Residual-PAC Privacy: Automatic Privacy Control Beyond the Gaussian Barrier
Tao Zhang, Yevgeniy Vorobeychik
摘要
The Probably Approximately Correct (PAC) Privacy framework [xiao2023pac] provides a powerful instance-based methodology to preserve privacy in complex data-driven systems. Existing PAC Privacy algorithms (we call them Auto-PAC) rely on a Gaussian mutual information upper bound. However, we show that the upper bound obtained by Auto-PAC is tight if and only if under the data distribution, the unperturbed output is Gaussian and the noise is independent Gaussian. We propose two approaches for addressing this issue. First, we introduce two tractable post‐processing methods for Auto-PAC, based on Donsker–Varadhan representation and sliced Wasserstein distances. However, the result still leaves "wasted" privacy budget. To address this issue more fundamentally, we introduce Residual-PAC (R-PAC) Privacy, an f-divergence-based measure to quantify privacy that remains after adversarial inference. To implement R-PAC Privacy in practice, we propose a Stackelberg Residual-PAC (SR-PAC) automatic privatization algorithm, a game-theoretic framework that selects optimal noise distributions through convex bilevel optimization. Our approach achieves efficient privacy budget utilization for arbitrary data distributions and naturally composes when multiple mechanisms access the dataset. Our experiments demonstrate that SR-PAC obtains consistently a better privacy-utility tradeoff than both PAC and differential privacy baselines.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper1
问问它们各自怎么用它它引用的顶会 Paper12
- Deep Learning with Differential PrivacyMartín Abadi, Andy Chu, Ian J. Goodfellow, H. Brendan McMahan 等CCS 2016 · 被引用 7,620 次
- Membership Inference Attacks Against Machine Learning ModelsReza Shokri, Marco Stronati, Congzheng Song, Vitaly ShmatikovS&P 2017 · 被引用 5,137 次
- Membership Inference Attacks From First PrinciplesNicholas Carlini, Steve Chien, Milad Nasr, Shuang Song 等S&P 2022 · 被引用 1,049 次
- Machine Learning with Membership Privacy using Adversarial RegularizationMilad Nasr, Reza Shokri, Amir HoumansadrCCS 2018 · 被引用 543 次
- Large Language Models Can Be Strong Differentially Private LearnersXuechen Li, Florian Tramèr, Percy Liang, Tatsunori HashimotoICLR 2022 · 被引用 502 次
相关 Paper
- PAC Privacy: Automatic Privacy Measurement and Control of Data ProcessingHanshen Xiao, Srinivas DevadasCRYPTO 2023 · 被引用 7 次
- Accuracy-First Rényi Differential Privacy and Post-Processing ImmunityOssi Räisä, Antti Koskela, Antti HonkelaICML 2026
- Shedding a PAC-Bayesian Light on Adaptive Sliced-Wasserstein DistancesRuben Ohana, Kimia Nadjahi, Alain Rakotomamonjy, Liva RalaivolaICML 2023 · 被引用 7 次
- Differentially Private Sliced Wasserstein DistanceAlain Rakotomamonjy, Liva RalaivolaICML 2021 · 被引用 26 次
- Private Hyperparameter Tuning with Ex-Post GuaranteeBadih Ghazi, Pritish Kamath, Alexander Knop, Ravi Kumar 等NeurIPS 2025 · 被引用 4 次
