证明任何满足基本条件的隐私保护机制都等价于差分隐私
Differential privacy from axioms
- 从四个核心公理出发,构建隐私度量的理论框架
- 任何满足这些公理的隐私机制在样本复杂度上与差分隐私等价
- 揭示差分隐私的不可替代性,适合理论隐私研究者
差分隐私(DP)是理论与实践中公认的隐私标准,但其要求过于严格,需防范极端最坏情况。尽管已有研究探索平均情况下的松弛形式,本文旨在回答:是否存在更弱但仍有意义的隐私概念?我们的核心结论表明:在统计设置下,任何满足非平凡组合性质的合理隐私度量均等价于差分隐私,仅在样本复杂度上存在多项式差异。为此,我们提出四个基本公理:预处理不变性、禁止明显非隐私行为、强组合性与线性可扩展性。主定理证明,满足这四个公理的隐私度量必与差分隐私等价。同时,我们证明这些公理不可简化——任一公理缺失都会导致病态隐私度量。该结果表明,差分隐私在理论上具有不可替代的地位。
原文摘要 · Abstract (English)
Differential privacy (DP) is the de facto notion of privacy both in theory and in practice. However, despite its popularity, DP imposes strict requirements which guard against strong worst-case scenarios. For example, it guards against seemingly unrealistic scenarios where an attacker has full information about all but one point in the data set, and still nothing can be learned about the remaining point. While preventing such a strong attack is desirable, many works have explored whether average-case relaxations of DP are easier to satisfy [HWR13,WLF16,BF16,LWX23]. In this work, we are motivated by the question of whether alternate, weaker notions of privacy are possible: can a weakened privacy notion still guarantee some basic level of privacy, and on the other hand, achieve privacy more efficiently and/or for a substantially broader set of tasks? Our main result shows the answer is no: even in the statistical setting, any reasonable measure of privacy satisfying nontrivial composition is equivalent to DP. To prove this, we identify a core set of four axioms or desiderata: pre-processing invariance, prohibition of blatant non-privacy, strong composition, and linear scalability. Our main theorem shows that any privacy measure satisfying our axioms is equivalent to DP, up to polynomial factors in sample complexity. We complement this result by showing our axioms are minimal: removing any one of our axioms enables ill-behaved measures of privacy.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。