USENIX Security2026Top-tier venue
Residual-PAC Privacy: Automatic Privacy Control Beyond the Gaussian Barrier
Tao Zhang, Yevgeniy Vorobeychik
Abstract
The Probably Approximately Correct (PAC) Privacy framework [xiao2023pac] provides a powerful instance-based methodology to preserve privacy in complex data-driven systems. Existing PAC Privacy algorithms (we call them Auto-PAC) rely on a Gaussian mutual information upper bound. However, we show that the upper bound obtained by Auto-PAC is tight if and only if under the data distribution, the unperturbed output is Gaussian and the noise is independent Gaussian. We propose two approaches for addressing this issue. First, we introduce two tractable post‐processing methods for Auto-PAC, based on Donsker–Varadhan representation and sliced Wasserstein distances. However, the result still leaves "wasted" privacy budget. To address this issue more fundamentally, we introduce Residual-PAC (R-PAC) Privacy, an f-divergence-based measure to quantify privacy that remains after adversarial inference. To implement R-PAC Privacy in practice, we propose a Stackelberg Residual-PAC (SR-PAC) automatic privatization algorithm, a game-theoretic framework that selects optimal noise distributions through convex bilevel optimization. Our approach achieves efficient privacy budget utilization for arbitrary data distributions and naturally composes when multiple mechanisms access the dataset. Our experiments demonstrate that SR-PAC obtains consistently a better privacy-utility tradeoff than both PAC and differential privacy baselines.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext eef9139e-e0c4-4092-ae0c-810b24ffaaafCited by top-tier papers1
Ask how each one uses itBuilds on12
- Deep Learning with Differential PrivacyMartín Abadi, Andy Chu, Ian J. Goodfellow, H. Brendan McMahan et al.CCS 2016 · 7,620 citations
- Membership Inference Attacks Against Machine Learning ModelsReza Shokri, Marco Stronati, Congzheng Song, Vitaly ShmatikovS&P 2017 · 5,137 citations
- Membership Inference Attacks From First PrinciplesNicholas Carlini, Steve Chien, Milad Nasr, Shuang Song et al.S&P 2022 · 1,049 citations
- Machine Learning with Membership Privacy using Adversarial RegularizationMilad Nasr, Reza Shokri, Amir HoumansadrCCS 2018 · 543 citations
- Large Language Models Can Be Strong Differentially Private LearnersXuechen Li, Florian Tramèr, Percy Liang, Tatsunori HashimotoICLR 2022 · 502 citations
Related papers
- PAC Privacy: Automatic Privacy Measurement and Control of Data ProcessingHanshen Xiao, Srinivas DevadasCRYPTO 2023 · 7 citations
- Accuracy-First Rényi Differential Privacy and Post-Processing ImmunityOssi Räisä, Antti Koskela, Antti HonkelaICML 2026
- Shedding a PAC-Bayesian Light on Adaptive Sliced-Wasserstein DistancesRuben Ohana, Kimia Nadjahi, Alain Rakotomamonjy, Liva RalaivolaICML 2023 · 7 citations
- Differentially Private Sliced Wasserstein DistanceAlain Rakotomamonjy, Liva RalaivolaICML 2021 · 26 citations
- Private Hyperparameter Tuning with Ex-Post GuaranteeBadih Ghazi, Pritish Kamath, Alexander Knop, Ravi Kumar et al.NeurIPS 2025 · 4 citations
