Score
Design and analyze online stopping rules and stopping criteria (thresholds, decision rules, and dynamic-programming policies) that operate on and are implementable using locally differentially private (LDP) reports. Build algorithms and implementations for LDP-aware thresholding, prove optimality or derive tight competitive/profit-inequality style guarantees against benchmarks, and specify how privacy constraints affect the stopping thresholds and performance bounds.
This work addresses the challenge of designing online decision-making platforms that simultaneously optimize utility and preserve privacy in the absence of a trusted central authority, particularly when sensitive valuations are at risk of misuse. It introduces, for the first time, the prophet inequality framework into local differential privacy (LDP), studying optimal stopping under ε-LDP constraints. By integrating randomized response mechanisms with dynamic programming–based threshold rules, the authors devise an irrevocable stopping strategy that maximizes the expected true value of the selected item while guaranteeing privacy. A key insight is that a simple binary LDP mechanism suffices to achieve optimal stopping, and stronger privacy guarantees can surprisingly narrow the performance gap between online algorithms and the prophet benchmark. Tight competitive ratios are established: $e^\varepsilon/(n-1+e^\varepsilon)$ relative to non-private strategies and $(1+e^{-\varepsilon})/2$ relative to an LDP-aware prophet, fully characterizing the privacy–utility trade-off.
This paper studies the thresholded multi-armed bandit problem under local differential privacy (LDP): identifying arms whose expected reward exceeds a given threshold, subject to fixed budget and confidence constraints. We propose a privacy mechanism based on Bernoulli randomized response and develop a unified algorithmic framework that integrates concentration inequality analysis with information-theoretic lower bound derivation to jointly optimize privacy preservation and decision efficiency. We prove that the proposed algorithm achieves a sample complexity within at most a logarithmic factor of the fundamental information-theoretic lower bound for LDP threshold identification—establishing, for the first time, near-optimal trade-offs among estimation error, privacy loss, and sampling efficiency. Extensive experiments demonstrate its high efficiency and robustness in arm identification under strong LDP guarantees, revealing the intrinsic precision limits of sequential decision-making under privacy constraints.
In online stopping problems (e.g., the secretary problem), publicly revealing selected candidates may leak users’ preferences, posing significant privacy risks. Method: This paper pioneers the integration of differential privacy with optimal stopping theory, proposing a tunable parametric mechanism that guarantees ε-differential privacy while enabling controllable utility–privacy trade-offs. Our approach combines randomized response, probabilistic analysis, and competitive ratio analysis to rigorously characterize the accuracy–privacy frontier. Contribution/Results: We prove that, in the classical secretary problem, our mechanism achieves an O(1)-approximation to the optimal expected reward, with a tight trade-off between the privacy budget ε and the approximation ratio. This work establishes the first mathematically rigorous and practically applicable privacy-aware optimal stopping framework, introducing a novel paradigm for privacy-preserving online decision-making.
This work investigates fundamental limitations imposed by differential privacy (DP) on online learning. Addressing the problem of characterizing learnability under privacy constraints, the authors rigorously separate online learnability across three settings: non-private, pure DP, and approximate DP. Methodologically, they integrate tools from online learning theory, VC and Littlestone dimension analysis, adversarial modeling, and probabilistic lower-bound construction. Their contributions are threefold: (i) They prove that approximate DP is necessary to withstand adaptive adversaries, while pure DP fails to ensure learnability for almost all hypothesis classes; (ii) they constructively show that, for nearly all hypothesis classes, every private online learner incurs infinitely many mistakes, establishing a tight infinite-mistake lower bound; and (iii) they provide the first explicit example of a hypothesis class that is online learnable under approximate DP but not under pure DP. These results significantly advance the understanding of the intrinsic privacy–utility trade-off in online learning.
This work addresses the excessive noise in differentially private (DP) linear queries—such as sum, mean, and count—caused by high global sensitivity. We propose a noise-reduction method based on simplex projection: mapping high-sensitivity data onto a fixed-norm probability simplex to reuse privacy loss without increasing the ε budget. We first identify a “free lunch” phenomenon for linear queries on the simplex: redundant queries can be answered with zero additional privacy cost. Leveraging sensitivity analysis, decomposition of linear queries, and algebraic reconstruction, we theoretically prove—and empirically validate—that our method reduces the variance of DP estimates by a factor of O(n) under ε-DP, significantly improving accuracy for mean and sum estimation while preserving strict privacy guarantees.
This work addresses the problem of efficiently learning decision lists and large-margin halfspace classifiers under differential privacy constraints. In the PAC learning model, the authors design a private algorithm that learns decision lists with sample complexity nearly matching that of non-private learners—the first such result in the PAC framework. In the online learning setting, they propose a differentially private variant of the Winnow algorithm that achieves a mistake bound polynomial in the logarithm of the dimension and the inverse of the margin for private halfspace learning. Furthermore, this approach is successfully extended to enable private online learning of decision lists, providing theoretical guarantees in both learning models while preserving privacy.
This paper studies statistical estimation under local differential privacy (LDP) with heterogeneous privacy requirements—where users specify distinct privacy budgets—focusing on one- and multi-dimensional mean estimation and discrete distribution learning under the ℓ∞-distance, with high-probability error bounds (rather than expectation-based guarantees). Methodologically, it integrates customized privacy mechanism design, concentration inequalities, and information-theoretic lower bound analysis. The work establishes the first finite-sample upper bounds for heterogeneous LDP with explicit high-probability guarantees, and provides matching minimax lower bounds, thereby rigorously proving statistical optimality. Specifically, it achieves optimal high-probability ℓ₂-error bounds for mean estimation and high-probability ℓ∞-convergence for distribution learning. These results furnish a theoretical foundation and design principles for personalized LDP mechanisms.
This work addresses the excessive noise introduced by traditional differential privacy in linear query settings, which stems from its disregard for data distribution and consequently degrades utility. By leveraging pointwise maximal leakage (PML) and incorporating prior knowledge of the data distribution, the authors develop a context-aware privacy analysis of the Laplace mechanism, yielding a tight privacy bound applicable to general linear queries. This approach overcomes the distribution-agnostic limitation of standard differential privacy, significantly reducing required noise while maintaining rigorous privacy guarantees. Theoretical analysis demonstrates that the proposed privacy bound is strictly tighter than the conventional differential privacy bound, and numerical experiments confirm that integrating prior distributional knowledge enhances data utility without compromising privacy protection.
This study addresses the challenge that existing differential privacy (DP) auditing methods struggle to detect residual harms in AI systems when developers strategically respond to audit protocols. The authors model privacy auditing as a Stackelberg game, wherein the auditor first commits to a query strategy and privacy budget allocation, and the developer subsequently optimizes mitigation measures in response. To capture the limitations of conventional DP audits, they introduce the welfare-weighted undetected gap metric $B_w$ and demonstrate that optimal auditing requires balancing four key factors. They develop a strategy-aware privacy budget allocation method via bilevel optimization, reformulated into a single-level problem using KKT conditions, and solved by a supergradient-projected gradient algorithm (SPAD). Theoretical analysis and experiments show that, under realistic conditions such as heterogeneous detectability, their approach significantly outperforms baseline strategies like uniform or harm-proportional budget allocations.
This work addresses the challenge of formally verifying or automatically refuting ε-differential privacy (ε-DP) in complex mechanisms involving both discrete and continuous random sampling. To this end, the authors propose a fully automated refutation method based on upper-expectation supermartingales and lower-expectation submartingales. The approach simultaneously searches for a pair of inputs violating ε-DP and a non-negative output function that witnesses the violation, leveraging expected divergence to construct a sound and semi-complete proof rule. This is the first technique to enable fully automated ε-DP refutation with guarantees of soundness and semi-completeness while supporting mixed distributions. The prototype tool, SuperDP, outperforms existing methods on several challenging benchmarks, successfully disproving ε-DP for mechanisms previously beyond the reach of automated analysis.