Private Online Learning against an Adaptive Adversary: Realizable and Agnostic Settings

📅 2025-10-01
📈 Citations: 0
✨ Influential: 0
📄 PDF
🤖 AI Summary
This paper studies online learning against adaptive adversaries under differential privacy constraints, addressing both the realizable and agnostic settings. Building on Littlestone dimension theory, we propose the first differentially private algorithm that simultaneously ensures strong performance guarantees: it achieves an $O_d(log T)$ mistake bound in the realizable setting and a $ ilde{O}_d(sqrt{T})$ sublinear regret in the agnostic setting. Our work closes a fundamental gap in the optimization of mistake bounds for private online learning against adaptive adversaries and constitutes the first systematic extension of differentially private online learning to the agnostic setting. Crucially, we provide a rigorous proof that all concept classes with finite Littlestone dimension are learnable under differential privacy in both settings. This result substantially advances the theoretical foundations of private online learning, unifying and generalizing prior analyses limited to the realizable case or oblivious adversaries.

Technology Category

Machine Learning: Online Learning & BanditsGame Theory and Economic Paradigms: Adversarial LearningSearch and Optimization: Learning to Search

Application Category

Search and Retrieval-Augmented AI: Web learning to rank, online learning, and counterfactual learning for rankingEconomics, Online Markets and Human Computation: Fairness, privacy, and diversity in economic environmentsSecurity and Privacy: Large-scale security measurements
📝 Abstract
We revisit the problem of private online learning, in which a learner receives a sequence of $T$ data points and has to respond at each time-step a hypothesis. It is required that the entire stream of output hypotheses should satisfy differential privacy. Prior work of Golowich and Livni [2021] established that every concept class $mathcal{H}$ with finite Littlestone dimension $d$ is privately online learnable in the realizable setting. In particular, they proposed an algorithm that achieves an $O_{d}(log T)$ mistake bound against an oblivious adversary. However, their approach yields a suboptimal $ ilde{O}_{d}(sqrt{T})$ bound against an adaptive adversary. In this work, we present a new algorithm with a mistake bound of $O_{d}(log T)$ against an adaptive adversary, closing this gap. We further investigate the problem in the agnostic setting, which is more general than the realizable setting as it does not impose any assumptions on the data. We give an algorithm that obtains a sublinear regret of $ ilde{O}_d(sqrt{T})$ for generic Littlestone classes, demonstrating that they are also privately online learnable in the agnostic setting.
Problem

Research questions and friction points this paper is trying to address.

Achieving private online learning with logarithmic mistakes against adaptive adversaries
Extending private online learning to agnostic settings with sublinear regret
Closing the performance gap between oblivious and adaptive adversaries in private learning
Innovation

Methods, ideas, or system contributions that make the work stand out.

Achieves O_d(log T) mistake bound against adaptive adversary
Provides sublinear regret of O_d(sqrt T) in agnostic setting
Uses private online learning for Littlestone concept classes
🔎 Similar Papers
No similar papers found.
B
Bo Li
Department of Computer Science and Engineering, HKUST
W
Wei Wang
Department of Computer Science and Engineering, HKUST
P
Peng Ye
Department of Computer Science and Engineering, HKUST