AI 中文总结
研究持续观测下更严格隐私概念,定义编辑相邻数据流。证明加性噪声机制在该场景下的误差,构建有多项式对数加性误差的机制,表明此概念处于最佳点,实验显示其在攻击成功概率与加性误差间权衡更优。
AI 中文摘要
持续观测下的差分隐私量化了在在线环境中发布使用敏感输入数据流生成的输出时发生的隐私损失。本文考虑了比先前工作更严格的隐私概念,其中个人的参与可能会使整个数据流在时间步长上发生偏移。我们定义了一种新的编辑相邻数据流概念来捕捉这种情况。我们的发现如下:首先,对于长度为\(T\)的数据流,当在持续观测下对编辑相邻数据流要求为\(\varepsilon\)-差分隐私时,每个加性噪声机制都会产生\(\tilde{\Omega}(\min\{T^{1/3}/\varepsilon^{2/3}, T\})\)的误差。其次,我们为更严格的隐私概念构建了第一个具有多项式对数加性误差的机制。第三,编辑相邻数据流的概念在一般性和产生的加性误差方面处于一个“最佳点”。最后,我们在合成数据上通过实验表明,与先前工作相比,我们的机制在简单区分攻击的成功概率和相应机制产生的加性误差之间实现了更好的权衡。
英文摘要
Differential privacy under Continual Observation (CO) quantifies the loss in privacy that occurs when outputs generated using a stream of sensitive input data are published in the online setting. In this paper, we consider a more stringent notion of privacy compared to prior work wherein an individual's participation may shift the entire stream by a time-step. We define a new notion of edit-neighboring streams that captures this scenario. Our findings are as follows. First, we prove that on a stream of length $T$, every additive-noise mechanism incurs error $\tildeΩ(\min\{T^{1/3}/\varepsilon^{2/3}, T\})$ when required to be $\varepsilon$-DP under CO for edit-neighboring streams. This includes state-of-the-art continual counters constructed via the factorization mechanism that in the standard neighboring setting incur only polylogarithmic additive error. Second, we construct the first mechanisms with polylogarithmic additive error for our more stringent notion of privacy. We show that we can recover the same additive error as in the standard notion of privacy albeit with worse constant coefficients for both arbitrary input streams and sparse streams. Third, we show that the notion of edit-neighboring streams inhabits a `sweet-spot' in terms of generality and additive error incurred. More precisely, we show that the even more general notion of prefix-sum neighboring streams---which arises naturally in reductions for problems under CO---must incur additive error scaling as $\tildeΩ(\min\{T^{1/3}/\varepsilon^{2/3}, T\})$ for any mechanism that is $\varepsilon$-DP under continual observation. Finally, we show empirically on synthetic data that when compared with prior work, our mechanism achieves a superior trade-off between the success probability of a simple distinguishing attack, and the additive error incurred by the respective mechanisms.
CommentsTo appear at CCS 2026