Covariance-Aware Private Mean Estimation Without Private Covariance Estimation
Covariance-Aware Private Mean Estimation Without Private Covariance Estimation
复制标题
DOI:
--
复制
发表时间:
2021-06
期刊:
影响因子:
--
通讯作者:
Gavin Brown;Marco Gaboardi;Adam D. Smith;Jonathan Ullman;Lydia Zakynthinou
中科院分区:
文献类型:
--
作者:
Gavin Brown;Marco Gaboardi;Adam D. Smith;Jonathan Ullman;Lydia Zakynthinou
We present two sample-efficient differentially private mean estimators for $d$-dimensional (sub)Gaussian distributions with unknown covariance. Informally, given $n \gtrsim d/\alpha^2$ samples from such a distribution with mean $\mu$ and covariance $\Sigma$, our estimators output $\tilde\mu$ such that $\| \tilde\mu - \mu \|_{\Sigma} \leq \alpha$, where $\| \cdot \|_{\Sigma}$ is the Mahalanobis distance. All previous estimators with the same guarantee either require strong a priori bounds on the covariance matrix or require $\Omega(d^{3/2})$ samples. Each of our estimators is based on a simple, general approach to designing differentially private mechanisms, but with novel technical steps to make the estimator private and sample-efficient. Our first estimator samples a point with approximately maximum Tukey depth using the exponential mechanism, but restricted to the set of points of large Tukey depth. Its accuracy guarantees hold even for data sets that have a small amount of adversarial corruption. Proving that this mechanism is private requires a novel analysis. Our second estimator perturbs the empirical mean of the data set with noise calibrated to the empirical covariance, without releasing the covariance itself. Its sample complexity guarantees hold more generally for subgaussian distributions, albeit with a slightly worse dependence on the privacy parameter. For both estimators, careful preprocessing of the data is required to satisfy differential privacy.