用黎曼几何的黎曼距离重定义差分隐私,提升多轮计算的隐私保障。
Rao Differential Privacy
- 以黎曼距离替代传统密度散度,从信息几何角度定义隐私
- 在连续多轮隐私计算中,隐私预算衰减更慢,组合结果更优
- 适合关注长期隐私保护的系统设计者和算法研究人员
差分隐私(DP)近年来成为发布隐私估计的标准定义,其通过将噪声校准至个体贡献的量级,使单个个体信息被隐藏的同时保持估计的实用性。自最初定义以来,已有多种替代定义被提出,旨在改进组合性质、放宽条件或形式化表达。然而,至今几乎所有隐私定义均基于密度之间的散度。本文从信息几何视角重新审视差分隐私,不依赖散度,而是采用黎曼距离(Rao distance)作为隐私定义的基础。我们证明所提出的隐私定义保留了原有定义的直观解释,同时在顺序组合方面表现更优,能更有效地控制多轮计算中的隐私泄露。
原文摘要 · Abstract (English)
Differential privacy (DP) has recently emerged as a definition of privacy to release private estimates. DP calibrates noise to be on the order of an individuals contribution. Due to the this calibration a private estimate obscures any individual while preserving the utility of the estimate. Since the original definition, many alternate definitions have been proposed. These alternates have been proposed for various reasons including improvements on composition results, relaxations, and formalizations. Nevertheless, thus far nearly all definitions of privacy have used a divergence of densities as the basis of the definition. In this paper we take an information geometry perspective towards differential privacy. Specifically, rather than define privacy via a divergence, we define privacy via the Rao distance. We show that our proposed definition of privacy shares the interpretation of previous definitions of privacy while improving on sequential composition.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。