arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

为更大群体提供更好的隐私保障

Better Privacy Guarantees for Larger Groups

Jack Fitzsimons

arXiv 2607.14406首次发表:更新:

AI 中文总结

研究固定不相交群体在添加或删除一个邻接关系下,私密直方图在较大计数时能否允许更多误差以保护较大群体成员的问题,采用移位变换框架得出平方反比率最优,确定了隐私预算对群体大小的最佳依赖关系。

AI 中文摘要

Pujol和Desfontaines提出一个问题:一个私密直方图在较大计数时是否能允许更多误差,并利用该余量更强有力地保护较大群体的成员。我们针对固定不相交群体,在添加或删除一个邻接关系下研究此问题。隐私预算\(v(n)\)取决于受影响的计数,是非递增的,且必须在每个阶数上限制两个Rényi散度方向。这是本文研究的与计数相关形式的零集中差分隐私(zCDP)。原始严格相对误差条件在计数为零时是不可能的。因此,我们通过要求\(\mathbb{E}\lvert\widehat{x}_i - x_i\rvert < r\max\{x_i,1\}\)使边界容差明确,且不改变任何正计数时的要求。我们的主要结果确定了对群体大小的最佳依赖关系。对于上界,我们直接采用现有的移位变换框架。由此产生的移位对数高斯机制有一个经认证预算\(v(n)=O_r(n^{-2})\)。相反,对于每个固定的\(0<r<1\),任何满足相同正计数效用要求和与计数相关的zCDP的机制必须有\(v(n)=\Omega_r(n^{-2})\)。所以在修正公式下,平方反比率是最优的。一个多计数信息论证进一步将大计数然后小误差极限中的首项系数置于\(\pi/(4e^2)\)和\(1/\pi\)之间,相差不到三倍。在\(r = \)1时,一个与数据无关的发布满足修正标准且隐私损失为零。

英文摘要

Pujol and Desfontaines asked whether a private histogram can allow more error on larger counts and use that slack to protect members of larger groups more strongly. We study this question for fixed disjoint groups under add-or-remove-one adjacency. The privacy budget $v(n)$ depends on the affected count, is nonincreasing, and must bound both Rényi-divergence directions at every order. This is the count-dependent form of zero-concentrated differential privacy (zCDP) studied here. The original strict relative-error condition is impossible at count zero. We therefore make the boundary tolerance explicit by requiring $\mathbb{E}\lvert\widehat{x}_i-x_i\rvert < r\max\{x_i,1\}$, without changing the requirement at any positive count. Our main result determines the best dependence on group size. For the upper bound, we directly specialize an existing shifted-transformation framework. The resulting shifted-log Gaussian mechanism has a certified budget $v(n)=O_r(n^{-2})$. Conversely, for every fixed $0<r<1$, any mechanism satisfying the same positive-count utility requirement and count-dependent zCDP must have $v(n)=Ω_r(n^{-2})$. Thus the inverse-square rate is optimal under the repaired formulation. A many-count information argument further places the leading coefficient in the large-count-then-small-error limit between $π/(4e^2)$ and $1/π$, a factor below three. At $r=1$, a data-independent release meets the repaired criterion with zero privacy loss.

Comments20 pages, 2 tables. Addresses the Pujol and Desfontaines open problem under an explicit zero-tolerant formulation. Revised exposition, added theorem-level summary and references; results unchanged

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑