发表机构
Institute of Science and Technology Austria; BARC University of Copenhagen(奥地利科学与技术研究所; 哥本哈根大学BARC)
机构由 AI 辅助整理,请以论文原文为准。AI 中文总结
研究提出抖动高斯机制用于差分隐私,将离散化用于隐私输出,继承高斯机制隐私保证且避免浮点漏洞。该机制随机性高效,通过分离随机性来源减少随机比特数,应用于模型训练可实现安全噪声生成且开销适度。
AI 中文摘要
我们提出了抖动高斯机制,这是一种用于差分隐私的离散高斯机制的新型替代方案,它对隐私输出进行离散化而非噪声分布本身。通过将这种离散化解释为高斯机制的后处理,我们的构造直接继承了标准高斯机制的隐私保证,同时避免了由有限精度浮点输出引起的漏洞。我们表明该机制在随机性上是高效的:通过直接对离散化输出值进行采样,隐私所需的高质量随机比特数可显著减少且与噪声水平无关。这通过将随机性分为两个来源实现:用于隐私关键采样步骤的高质量源,以及可能为对手所知的高性能公共源,它为随机离散化提供所需的额外随机性。这种分离使得能够使用密码学安全的随机性而不会有显著性能损失。作为应用,我们研究了使用差分隐私随机梯度下降进行模型训练,并表明可以通过适度的实际开销实现具有减少浮点漏洞暴露的密码学安全噪声生成。
英文摘要
We present the dithered Gaussian mechanism, an alternative to the discrete Gaussian mechanism for differential privacy that discretizes the private output rather than the noise distribution itself. By interpreting this discretization as post-processing of the Gaussian mechanism, our construction directly inherits the privacy guarantees of the standard Gaussian mechanism while avoiding vulnerabilities caused by finite-precision floating-point outputs. In addition, the mechanism is provably randomness-efficient: by sampling the discretized output values directly, the number of high-quality random bits required for privacy can be reduced significantly and made independent of the noise level. This is achieved by separating the randomness into two sources: a high-quality source used for the privacy-critical sampling step, and a high-performance public source, possibly known to the adversary, that supplies the additional randomness needed for randomized discretization. This separation enables the use of cryptographically secure randomness without substantial performance loss. As an application, we study model training with DP-SGD and show that cryptographically secure noise generation with reduced exposure to floating-point vulnerabilities can be achieved with modest practical overhead.
CommentsImproved Sampling Algorithm + Numerical Comparison with Baselines