Privacy Loss of Noise Perturbation via Concentration Analysis of A Product Measure
Shuainan Liu, Tianxi Ji, Zhongshuo Fang, Lu Wei, Pan Li
摘要
Noise perturbation is one of the most fundamental approaches for achieving (𝜖, 𝛿)-differential privacy (DP) guarantees when releasing the result of a query or function 𝑓 (•) ∈ R 𝑀 evaluated on a sensitive dataset 𝒙. In this approach, calibrated noise n ∈ R 𝑀 is used to obscure the difference vector 𝑓 (𝒙) -𝑓 (𝒙 ′ ), where 𝒙 ′ is known as a neighboring dataset. A DP guarantee is obtained by studying the tail probability bound of a privacy loss random variable (PLRV), defined as the Radon-Nikodym derivative between two distributions. When n follows a multivariate Gaussian distribution, the PLRV is characterized as a specific univariate Gaussian. In this paper, we propose a novel scheme to generate n by leveraging the fact that the perturbation noise is typically spherically symmetric (i.e., the distribution is rotationally invariant around the origin). The new noise generation scheme allows us to investigate the privacy loss from a geometric perspective and express the resulting PLRV using a product measure, 𝑊 × 𝑈 ; measure 𝑊 is related to a radius random variable controlling the magnitude of n, while measure 𝑈 involves a directional random variable governing the angle between n and the difference 𝑓 (𝒙) -𝑓 (𝒙 ′ ). We derive a closed-form moment bound on the product measure to prove (𝜖, 𝛿)-DP. Under the same (𝜖, 𝛿)-DP guarantee, our mechanism yields a smaller expected noise magnitude than the classic Gaussian noise in high dimensions, thereby significantly improving the utility of the noisy result 𝑓 (𝒙) + n. To validate this, we consider privacypreserving convex and non-convex empirical risk minimization (ERM) problems in high dimensional space. We propose leveraging our developed noise in output perturbation, objective perturbation, and gradient perturbation to establish DP guarantees when solving ERMs. Experiments on multiple datasets show that our method achieves significant utility improvements for convex ERM models (e.g., regression and SVM) under the same privacy guarantees. For non-convex models (e.g., neural networks), it provides substantially stronger privacy guarantees under comparable utility. 1
• Theory of computation → Randomness, geometry and discrete structures; • Security and privacy → Data anonymization and sanitization.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
它引用的顶会 Paper10
- Deep Learning with Differential PrivacyMartín Abadi, Andy Chu, Ian J. Goodfellow, H. Brendan McMahan 等CCS 2016 · 被引用 7,620 次
- Numerical Composition of Differential PrivacySivakanth Gopi, Yin Tat Lee, Lukas WutschitzNeurIPS 2021 · 被引用 259 次
- Towards Practical Differentially Private Convex OptimizationRoger Iyengar, Joseph P. Near, Dawn Song, Om Thakkar 等S&P 2019 · 被引用 201 次
- MVG Mechanism: Differential Privacy under Matrix-Valued QueryThee Chanyaswad, Alex Dytso, H. Vincent Poor, Prateek MittalCCS 2018 · 被引用 55 次
- DP-PCA: Statistically Optimal and Differentially Private PCAXiyang Liu, Weihao Kong, Prateek Jain, Sewoong OhNeurIPS 2022 · 被引用 38 次
相关 Paper
- Less is More: Revisiting the Gaussian Mechanism for Differential PrivacyTianxi Ji, Pan LiUSENIX Security 2024 · 被引用 9 次
- A Central Limit Theorem for Differentially Private Query AnsweringJinshuo Dong, Weijie J. Su, Linjun ZhangNeurIPS 2021 · 被引用 21 次
- Geometry of Sensitivity: Twice Sampling and Hybrid Clipping in Differential Privacy with Optimal Gaussian Noise and Application to Deep LearningHanshen Xiao, Jun Wan, Srinivas DevadasCCS 2023 · 被引用 9 次
- Asymptotic Optimality of the High-Dimensional Gaussian Mechanism and Improved Low-Dimensional Mechanisms for Differential PrivacyAlexander Bienstock, Antigoni Polychroniadou, Yu WeiICML 2026
- Analyzing and Optimizing Perturbation of DP-SGD GeometricallyJiawei Duan, Haibo Hu, Qingqing Ye, Xinyue SunICDE 2025 · 被引用 3 次
