ldp mechanism design

Designs and analyzes algorithms that transform individual user values into privatized reports satisfying ε-local differential privacy, including randomized-response and one-bit/binary mechanisms. This includes selecting flip probabilities, output encodings, and any compression or post-processing to minimize utility loss while meeting the LDP constraint.

ldpmechanismdesign

Recent Skill Trend

Momentum and market value over time
Trending
Score
No comparison yet
0.63
Oct 01, 2026Oct 01, 2026
Career
Value
No comparison yet
$200K/year
Oct 01, 2026Oct 01, 2026

Must-Read Papers

Most classic and influential ideas
View more

Balancing privacy budget and data utility remains challenging in Local Differential Privacy (LDP). Method: This paper proposes the Adaptive Bipartite Randomized Response (BRR) mechanism, the first to formulate LDP perturbation as a globally optimal linear programming problem; it rigorously proves that utility maximization is equivalent to maximizing the number of high-value outputs released with the same probability as the true value. BRR achieves this via generalized randomized response modeling, constrained optimization, and downstream-task-aware utility functions—explicitly incorporating distance sensitivity for decision trees and deep learning. Contribution/Results: Theoretical analysis establishes optimality, while empirical evaluation demonstrates that BRR significantly outperforms state-of-the-art continuous- and distributed-LDP mechanisms across diverse benchmarks, improving utility by 20%–50% with near-linear time complexity.

Introducing Bipartite Randomized Response for adaptive LDPMaximizing data utility under Local Differential Privacy constraintsOptimizing privacy-utility trade-off with computationally efficient solutions

Local differential privacy (LDP) inherently degrades data utility due to mandatory noise injection, and existing post-processing (PP) techniques lack systematic, comparative evaluation. Method: We introduce LDP$^3$, the first comprehensive benchmark platform for PP methods—featuring six LDP protocols, seven PP techniques, four utility metrics, and six real-world datasets, implemented via a modular, multithreaded architecture. Contribution/Results: Experiments demonstrate that PP significantly improves utility under low privacy budgets (ε ≤ 1), yielding up to 35% average gain; however, marginal benefits diminish as ε increases. Crucially, PP effectiveness is highly sensitive to data distribution, utility metric, and analytical task—no universally optimal method exists. This work provides the first quantitative characterization of PP’s applicability boundaries and inherent limitations, establishing a reproducible evaluation framework and empirically grounded guidelines for practical LDP deployment.

Comparing performance of PP methods across diverse LDP settingsDeveloping a benchmark platform for optimal PP method selectionEvaluating post-processing methods for improving LDP data utility

Quantifying Classifier Utility under Local Differential Privacy

Jul 03, 2025
YZ
Ye Zheng
🏛️ Rochester Institute of Technology

This paper addresses the theoretical quantification of classifier utility under Local Differential Privacy (LDP). Confronting the challenge that LDP perturbation degrades model performance—particularly for black-box classifiers whose behavior is analytically intractable—the authors propose a novel analytical paradigm: formally linking the distributional concentration properties of LDP mechanisms to the local robustness of classifiers. This yields the first general utility analysis framework applicable to arbitrary LDP mechanisms and black-box classifiers. Two key technical innovations are introduced: (i) refined characterization of distributional concentration under LDP, and (ii) black-box function modeling grounded in robustness theory. Together, they enable predictive, theoretically grounded utility bounds. Experiments demonstrate high accuracy of the derived bounds in low-dimensional settings and reveal that piecewise LDP mechanisms consistently achieve superior utility on canonical classification tasks.

Analyze impact of LDP perturbations on black-box classifiersGuide selection of LDP mechanisms for optimal utilityQuantify classifier utility under local differential privacy

How to Get Actual Privacy and Utility from Privacy Models: the k-Anonymity and Differential Privacy Families

Oct 13, 2025
JD
Josep Domingo-Ferrer
🏛️ Universitat Rovira i Virgili | CYBERCAT-Center for Cybersecurity Research of Catalonia

Existing mainstream privacy models suffer from fundamental limitations: k-anonymity operates syntactically, rendering it vulnerable to background knowledge attacks and lacking semantic constraints; differential privacy faces a sharp utility–privacy trade-off—small privacy budgets cause severe data distortion, while large budgets degrade privacy guarantees. Method: We propose Semantic k-Anonymity, which formally incorporates domain-specific semantic constraints and dependencies among sensitive attributes to reconstruct the equivalence-class partitioning mechanism—enhancing disclosure resistance without compromising data utility. Contribution/Results: Through rigorous formal modeling, principled semantic constraint design, and empirical risk assessment, we demonstrate that Semantic k-Anonymity achieves more robust privacy protection and higher data utility than conventional k-anonymity and differential privacy in realistic settings, thereby reducing reliance on post-hoc risk evaluation.

Current privacy models require costly empirical risk assessmentsDifferential privacy causes excessive utility loss with small budgetsk-anonymity fails to fully prevent data disclosure risks

Improving the Privacy Loss Under User-Level DP Composition for Fixed Estimation Error

May 10, 2024
VA
V. A. Rameshwar
🏛️ Indian Institute of Science

This paper addresses the sequential release of means and variances over multiple mutually exclusive subsets under user-level differential privacy, assuming heterogeneous data and publicly known per-subset user contribution counts. The goal is to maintain fixed statistical estimation error while mitigating the rapid degradation of privacy loss as the number of subsets increases. We propose an iterative algorithm based on user-contribution suppression and, for the first time, derive exact closed-form expressions for the global sensitivity and worst-case bias of mean and variance estimators under truncation/suppression mechanisms. Theoretically, we prove that this mechanism significantly reduces the cumulative privacy budget consumption rate. Empirically, experiments on both real and synthetic datasets demonstrate that, for a fixed estimation error, the privacy loss degradation factor decreases by several-fold; moreover, when the number of users per subset is fixed, the worst-case estimation error is substantially improved.

Improving sample mean and variance release with user suppressionOptimizing privacy loss under fixed worst-case estimation errorReducing privacy loss in differential privacy for disjoint subsets

Latest Papers

What's happening recently
View more

This study addresses a fundamental tension between differential privacy and data valuation: the former requires insensitivity to individual records, while the latter demands precise quantification of each data point’s contribution. The work systematically analyzes how mainstream valuation methods—such as Shapley values and influence functions—fail under differential privacy constraints, identifying high-sensitivity components within these algorithms. It proposes design principles for privacy-friendly valuation mechanisms and employs sensitivity analysis alongside privacy-utility trade-off evaluations to reveal the limitations of current approaches in preserving the discriminative power of rare samples. By delineating the feasible boundaries of private data valuation, this research lays a theoretical foundation for developing practical mechanisms that jointly uphold privacy guarantees and valuation utility.

data valuationdifferential privacyheterogeneous data

This work addresses the challenge non-technical users face in understanding the trade-off between privacy loss parameters and the reliability of statistical inference in differential privacy. By reframing the privacy–utility trade-off within a hypothesis testing framework, the paper introduces the concept of “relative disclosure risk,” which directly links privacy loss parameters to the validity of statistical inference. Through theoretical analysis of how differentially private mechanisms affect the significance of hypothesis tests, the study quantifies the uncertainty introduced by randomization and its effectiveness in mitigating membership inference attacks. The resulting insights yield an actionable guideline for non-expert users to select appropriate privacy mechanisms, thereby promoting transparent deployment and principled configuration of differential privacy in practical applications.

data analysisdifferential privacydisclosure risk

Existing local differential privacy (LDP) protocols lack a systematic and principled approach for comparing privacy strength across diverse adversary models, as reliance solely on the privacy parameter ε or utility metrics proves insufficient for comprehensive evaluation. This work introduces, for the first time, quantitative information flow (QIF) theory and Blackwell’s refinement order into LDP analysis, modeling protocols as probabilistic channels to formally compare seven prominent frequency estimation mechanisms—GRR, BLH, OLH, SUE, OUE, and THE. The proposed framework reveals that several protocols commonly regarded as “optimal” are in fact either strictly dominated by others or incomparable under rigorous information-theoretic criteria. By establishing the first adversary-aware evaluation framework for LDP protocols, this study provides both theoretical foundations and practical guidance for mechanism design and selection.

Attacker ModelsLocal Differential PrivacyPrivacy Comparison

This work addresses the design of optimal mechanisms for binary hypothesis testing under ε-local differential privacy (LDP). It proposes the Sort-Partition-Randomize (SPR) framework, which first orders input symbols by their likelihood ratios, partitions them into contiguous blocks, and then applies randomized response to the block labels. Leveraging this structure, the paper establishes the existence of an optimal mechanism for any privacy budget ε and any f-divergence–based utility objective—including total variation distance and KL divergence—and presents, for the first time, a dynamic programming algorithm that computes such a mechanism exactly in O(k³) time. This approach overcomes prior limitations restricted to asymptotic privacy regimes, enabling efficient computation of optimal mechanisms across the full range of privacy parameters.

binary hypothesis testingf-divergencelocal differential privacy

This work addresses the fundamental challenge in privacy mechanism design: maximizing worst-case utility under strict privacy constraints while avoiding inefficient outputs. It introduces, for the first time, the novel privacy metric Pointwise Maximal Leakage (PML) to this setting and proposes a discrete privacy mechanism that optimizes worst-case utility under hard PML constraints. Crucially, the mechanism permits certain conditional probabilities to be exactly zero—a flexibility prohibited under differential privacy—thereby overcoming a key limitation of traditional approaches. By incorporating output support set constraints, the authors formulate a computationally efficient optimization framework. Experimental results demonstrate that the proposed mechanism consistently outperforms conventional differential privacy methods across multiple benchmarks, achieving superior utility-security trade-offs with low computational complexity.

Discrete mechanismPointwise Maximal LeakagePrivacy mechanism

Hot Scholars

KP

Kirk Pruhs

Professor of Computer Science, University of Pittsburgh
Algorithms
SD

Stark Draper

Professor of ECE, University of Toronto
Information theoryError-correction codingOptimization and AISecurity
AD

Abdulrahman Diaa

PhD Student, University of Waterloo
Privacy-preserving Machine LearningTrustworthy Machine Learning
SK

Sanjeev Kulkarni

Professor of Electrical and Computer Engineering, Princeton University
statistical pattern recognitionmachine learninginformation theorysignal processing
YD

Yon Dohn Chung

Department of Computer Science and Engineering, Korea University
DatabaseData PrivacyBigData