arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

无独立性的隐私放大:负相关性能在多大程度上承载泊松子采样的保证

Privacy Amplification Without Independence: How Far Negative Dependence Carries the Guarantees of Poisson Subsampling

Xujun Che, Depeng Xu

arXiv 2609.01944首次发表:更新:

发表机构

University of North Carolina at Charlotte(北卡罗来纳大学夏洛特分校)

机构由 AI 辅助整理,请以论文原文为准。

AI 中文总结

该研究针对结构化参与场景,明确负关联下隐私放大的条件,揭示整数阶限制、随机分配的优势反转规律及泊松优势的失效阈值,为隐私核算提供严谨替换规则。

AI 中文摘要

泊松子采样是差分隐私优化中的默认采样器,因其独立性使隐私放大易于处理。然而实际系统正转向结构化参与:随机分配(球入箱)、每轮分配、随机签到等方案,被广泛认为在匹配速率下至少与泊松子采样一样私密。我们针对从高斯机制到相关噪声矩阵机制,精确分离并界定支撑这一信念的概率机制:(1)若参与指示向量是负关联(NA)的,则在所有整数Rényi阶α≥2、所有有限参数下,其去方向Rényi散度受限于边际匹配的独立方案;对于固定梯度序列,只要噪声策略的Gram矩阵是符号平衡的(一个可在O(t²)时间内验证的条件),该结论可扩展到机制层面。(2)整数阶限制至关重要:对于k=1的随机分配,我们证明Rényi差准则的线性规律:在大t时,对于所有α<3/2(包括KL散度),优势发生反转,且交叉阶独立于σ趋近于3/2。(3)我们还精确定位了速率匹配泊松优势的已知失效情况:在(1−q)^t以下, hockey-stick排序反转,因此将泊松对代入组合机制是不严谨的;通过上尾论证得到有限交叉点γ_⋆,将该阈值图景与3/2处的Rényi边界关联。这些结果共同为隐私核算提供了替换映射:基于泊松的计算在结构化参与中何时仍严谨、何时失效,以及严谨替代方案在部署中的成本。

英文摘要

Poisson subsampling is the default sampler in differentially private optimization because its independence makes privacy amplification tractable. Practical systems, however, are moving toward structured participation: random allocation (balls-in-bins), per-epoch allocation, random check-ins, schemes widely believed to be at least as private as Poisson subsampling at the matched rate. We isolate the probabilistic mechanism behind this belief and delimit it exactly, for Gaussian mechanisms up to correlated-noise matrix mechanisms. (1) If the participation indicator vector is negatively associated (NA), then at every integer Rényi order $α\ge2$, exactly at all finite parameters, its remove-direction Rényi divergence is dominated by that of the marginal-matched independent scheme. For fixed gradient sequences, this extends to the mechanism level whenever the noise strategy's Gram matrix is sign-balanced, an $O(t^2)$-checkable condition. (2) The integer-order restriction is essential. For random allocation with $k=1$, we prove a linear law for the Rényi-difference criterion: at large $t$, dominance reverses for every $α<3/2$, including KL divergence, while the crossing order tends to $3/2$ independently of $σ$. (3) We also localize the known failure of rate-matched Poisson domination exactly: below $(1-q)^t$, the hockey-stick ordering reverses, so substituting the Poisson pair into composition machinery is unsound. An upper-tail argument yields a finite crossover $γ_\star$, connecting this threshold picture to the Rényi boundary at $3/2$. Together, these results give a substitution map for privacy accounting: when Poisson-based computations remain sound for structured participation, where they fail, and what sound alternatives cost in deployment.

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑