近似差分隐私下广义高斯机制的尺度分析与形状选择
Scale Analysis and Shape Selection for the Generalized Gaussian Mechanism under Approximate Differential Privacy
查看机构详情
- Carleton University(卡尔顿大学)
机构由 AI 辅助整理,请以论文原文为准。
浏览论文内容
中文总结 AI 辅助
本文针对近似差分隐私下的广义高斯机制,研究其尺度估计与形状选择,提出区间式形状搜索算法,优化形状参数可在保证隐私的同时提升效用、降低方差。
中文摘要 AI 辅助
差分隐私为保护隐私信息提供了严格框架,通常通过向查询结果添加随机噪声实现。广义高斯族是一类灵活的加性噪声分布,由形状参数p索引,包含拉普拉斯分布(p=1)和高斯分布(p=2)作为特例。本文研究(ε,δ)-差分隐私下广义高斯机制(GGM)的隐私可行尺度估计与形状参数选择。给定灵敏度向量Δ和p∈[1,∞],令b(p)为满足该隐私要求的尺度参数最小值。一维情况下,b(p)可由方程组隐式表征;对于向量值查询,本文构造了b(p)的可计算上近似,且保留隐私保证。在尺度齐次效用准则下对形状进行比较,以m阶绝对矩为主要示例。本文开发了具有近似保证的区间式形状搜索算法,其近似精度可任意提升;还证明了最优形状在灵敏度向量重标下的不变性,并刻画了高隐私极限下的极限行为。计算实验表明,在多种场景下,优化形状参数可在保持相同隐私保护水平的同时,将各坐标的方差降低5%至20%,部分场景降幅更大;任务特定实验进一步显示,形状优化可提升任务级效用、降低攻击者成功率,或同时实现两者。
英文摘要
Differential privacy provides a rigorous framework for protecting private information, typically achieved by adding random noise to query results. The generalized Gaussian family is a flexible class of additive noise distributions indexed by the shape parameter $p$ and includes the Laplace and Gaussian distributions as special cases $p=1$ and $p=2$, respectively. This paper studies the privacy-feasible scale estimation and the shape parameter selection of the generalized Gaussian mechanism (GGM) under $(\varepsilon,δ)$-differential privacy. For a given sensitivity vector $Δ$ and $p\in[1,\infty]$, let $b(p)$ denote the smallest value of the scale parameter for which the mechanism satisfies this privacy requirement. In the one-dimensional case, $b(p)$ can be implicitly characterized by a system of equations. For vector-valued queries, we construct a computable upper approximation of $b(p)$ that preserves the privacy guarantee. Shapes are compared under a scale-homogeneous utility criterion, with the $m$-th absolute moment as the main example. We develop an interval-wise shape search algorithm with an approximation guarantee that can be made arbitrarily precise. We also establish the invariance of the optimal shape under rescaling of the sensitivity vector and characterize its limiting behaviour under high privacy limits. Computational experiments show that optimizing shape parameters can improve utility by reducing the variance of each coordinate by 5% to 20% across a variety of cases, with some cases showing even greater reductions, while maintaining the same level of privacy protection. Task-specific experiments further show that shape optimization can improve task-level utility, reduce attacker success, or achieve both.