đ€ AI Summary
This study addresses the challenge of approximating polytope John ellipsoids under differential privacy, where handling arbitrary discrepancies in a single constraint remains intractable within the standard model. To overcome this, we propose the first differentially private algorithm for John ellipsoid approximation. Building upon the non-private multiplicative weights update method, our approach projects data onto a Îș-dense distribution set and incorporates a Gaussian noise mechanism to achieve Ï-zCDP privacy guarantees, which is further extended to the minimum enclosing ellipsoid problem. The proposed algorithm computes a (1+Îł)-approximate solution in polynomial time while bounding the number of violated constraints. Under mild data assumptions, it attains theoretical guarantees comparable to those of its non-private counterparts, along with explicit sample complexity bounds.
đ Abstract
We study the problem of approximating the John ellipsoid (JE) of a given (centrally symmetric) polytope of $n$ constraints in a Euclidean space under differential privacy (DP). We give the first differentially private algorithm for this problem under the standard model, where neighboring datasets may differ arbitrarily in one a single constraint. Our work also extends to the complimentary problem of Minimum Enclosing Ellipsoid of $n$ points in the Euclidean space. Our approach is based on the recent non-private multiplicative-weights algorithm of~\cite{pmlr-v99-cohen19a}. First we introduce a non-private generalization of the Cohen et al algorithm, yielding a $(1+\gamma)$-approximation of the JE problem while violating at most $\kappa n$ constraints in $O(\log(1/\kappa)/\gamma)$ iterations. This variant works by projecting the intermediate weights assigned to the constraints onto the set of $\kappa$-dense distributions, similarly to~\cite{bun2020efficientnoisetolerantprivatelearning}. We then design a $\rho$-zCDP variant of this algorithm by adding Gaussian noise to the weighted covariance matrix aggregated in each step of the algorithm. Under a mild goodness assumption on the data we can assert that the resulting noisy matrix is close to the true matrix, thereby achieving essentially the same guarantee as the non-private algorithm provided sufficiently many input points. Thus our method achieves an efficient DP poly-time algorithm under concrete sample complexity bounds.