Optimal conversion from R\'enyi Differential Privacy to $f$-Differential Privacy

📅 2026-02-04
📈 Citations: 0
✨ Influential: 0
📄 PDF
🤖 AI Summary
This work investigates the optimal conversion from Rényi differential privacy (RDP) to $f$-differential privacy ($f$-DP) to derive the tightest possible privacy guarantees. By analyzing the geometric structure of RDP privacy regions—particularly their convexity and the boundary characterized by the Bernoulli mechanism—the authors propose a black-box transformation method based on the intersection of single-order RDP regions. This approach achieves global optimality simultaneously across all RDP profiles and Type I error levels, rigorously establishing for the first time a theoretical limit on the $f$-DP bounds inferable solely from RDP information. The resulting tightest $f$-DP bound is given by the pointwise supremum of individual single-order RDP-induced bounds in function space, thereby unifying and strengthening existing results.

Technology Category

Machine Learning: PrivacyReasoning under Uncertainty: Stochastic OptimizationSearch and Optimization: Mixed Discrete/Continuous Search

Application Category

Security and Privacy: Data transparency and provenanceResponsible Web: Data and user privacy-enhancing technologies for the WebUser Modeling, Personalization and Recommendation: User privacy protection in personalized systems
📝 Abstract
We prove the conjecture stated in Appendix F.3 of [Zhu et al. (2022)]: among all conversion rules that map a R\'enyi Differential Privacy (RDP) profile $\tau \mapsto \rho(\tau)$ to a valid hypothesis-testing trade-off $f$, the rule based on the intersection of single-order RDP privacy regions is optimal. This optimality holds simultaneously for all valid RDP profiles and for all Type I error levels $\alpha$. Concretely, we show that in the space of trade-off functions, the tightest possible bound is $f_{\rho(\cdot)}(\alpha) = \sup_{\tau \geq 0.5} f_{\tau,\rho(\tau)}(\alpha)$: the pointwise maximum of the single-order bounds for each RDP privacy region. Our proof unifies and sharpens the insights of [Balle et al. (2019)], [Asoodeh et al. (2021)], and [Zhu et al. (2022)]. Our analysis relies on a precise geometric characterization of the RDP privacy region, leveraging its convexity and the fact that its boundary is determined exclusively by Bernoulli mechanisms. Our results establish that the"intersection-of-RDP-privacy-regions"rule is not only valid, but optimal: no other black-box conversion can uniformly dominate it in the Blackwell sense, marking the fundamental limit of what can be inferred about a mechanism's privacy solely from its RDP guarantees.
Problem

Research questions and friction points this paper is trying to address.

Rényi Differential Privacy
f-Differential Privacy
privacy conversion
hypothesis testing
optimality
Innovation

Methods, ideas, or system contributions that make the work stand out.

Rényi Differential Privacy
f-Differential Privacy
privacy region intersection
hypothesis testing trade-off
Blackwell optimality
🔎 Similar Papers
No similar papers found.
A
Anneliese Riess
Helmholtz Munich, Technical University of Munich
J
Juan Felipe Gomez
Harvard University
F
F. Calmon
Harvard University
J
Julia Anne Schnabel
Helmholtz Munich, Technical University of Munich
G
G. Kaissis
Hasso-Plattner-Institut