English

Infinitely Divisible Noise in the Low Privacy Regime

Machine Learning 2022-03-08 v3 Cryptography and Security Data Structures and Algorithms

Abstract

Federated learning, in which training data is distributed among users and never shared, has emerged as a popular approach to privacy-preserving machine learning. Cryptographic techniques such as secure aggregation are used to aggregate contributions, like a model update, from all users. A robust technique for making such aggregates differentially private is to exploit infinite divisibility of the Laplace distribution, namely, that a Laplace distribution can be expressed as a sum of i.i.d. noise shares from a Gamma distribution, one share added by each user. However, Laplace noise is known to have suboptimal error in the low privacy regime for ε\varepsilon-differential privacy, where ε>1\varepsilon > 1 is a large constant. In this paper we present the first infinitely divisible noise distribution for real-valued data that achieves ε\varepsilon-differential privacy and has expected error that decreases exponentially with ε\varepsilon.

Keywords

Cite

@article{arxiv.2110.06559,
  title  = {Infinitely Divisible Noise in the Low Privacy Regime},
  author = {Rasmus Pagh and Nina Mesing Stausholm},
  journal= {arXiv preprint arXiv:2110.06559},
  year   = {2022}
}

Comments

To appear at International Conference on Algorithmic Learning Theory (ALT), 2022