English

Bias and Variance of Post-processing in Differential Privacy

Machine Learning 2020-10-12 v1 Artificial Intelligence Cryptography and Security

Abstract

Post-processing immunity is a fundamental property of differential privacy: it enables the application of arbitrary data-independent transformations to the results of differentially private outputs without affecting their privacy guarantees. When query outputs must satisfy domain constraints, post-processing can be used to project the privacy-preserving outputs onto the feasible region. Moreover, when the feasible region is convex, a widely adopted class of post-processing steps is also guaranteed to improve accuracy. Post-processing has been applied successfully in many applications including census data-release, energy systems, and mobility. However, its effects on the noise distribution is poorly understood: It is often argued that post-processing may introduce bias and increase variance. This paper takes a first step towards understanding the properties of post-processing. It considers the release of census data and examines, both theoretically and empirically, the behavior of a widely adopted class of post-processing functions.

Keywords

Cite

@article{arxiv.2010.04327,
  title  = {Bias and Variance of Post-processing in Differential Privacy},
  author = {Keyu Zhu and Pascal Van Hentenryck and Ferdinando Fioretto},
  journal= {arXiv preprint arXiv:2010.04327},
  year   = {2020}
}
R2 v1 2026-06-23T19:11:40.602Z