John椭球的差分隐私近似
Differentially Private Approximation of the John Ellipsoid
浏览论文内容
中文总结 AI 辅助
本文提出首个标准模型下John椭球近似问题的差分隐私算法,基于乘法权重方法并添加高斯噪声,在温和假设下达到与非私有算法相近的近似保证。
中文摘要 AI 辅助
我们研究了在差分隐私(DP)约束下,对欧几里得空间中由$n$个约束定义的中心对称多胞体的John椭球(JE)进行近似的问题。我们在标准模型下首次给出了该问题的差分隐私算法,其中相邻数据集可能在单个约束上任意不同。我们的工作还扩展到了欧几里得空间中$n$个点的最小包围椭球这一互补问题。我们的方法基于近期Cohen等人提出的非私有乘法权重算法。首先,我们引入了Cohen等人算法的非私有泛化版本,在$O(\log(1/\kappa)/\gamma)$次迭代中,最多违反$\kappa n$个约束,得到JE问题的$(1+\gamma)$近似。该变体通过将分配给约束的中间权重投影到$\kappa$-稠密分布集合上实现,类似于Bun等人的工作。然后,我们通过向算法每一步聚合的加权协方差矩阵添加高斯噪声,设计了该算法的$\rho$-zCDP变体。在数据的温和良好性假设下,我们可以断言得到的噪声矩阵接近真实矩阵,从而在输入点足够多的情况下,实现与非私有算法基本相同的保证。因此,我们的方法在具体的样本复杂度界限下,实现了高效的DP多项式时间算法。
英文摘要
We study the problem of approximating the John ellipsoid (JE) of a given (centrally symmetric) polytope of $n$ constraints in a Euclidean space under differential privacy (DP). We give the first differentially private algorithm for this problem under the standard model, where neighboring datasets may differ arbitrarily in one a single constraint. Our work also extends to the complimentary problem of Minimum Enclosing Ellipsoid of $n$ points in the Euclidean space. Our approach is based on the recent non-private multiplicative-weights algorithm of~\cite{pmlr-v99-cohen19a}. First we introduce a non-private generalization of the Cohen et al algorithm, yielding a $(1+γ)$-approximation of the JE problem while violating at most $κn$ constraints in $O(\log(1/κ)/γ)$ iterations. This variant works by projecting the intermediate weights assigned to the constraints onto the set of $κ$-dense distributions, similarly to~\cite{bun2020efficientnoisetolerantprivatelearning}. We then design a $ρ$-zCDP variant of this algorithm by adding Gaussian noise to the weighted covariance matrix aggregated in each step of the algorithm. Under a mild goodness assumption on the data we can assert that the resulting noisy matrix is close to the true matrix, thereby achieving essentially the same guarantee as the non-private algorithm provided sufficiently many input points. Thus our method achieves an efficient DP poly-time algorithm under concrete sample complexity bounds.