Edit-Neighboring Data Streams and Privacy under Continual Observation
Joel Daniel Andersson, Anamay Chaturvedi, Monika Henzinger, Roodabeh Safavi
摘要
Differential privacy under Continual Observation (CO) quantifies the loss in privacy that occurs when outputs generated using a stream of sensitive input data are published in the online setting. In prior work, this formulation requires that any private mechanism when given as input two neighboring streams that differ in the value of at most one stream element must generate output streams that are almost indistinguishable.
In this paper, we consider a more general notion of privacy wherein an individual's decision to participate in the data collection process may potentially shift the entire stream by a time-step. We define a new notion of edit-neighboring streams that captures this scenario. Our findings are as follows.
First, we prove that on a stream of length T , no additive-noise mechanism achieves additive error less than Ω(minT 1/3 /ε 2/3 , T ) when required to be ε-DP under CO for edit-neighboring streams. In particular, this includes state-of-the-art continual counters constructed via the factorization mechanism that in the standard neighboring setting incur only polylogarithmic additive error.
Second, we construct the first mechanisms with polylogarithmic additive error for our more stringent notion of privacy. We show that we can recover the same additive error as in the standard notion of privacy albeit with worse constant coefficients for both arbitrary input streams and sparse streams.
Third, we show that the notion of edit-neighboring streams inhabits a 'sweet-spot' in terms of generality and additive error incurred. More precisely, we show that the even more general notion of prefix-sum neighboring streams-which arises naturally in reductions for problems under CO-must incur additive error scaling as Ω(minT 1/3 /ε 2/3 , T ) for any mechanism that is ε-DP under continual observation.
Finally, we show empirically on synthetic data that when compared with prior work, our mechanism achieves a superior trade-off between the success probability of a simple distinguishing attack, and the additive error incurred by the respective mechanisms.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
它引用的顶会 Paper25
- Auditing Differentially Private Machine Learning: How Private is Private SGD?Matthew Jagielski, Jonathan R. Ullman, Alina OpreaNeurIPS 2020 · 被引用 354 次
- Adversary Instantiation: Lower Bounds for Differentially Private Machine LearningMilad Nasr, Shuang Song, Abhradeep Thakurta, Nicolas Papernot 等S&P 2021 · 被引用 288 次
- Practical and Private (Deep) Learning Without Sampling or ShufflingPeter Kairouz, Brendan McMahan, Shuang Song, Om Thakkar 等ICML 2021 · 被引用 239 次
- Privacy Auditing with One (1) Training RunThomas Steinke, Milad Nasr, Matthew JagielskiNeurIPS 2023 · 被引用 178 次
- Improved Differential Privacy for SGD via Optimal Private Linear Operators on Adaptive StreamsSergey Denisov, H. Brendan McMahan, John Rush, Adam D. Smith 等NeurIPS 2022 · 被引用 96 次
相关 Paper
- Continual Observation under User-level Differential PrivacyWei Dong, Qiyao Luo, Ke YiS&P 2023
- The Price of Differential Privacy under Continual ObservationPalak Jain, Sofya Raskhodnikova, Satchit Sivakumar, Adam D. SmithICML 2023 · 被引用 63 次
- Counting Distinct Elements in the Turnstile Model with Differential Privacy under Continual ObservationPalak Jain, Iden Kalemaj, Sofya Raskhodnikova, Satchit Sivakumar 等NeurIPS 2023 · 被引用 24 次
- Continual Counting with Gradual Privacy ExpirationJoel Daniel Andersson, Monika Henzinger, Rasmus Pagh, Teresa Anna Steiner 等NeurIPS 2024 · 被引用 4 次
- Skirting Additive Error Barriers for Private Turnstile StreamsAnders Aamand, Justin Y. Chen, Sandeep SilwalICLR 2026 · 被引用 2 次
