Implementing the Exponential Mechanism with Base-2 Differential Privacy
Christina Ilvento
摘要
Despite excellent theoretical support, Differential Privacy (DP) can still be a challenge to implement in practice. In part, this challenge is due to the concerns associated with translating arbitrary- or infinite-precision theoretical mechanisms to the reality of floating point or fixed-precision. Beginning with the troubling result of Mironov demonstrating the security issues of using floating point for implementing the Laplace mechanism, there have been many reasonable questions raised concerning the vulnerabilities of real-world implementations of DP. In this work, we examine the practicalities of implementing the exponential mechanism of McSherry and Talwar. We demonstrate that naive or malicious implementations can result in catastrophic privacy failures. To address these problems, we show that the mechanism can be implemented exactly for a rich set of utility functions and values of the privacy parameter epsilon with limited practical overhead in running time and minimal code complexity. How do we achieve this result? We employ a simple trick of switching from base-e to base 2, allowing us to perform precise base-2 arithmetic. A short, precise expression is always available for epsilon, and the only approximation error we incur is the conversion of the base-2 privacy parameter back to base-e for reporting purposes. The core base-2 arithmetic of the mechanism can be simply and efficiently implemented using open-source high precision arithmetic libraries. Furthermore, the exact nature of the implementation lends itself to simple monitoring of correctness and proofs of privacy.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper10
- The Discrete Gaussian for Differential PrivacyClément L. Canonne, Gautam Kamath, Thomas SteinkeNeurIPS 2020 · 被引用 355 次
- Permute-and-Flip: A new mechanism for differentially private selectionRyan McKenna, Daniel SheldonNeurIPS 2020 · 被引用 66 次
- Are We There Yet? Timing and Floating-Point Attacks on Differential Privacy SystemsJiankai Jin, Eleanor McMurtry, Benjamin I. P. Rubinstein, Olga OhrimenkoS&P 2022 · 被引用 57 次
- OpBoost: A Vertical Federated Tree Boosting Framework Based on Order-Preserving DesensitizationXiaochen Li, Yuke Hu, Weiran Liu, Hanwen Feng 等VLDB 2023 · 被引用 42 次
- Secure Multi-party Computation of Differentially Private Heavy HittersJonas Böhler, Florian KerschbaumCCS 2021 · 被引用 34 次
它引用的顶会 Paper1
相关 Paper
- Exact Privacy Guarantees for Markov Chain Implementations of the Exponential Mechanism with Artificial AtomsJeremy Seeman, Matthew Reimherr, Aleksandra B. SlavkovicNeurIPS 2021 · 被引用 12 次
- Verified Foundations for Differential PrivacyMarkus de Medeiros, Muhammad Naveed, Tancrède Lepoint, Temesghen Kahsai 等PLDI 2025 · 被引用 7 次
- Widespread Underestimation of Sensitivity in Differentially Private Libraries and How to Fix ItSílvia Casacuberta, Michael Shoemate, Salil P. Vadhan, Connor WagamanCCS 2022 · 被引用 12 次
- Differentially Private QuantilesJennifer Gillenwater, Matthew Joseph, Alex KuleszaICML 2021 · 被引用 2 次
- DP-Sniper: Black-Box Discovery of Differential Privacy Violations using ClassifiersBenjamin Bichsel, Samuel Steffen, Ilija Bogunovic, Martin T. VechevS&P 2021 · 被引用 53 次
