English

Privacy Amplification by Subsampling: Tight Analyses via Couplings and Divergences

Machine Learning 2018-11-26 v2 Cryptography and Security Machine Learning

Abstract

Differential privacy comes equipped with multiple analytical tools for the design of private data analyses. One important tool is the so-called "privacy amplification by subsampling" principle, which ensures that a differentially private mechanism run on a random subsample of a population provides higher privacy guarantees than when run on the entire population. Several instances of this principle have been studied for different random subsampling methods, each with an ad-hoc analysis. In this paper we present a general method that recovers and improves prior analyses, yields lower bounds and derives new instances of privacy amplification by subsampling. Our method leverages a characterization of differential privacy as a divergence which emerged in the program verification community. Furthermore, it introduces new tools, including advanced joint convexity and privacy profiles, which might be of independent interest.

Keywords

Cite

@article{arxiv.1807.01647,
  title  = {Privacy Amplification by Subsampling: Tight Analyses via Couplings and Divergences},
  author = {Borja Balle and Gilles Barthe and Marco Gaboardi},
  journal= {arXiv preprint arXiv:1807.01647},
  year   = {2018}
}

Comments

To appear in NeurIPS 2018

R2 v1 2026-06-23T02:50:50.591Z