Score
Analyze and quantify differential privacy guarantees when randomness or perturbation arises from communication or storage channels (noisy channels, coded transmissions). This involves modeling channel noise as a privacy mechanism, deriving DP bounds (including per-codeword or per-message leakage), and designing or selecting encodings and mappings that optimize privacy–utility tradeoffs under specified channel models.
This work addresses the challenge of transmitting count query results over a binary symmetric channel while preserving differential privacy. Conventional mechanisms often require injecting additional noise, which compromises utility or increases error rates. The authors propose an optimal permutation strategy for Hamming code codewords that leverages the channel’s inherent noise to strengthen differential privacy guarantees—without introducing extra perturbation, degrading data utility, or incurring additional computational overhead. By integrating differential privacy with information-theoretic coding principles, the method achieves enhanced privacy-utility trade-offs while maintaining end-to-end decoding accuracy. This approach establishes a novel paradigm for privacy-preserving communication in bandwidth-constrained settings.
Differential privacy (DP) lacks intuitive interpretability from the perspective of statistical disclosure risk, hindering practitioners’ understanding and trustworthy deployment. Method: This work establishes, for the first time, a rigorous theoretical linkage between DP parameters (ε, δ) and quantifiable disclosure risk. By integrating statistical inference theory, privacy analysis, and risk modeling, we derive tight upper bounds on an adversary’s worst-case success probability in inferring sensitive attributes under DP. Contribution/Results: The framework endows ε and δ with concrete, risk-based semantics—interpreting them as guarantees on bounded inference risk. It further provides a risk-accumulation interpretation of composition theorems, enabling principled, scenario-aware selection and validation of privacy parameters. Our results significantly enhance the interpretability and credibility of DP, offering both theoretical foundations and actionable guidelines for privacy engineering practice.
This work establishes a systematic theoretical connection between differential privacy (DP) and information theory to quantitatively characterize the intrinsic information leakage of privacy-preserving mechanisms. Method: DP mechanisms are modeled as stochastic channels from input data to output analysis; information-theoretic measures—including mutual information and min-entropy leakage—are introduced and endowed with rigorous privacy semantics. By integrating probabilistic distribution perturbation analysis with channel capacity characterization, the paper derives quantitative relationships between the privacy budget ε and information leakage. Contribution/Results: It provides the first operational information-theoretic interpretation of DP from a channel coding perspective, revealing that ε-DP inherently enforces a worst-case information constraint. Moreover, it establishes computable information-theoretic bounds for the privacy–utility trade-off, thereby significantly strengthening the theoretical foundation and interpretability of DP.
Differential privacy (DP) mechanisms are commonly reported at a single $(varepsilon,delta)$ point, obscuring substantial differences in actual privacy risk among mechanisms sharing identical $(varepsilon,delta)$ parameters—leading to systematic underestimation of risk. Method: We propose a unified quantification framework grounded in $Delta$-divergence, integrating f-differential privacy, Bayesian privacy interpretations, and Blackwell order theory for the first time to establish a decision-theoretically principled paradigm for comparing DP mechanisms. Contribution/Results: By rigorously characterizing worst-case privacy vulnerability disparities, we expose non-negligible excess risk in mainstream noise mechanisms used in DP-SGD. Our framework yields a verifiable, ordinal privacy strength assessment tool—enabling rigorous, theoretically grounded selection of privacy-preserving mechanisms.
Quantum machine learning (QML) models suffer from vulnerability to adversarial attacks and lack formal guarantees of privacy and robustness. Method: This paper establishes, for the first time, a theoretical connection between quantum noise channels and differential privacy, proposing an (α,γ)-parameterized quantum noise channel construction framework grounded in ε-differential privacy. We design a semidefinite programming (SDP)-based optimizer to enhance certified robustness against depolarizing noise, and systematically quantify the impact of α and γ on robustness via quantum state encoding analysis, revealing the critical role of encoding strategies. Contribution/Results: Experiments on small-scale QML models demonstrate significant improvements in adversarial accuracy. The framework provides a novel paradigm for QML that simultaneously ensures provable robustness and rigorous privacy protection, advancing the foundation for trustworthy quantum learning systems.
本文通过使用IBM的DiffPrivLib系统性地研究了随机数质量下降对差分隐私机制的影响,揭示了不同熵源下隐私损失的变化情况。
This work addresses critical limitations of the conventional discrete Gaussian mechanism in differential privacy, which is vulnerable to floating-point precision issues and demands substantial high-quality randomness. The authors propose the dithered Gaussian mechanism, which decouples randomness into a privacy-critical high-quality component and a non-critical, computationally efficient component through output-side discretization and dual-source randomization. This approach preserves the theoretical privacy guarantees of the standard Gaussian mechanism while eliminating floating-point security vulnerabilities. Notably, it drastically reduces the requirement for high-quality random bits—rendering this demand independent of noise magnitude—and enables cryptographically secure noise generation in DP-SGD with minimal computational overhead, thereby achieving a strong balance between security and practicality.
This work addresses the lack of efficient compression mechanisms for high-dimensional data, such as images, under differential privacy, which leads to substantial storage overhead and limited practicality. The authors propose DP-DiPP, a novel framework that uniquely integrates Poisson Private Representations (PPR) with the diffusion-based compression method DiffC, leveraging stochastic encoding and diffusion models to achieve a flexible trade-off among privacy, compression ratio, and utility. Evaluated on private image classification using CIFAR-10, DP-DiPP achieves 10–30 times higher compression ratios compared to existing baselines while maintaining comparable privacy guarantees and model utility.
This work investigates privacy leakage arising from releasing posterior sample paths of Gaussian processes under the strict setting where training data are entirely private. It establishes, for the first time, that the inherent randomness of posterior sampling naturally provides differential privacy guarantees, and derives rigorous privacy bounds using Rényi differential privacy theory. The study proposes effective ridge regularization as a core mechanism to control privacy levels, complemented by calibrated noise injection for enhanced protection. Both theoretical analysis and empirical results demonstrate that the degree of privacy leakage is significantly influenced by the strength of regularization, posterior variance, and the number of released samples. In settings with noisy observations, moderate regularization effectively safeguards privacy while preserving utility for downstream tasks.
In the moderate-to-low privacy regime (i.e., small $(\varepsilon, \delta)$), existing Gaussian mechanisms are significantly suboptimal due to excessive noise injection. This work proposes a hybrid Gaussian noise mechanism that constructs a convex combination of multiple Gaussian distributions with identical variances but distinct means, adaptively tuning both the means and mixing weights using sensitivity information. It presents the first systematic construction and analysis of a Gaussian mixture-based perturbation scheme satisfying $(\varepsilon, \delta)$-differential privacy. The authors derive tight variance conditions and an efficient algorithm that substantially reduce both L1 and L2 utility loss in the low-privacy regime, markedly narrowing the performance gap with the theoretically optimal mechanism and achieving near-optimal accuracy.