arXiv:2605.28078cs.CRcs.AI2026-05

改进差分隐私噪声机制,显著降低低隐私场景下的噪声幅度。

Mind the Gap: Mixtures of Gaussians in Approximate Differential Privacy

  • 用多个均值不同、方差相同的高斯分布混合构造新噪声机制。
  • 在低隐私条件下,噪声均值和方差明显低于现有方法。
  • 特别适合对隐私预算敏感的实用场景,如医疗数据发布。

我们设计了一类满足(ε, δ)-差分隐私的加性噪声机制,适用于已知敏感度的标量实值查询函数,重点关注中低隐私水平场景。这类机制称为“混合机制”,通过混合多个同方差但均值和权重不同的高斯分布实现,可视为零均值高斯(如解析高斯机制)与依赖查询敏感度的附加高斯分布的凸组合。我们推导出满足(ε, δ)-DP所需的紧致方差条件,并提供了高效的计算算法。相比解析高斯机制,本方法在预期噪声幅值(l₁损失)和零均值分布的方差(l₂损失)上均有显著降低。在驱动本设计的低隐私场景下,该机制逼近最优,几乎消除了解析高斯机制的最优性差距。

原文摘要 · Abstract (English)

We design a class of additive noise mechanisms that satisfy \((\varepsilon, δ)\)-differential privacy (DP) for scalar, real-valued query functions with known sensitivities, with a particular focus on moderate and low-privacy regimes. These mechanisms, which we call \textit{mixture mechanisms}, are constructed by mixing multiple Gaussian distributions that share the same variance but differ in their means and mixture weights. The resulting distributions can be interpreted as convex combinations of a zero-mean Gaussian (as used in the analytic Gaussian mechanism) and additional Gaussians whose means depend on the sensitivity of the query function. We derive tight conditions on the variances required for \((\varepsilon, δ)\)-DP and provide efficient algorithms to compute them. Compared to the analytic Gaussian mechanism, our mechanisms yield substantially lower expected noise amplitudes (\(l_1\)-loss) and variances (\(l_2\)-loss for zero-mean distributions). In the low-privacy regime that motivates our design, our mechanisms approach optimality, mitigating nearly all of the optimality gap of the analytic Gaussian mechanism.

差分隐私高斯机制噪声优化隐私预算

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。