Pith. sign in

REVIEW 8 cited by

R\'enyi Differential Privacy of the Sampled Gaussian Mechanism

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv 1908.10530 v1 pith:HGRV2H3N submitted 2019-08-28 cs.LG cs.CRstat.ML

classification cs.LGcs.CRstat.ML
keywords privacydifferentialgaussianmechanismenyiprecisesampledsampling
verification ladder T0 review T1 audit T2 compute T3 formal
0 comments
read the original abstract

The Sampled Gaussian Mechanism (SGM)---a composition of subsampling and the additive Gaussian noise---has been successfully used in a number of machine learning applications. The mechanism's unexpected power is derived from privacy amplification by sampling where the privacy cost of a single evaluation diminishes quadratically, rather than linearly, with the sampling rate. Characterizing the precise privacy properties of SGM motivated development of several relaxations of the notion of differential privacy. This work unifies and fills in gaps in published results on SGM. We describe a numerically stable procedure for precise computation of SGM's R\'enyi Differential Privacy and prove a nearly tight (within a small constant factor) closed-form bound.

Discussion (0). Continue with ORCID to comment.

Forward citations

Cited by 8 Pith papers

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score. Full citation record

  1. Tight Privacy Audit in One Run

    cs.CR 2025-09 reject novelty 7.0 of 10

    A one-run privacy audit claims tight lower bounds for general DP algorithms, but the core dominance proof is invalid.

  2. End-to-End Differential Privacy in Training Deep Neural Network Classifiers

    cs.LG 2026-07 conditional novelty 6.0 of 10

    Perturbing softmax outputs with the Dirichlet mechanism during training yields input-private, label-public classifiers that beat prior differentially private training accuracy on five image benchmarks.

  3. Differentially Private Natural Gradient Descent

    cs.LG 2026-07 conditional novelty 6.0 of 10

    DP-NGD enables second-order optimization under differential privacy by decoupling curvature estimation onto public data, performing isotropic DP operations in a whitened space, and dynamically clamping curvature eigen...

  4. Free Privacy Protection for Wireless Federated Learning: Enjoy It or Suffer from It?

    cs.LG 2025-06 reject novelty 6.0 of 10

    A bit-flipping mechanism for wireless federated learning claims Rényi differential privacy from channel noise, but the proof uses an expected bit-level distance rather than a worst-case sensitivity, leaving the guaran...

  5. Multi-level Certified Defense Against Poisoning Attacks in Offline Reinforcement Learning

    cs.LG 2025-05 conditional novelty 6.0 of 10

    A DP-based certified defense provides lower bounds on expected cumulative reward and per-state action stability for offline RL under transition- and trajectory-level poisoning, with larger certified radii than COPA.

  6. Comparing privacy notions for protection against reconstruction attacks in machine learning

    cs.LG 2025-02 conditional novelty 6.0 of 10

    Bayes' capacity, not the DP epsilon parameter, is shown to track how well Gaussian and von Mises-Fisher noise mechanisms resist gradient-based reconstruction attacks.

  7. Achieving Hilbert-Schmidt Independence Under R\'enyi Differential Privacy for Fair and Private Data Generation

    cs.LG 2025-08 conditional novelty 5.0 of 10

    FLIP combines a VAE, latent diffusion, Rényi DP, and CKA alignment across protected groups to produce tabular data with substantially reduced predictability of the protected attribute.

  8. AVEC: Bootstrapping Privacy for Local LLMs

    cs.CR 2025-09 conditional novelty 4.0 of 10

    AVEC is a proposed framework for per-query differential privacy budgeting, entity-level randomized response, and hash-based verification when delegating LLM queries to a remote model.

Pith tools