 2.2 (Differential Privacy [15] ). A randomized mechanism M is said to satisfy ๐-DP if โ๐ โ ๐ ๐๐๐๐ (M) and โ๐ท, ๐ท โฒ pair of neighboring databases, i.e., ๐ท โ ๐ท โฒ , Smaller ๐ gives stronger privacy guarantee. Definition 2.3 (Global Sensitivity). For a scalar query ๐, its global sensitivity is given by ฮ๐ = max ๐ทโ๐ท โฒ |๐(๐ท) -๐(๐ท โฒ )|. Definition 2.4 (Downward Local Sensitivity). For a scalar query ๐, its downward local sensitivity on database ๐ท is given by Example 2.5. Consider the private database ๐ท and sum query ๐ 2 from Example 2.1.Suppose ๐๐๐(๐๐๐๐๐ก๐๐-๐๐๐๐) is 0, 1, . . . , 99999, so ฮ๐ 2 = 99999 since the maximum change in the sum over all pairs of neighboring databases is the maximum value in the domain. On the other hand, given a database ๐ท, ๐ท๐ ๐,๐ท equals the largest value in ๐๐๐๐๐ก๐๐-๐๐๐๐ from tuples in ๐ท with ๐๐๐ข๐๐๐ก๐๐๐ equal to 12-th. Properties like composition [11] and post-processing [13] give a modular way to build complex DP mechanisms: Proposition 2.6. [11, 13] give the following: (1) ) (Parallel composition) If each M ๐ accesses disjoint sets of tuples, then they together satisfy max ๐ ๐ ๐ -DP. (3) (Post-processing) Any function applied to the output of an ๐-DP mechanism M also satisfies ๐-DP. Laplace mechanism (LM). The Laplace mechanism [14] is a common building block in DP mechanisms and is used to get a noisy estimate for scalar queries with numeric answers. The noise injected is calibrated to the global sensitivity of the query.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 9bbd9a7b-a594-4734-9034-a344ee2a9524Cited by top-tier papers3
- Computing Inconsistency Measures Under Differential PrivacyShubhankar Mohapatra, Amir Gilad, Xi He, Benny KimelfeldSIGMOD 2025 ยท 3 citations
- Convergent Privacy Framework for Multi-layer GNNs through Contractive Message PassingYu Zheng, Chenang Li, Zhou Li, Qingsong WangNDSS 2026 ยท 1 citation
- DP-GenG: Differentially Private Dataset Distillation Guided by DP-Generated DataShuo Shi, Jinghuai Zhang, Shijie Jiang, Chunyi Zhou et al.AAAI 2026
Builds on7
- Differentially Private Learning with Adaptive ClippingGalen Andrew, Om Thakkar, Brendan McMahan, Swaroop RamaswamyNeurIPS 2021 ยท 425 citations
- AIM: An Adaptive and Iterative Mechanism for Differentially Private Synthetic DataRyan McKenna, Brett Mullins, Daniel Sheldon, Gerome MiklauVLDB 2022 ยท 136 citations
- Data Synthesis via Differentially Private Markov Random FieldKuntai Cai, Xiaoyu Lei, Jianxin Wei, Xiaokui XiaoVLDB 2021 ยท 98 citations
- New Oracle-Efficient Algorithms for Private Synthetic Data ReleaseGiuseppe Vietri, Grace Tian, Mark Bun, Thomas Steinke et al.ICML 2020 ยท 86 citations
- Instance-optimal Mean Estimation Under Differential PrivacyZiyue Huang, Yuting Liang, Ke YiNeurIPS 2021 ยท 74 citations
Related papers
- An Uncertainty Principle is a Price of Privacy-Preserving MicrodataJohn M. Abowd, Robert Ashmead, Ryan Cumings-Menon, Simson L. Garfinkel et al.NeurIPS 2021 ยท 17 citations
- DPXPlain: Privately Explaining Aggregate Query AnswersYuchao Tao, Amir Gilad, Ashwin Machanavajjhala, Sudeepa RoyVLDB 2023 ยท 15 citations
- Individual Sensitivity Preprocessing for Data PrivacyRachel Cummings, David DurfeeSODA 2020 ยท 29 citations
- Iterative Methods for Private Synthetic Data: Unifying Framework and New MethodsTerrance Liu, Giuseppe Vietri, Steven WuNeurIPS 2021 ยท 85 citations
- Privacy-Enhanced Database Synthesis for Benchmark PublishingYunqing Ge, Jianbin Qin, Shuyuan Zheng, Yongrui Zhong et al.VLDB 2025 ยท 3 citations
