Fully-Adaptive Composition in Differential Privacy
Justin Whitehouse, Aaditya Ramdas, Ryan Rogers, Steven Wu
摘要
Composition is a key feature of differential privacy. Well-known advanced composition theorems allow one to query a private database quadratically more times than basic privacy composition would permit. However, these results require that the privacy parameters of all algorithms be fixed before interacting with the data. To address this, Rogers et al. [2016] introduced fully adaptive composition, wherein both algorithms and their privacy parameters can be selected adaptively. They defined two probabilistic objects to measure privacy in adaptive composition: privacy filters, which provide differential privacy guarantees for composed interactions, and privacy odometers, time-uniform bounds on privacy loss. There are substantial gaps between advanced composition and existing filters and odometers. First, existing filters place stronger assumptions on the algorithms being composed. Second, these odometers and filters suffer from large constants, making them impractical. We construct filters that match the rates of advanced composition, including constants, despite allowing for adaptively chosen privacy parameters. En route we also derive a privacy filter for approximate zCDP. We also construct several general families of odometers. These odometers match the tightness of advanced composition at an arbitrary, preselected point in time, or at all points in time simultaneously, up to a doubly-logarithmic factor. We obtain our results by leveraging advances in martingale concentration. In sum, we show that fully adaptive privacy is obtainable at almost no loss.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper17
- Composition Theorems for Interactive Differential PrivacyXin LyuNeurIPS 2022 · 被引用 29 次
- Brownian Noise Reduction: Maximizing Privacy Subject to Accuracy ConstraintsJustin Whitehouse, Aaditya Ramdas, Zhiwei Steven Wu, Ryan M. RogersNeurIPS 2022 · 被引用 16 次
- Adaptive Randomized Smoothing: Certified Adversarial Robustness for Multi-Step DefencesSaiyue Lyu, Shadab Shaikh, Frederick Shpilevskiy, Evan Shelhamer 等NeurIPS 2024 · 被引用 15 次
- Adaptive Principal Component Regression with Applications to Panel DataAnish Agarwal, Keegan Harris, Justin Whitehouse, Zhiwei Steven WuNeurIPS 2023 · 被引用 10 次
- Cohere: Managing Differential Privacy in Large Scale SystemsNicolas Küchler, Emanuel Opel, Hidde Lycklama, Alexander Viand 等S&P 2024 · 被引用 9 次
它引用的顶会 Paper3
- Hyperparameter Tuning with Renyi Differential PrivacyNicolas Papernot, Thomas SteinkeICLR 2022 · 被引用 157 次
- Individual Privacy Accounting via a Rényi FilterVitaly Feldman, Tijana ZrnicNeurIPS 2021 · 被引用 124 次
- Individual Privacy Accounting with Gaussian Differential PrivacyAntti Koskela, Marlon Tobaben, Antti HonkelaICLR 2023 · 被引用 2 次
相关 Paper
- Concurrent Composition for Interactive Differential Privacy with Adaptive Privacy-Loss ParametersSamuel Haney, Michael Shoemate, Grace Tian, Salil P. Vadhan 等CCS 2023 · 被引用 4 次
- Tight on Budget?: Tight Bounds for r-Fold Approximate Differential PrivacySebastian Meiser, Esfandiar MohammadiCCS 2018 · 被引用 61 次
- Numerical Composition of Differential PrivacySivakanth Gopi, Yin Tat Lee, Lukas WutschitzNeurIPS 2021 · 被引用 259 次
- Optimal Differential Privacy Composition for Exponential MechanismsJinshuo Dong, David Durfee, Ryan RogersICML 2020 · 被引用 52 次
- The Saddle-Point Method in Differential PrivacyWael Alghamdi, Juan Felipe Gómez, Shahab Asoodeh, Flávio P. Calmon 等ICML 2023 · 被引用 16 次
