Privacy Amplification by Subsampling: Tight Analyses via Couplings and Divergences

Privacy Amplification by Subsampling: Tight Analyses via Couplings and Divergences
复制标题

DOI:
--
复制
发表时间:
2018-07
期刊:
ArXiv
影响因子:
--
通讯作者:
Borja Balle;G. Barthe;Marco Gaboardi
Borja Balle;G. Barthe;Marco Gaboardi
中科院分区:
其他
文献类型:
--
作者:
Borja Balle;G. Barthe;Marco Gaboardi

文献摘要

被引文献

相似文献

差异隐私配备了多个分析工具,用于设计私人数据分析。一个重要的工具是所谓的“通过次抽样进行隐私放大”原则,该原则确保在随机总体子样本上运行的差别私有机制提供比在整个总体上运行时更高的隐私保证。对于不同的随机二次抽样方法,已经研究了这一原理的几个实例,每种方法都有一个特别的分析。在本文中,我们提出了一种通用的方法,它恢复和改进了先前的分析,得到了下界,并通过次抽样得到了隐私放大的新实例。我们的方法利用了差异隐私的特征作为程序验证社区中出现的分歧。此外,它还引入了新的工具,包括高级联合凸性和隐私配置文件,这可能是独立感兴趣的。
Differential privacy comes equipped with multiple analytical tools for the design of private data analyses. One important tool is the so-called "privacy amplification by subsampling" principle, which ensures that a differentially private mechanism run on a random subsample of a population provides higher privacy guarantees than when run on the entire population. Several instances of this principle have been studied for different random subsampling methods, each with an ad-hoc analysis. In this paper we present a general method that recovers and improves prior analyses, yields lower bounds and derives new instances of privacy amplification by subsampling. Our method leverages a characterization of differential privacy as a divergence which emerged in the program verification community. Furthermore, it introduces new tools, including advanced joint convexity and privacy profiles, which might be of independent interest.