English

Generalised Likelihood Ratio Testing Adversaries through the Differential Privacy Lens

Cryptography and Security 2022-10-25 v1 Artificial Intelligence Applications

Abstract

Differential Privacy (DP) provides tight upper bounds on the capabilities of optimal adversaries, but such adversaries are rarely encountered in practice. Under the hypothesis testing/membership inference interpretation of DP, we examine the Gaussian mechanism and relax the usual assumption of a Neyman-Pearson-Optimal (NPO) adversary to a Generalized Likelihood Test (GLRT) adversary. This mild relaxation leads to improved privacy guarantees, which we express in the spirit of Gaussian DP and (ε,δ)(\varepsilon, \delta)-DP, including composition and sub-sampling results. We evaluate our results numerically and find them to match the theoretical upper bounds.

Keywords

Cite

@article{arxiv.2210.13028,
  title  = {Generalised Likelihood Ratio Testing Adversaries through the Differential Privacy Lens},
  author = {Georgios Kaissis and Alexander Ziller and Stefan Kolek Martinez de Azagra and Daniel Rueckert},
  journal= {arXiv preprint arXiv:2210.13028},
  year   = {2022}
}
R2 v1 2026-06-28T04:19:54.890Z