研究量子学习中隐私与效用的权衡,给出最优保护方案。
Privacy-Utility Tradeoffs in Quantum Information Processing
- 用量子局部差分隐私定义隐私,以保真度和迹距离衡量效用。
- 证明去极化机制在通用场景下最优,且学习可观测量需Θ((εβ)⁻²)样本。
- 首次将私有量子假设检验下界用于实际任务,适合量子机器学习研究者。
当敏感信息编码于数据中时,从数据中学习有用信息的同时需保障隐私。隐私与效用之间存在自然权衡:提高隐私要求可能降低学习协议效用。在量子差分隐私框架下,这种权衡迄今尚未被深入研究。本文研究在$(\varepsilon,δ)$-量子局部差分隐私约束下,通用与特定应用效用指标的最优隐私-效用权衡。在通用情形下,优化原始态与私有化态之间的保真度与迹距离,证明去极化机制在给定隐私条件下达到最优效用。针对输入态可观测量期望值的学习任务,推导出在高概率下实现固定精度所需私有数据样本数的下界,借助现有私有量子假设检验的下界完成证明,首次展示其操作性应用。同时设计出在隐私参数与精度参数下达到最优样本复杂度的私有机制,表明特定任务中效用可显著优于通用设置。此外,发现私有学习可观测量期望值所需样本量为$Θ((\varepsilon β)^{-2})$,其中$\varepsilon \in (0,1)$为隐私参数,$β$为精度容差。最后,初步探讨私有经典阴影,其在私有学习任务中具有潜在应用价值。
原文摘要 · Abstract (English)
When sensitive information is encoded in data, it is important to ensure the privacy of information when attempting to learn useful information from the data. There is a natural tradeoff whereby increasing privacy requirements may decrease the utility of a learning protocol. In the quantum setting of differential privacy, such tradeoffs between privacy and utility have so far remained largely unexplored. In this work, we study optimal privacy-utility tradeoffs for both generic and application-specific utility metrics when privacy is quantified by $(\varepsilon,δ)$-quantum local differential privacy. In the generic setting, we focus on optimizing fidelity and trace distance between the original state and the privatized state. We show that the depolarizing mechanism achieves the optimal utility for given privacy requirements. We then study the specific application of learning the expectation of an observable with respect to an input state when only given access to privatized states. We derive a lower bound on the number of samples of privatized data required to achieve a fixed accuracy guarantee with high probability. To prove this result, we employ existing lower bounds on private quantum hypothesis testing, thus showcasing the first operational use of them. We also devise private mechanisms that achieve optimal sample complexity with respect to the privacy parameters and accuracy parameters, demonstrating that utility can be significantly improved for specific tasks in contrast to the generic setting. In addition, we show that the number of samples required to privately learn observable expectation values scales as $Θ((\varepsilon β)^{-2})$, where $\varepsilon \in (0,1)$ is the privacy parameter and $β$ is the accuracy tolerance. We conclude by initiating the study of private classical shadows, which promise useful applications for private learning tasks.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。