English

Local Pan-Privacy for Federated Analytics

Cryptography and Security 2025-03-18 v1 Data Structures and Algorithms Machine Learning

Abstract

Pan-privacy was proposed by Dwork et al. as an approach to designing a private analytics system that retains its privacy properties in the face of intrusions that expose the system's internal state. Motivated by federated telemetry applications, we study local pan-privacy, where privacy should be retained under repeated unannounced intrusions on the local state. We consider the problem of monitoring the count of an event in a federated system, where event occurrences on a local device should be hidden even from an intruder on that device. We show that under reasonable constraints, the goal of providing information-theoretic differential privacy under intrusion is incompatible with collecting telemetry information. We then show that this problem can be solved in a scalable way using standard cryptographic primitives.

Keywords

Cite

@article{arxiv.2503.11850,
  title  = {Local Pan-Privacy for Federated Analytics},
  author = {Vitaly Feldman and Audra McMillan and Guy N. Rothblum and Kunal Talwar},
  journal= {arXiv preprint arXiv:2503.11850},
  year   = {2025}
}
R2 v1 2026-06-28T22:21:19.515Z