🤖 AI Summary
To address slow convergence, poor distribution alignment, and the privacy–utility trade-off in generative modeling of high-dimensional privacy-sensitive data (e.g., biomedical datasets), this paper proposes a differential privacy (DP) synthetic data generation framework based on latent-space noise injection. Methodologically, it introduces the first local (ε,δ)-DP perturbation directly into the latent variable layer of Masked Autoregressive Flows (MAF), coupled with an invertible mapping to ensure bijective correspondence between original and synthetic data. A single tunable parameter governs the privacy budget, and √n statistical consistency is recovered under meta-analytic aggregation. Experiments demonstrate a significant reduction in Wasserstein distance, membership inference attack success rates below 5%, and asymptotic efficiency of aggregated estimators matching classical statistical benchmarks.
📝 Abstract
Synthetic Data Generation has become essential for scalable, privacy-preserving statistical analysis. While standard approaches based on generative models, such as Normalizing Flows, have been widely used, they often suffer from slow convergence in high-dimensional settings, frequently converging more slowly than the canonical $1/sqrt{n}$ rate when approximating the true data distribution. To overcome these limitations, we propose a Latent Noise Injection method using Masked Autoregressive Flows (MAF). Instead of directly sampling from the trained model, our method perturbs each data point in the latent space and maps it back to the data domain. This construction preserves a one to one correspondence between observed and synthetic data, enabling synthetic outputs that closely reflect the underlying distribution, particularly in challenging high-dimensional regimes where traditional sampling struggles. Our procedure satisfies local $(epsilon, delta)$-differential privacy and introduces a single perturbation parameter to control the privacy-utility trade-off. Although estimators based on individual synthetic datasets may converge slowly, we show both theoretically and empirically that aggregating across $K$ studies in a meta analysis framework restores classical efficiency and yields consistent, reliable inference. We demonstrate that with a well-calibrated perturbation parameter, Latent Noise Injection achieves strong statistical alignment with the original data and robustness against membership inference attacks. These results position our method as a compelling alternative to conventional flow-based sampling for synthetic data sharing in decentralized and privacy-sensitive domains, such as biomedical research.