REVIEW 8 cited by
R\'enyi Differential Privacy of the Sampled Gaussian Mechanism
Not yet reviewed by Pith; the record is open.
This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.
SPECIMEN: schema-true, not a live event
T0 review · schema-true
One-sentence machine reading of the paper's core claim.
pith:XXXXXXXX · record.json · timestamp
read the original abstract
The Sampled Gaussian Mechanism (SGM)---a composition of subsampling and the additive Gaussian noise---has been successfully used in a number of machine learning applications. The mechanism's unexpected power is derived from privacy amplification by sampling where the privacy cost of a single evaluation diminishes quadratically, rather than linearly, with the sampling rate. Characterizing the precise privacy properties of SGM motivated development of several relaxations of the notion of differential privacy. This work unifies and fills in gaps in published results on SGM. We describe a numerically stable procedure for precise computation of SGM's R\'enyi Differential Privacy and prove a nearly tight (within a small constant factor) closed-form bound.
Forward citations
Cited by 8 Pith papers
-
Tight Privacy Audit in One Run
A one-run privacy audit claims tight lower bounds for general DP algorithms, but the core dominance proof is invalid.
-
End-to-End Differential Privacy in Training Deep Neural Network Classifiers
Perturbing softmax outputs with the Dirichlet mechanism during training yields input-private, label-public classifiers that beat prior differentially private training accuracy on five image benchmarks.
-
Differentially Private Natural Gradient Descent
DP-NGD enables second-order optimization under differential privacy by decoupling curvature estimation onto public data, performing isotropic DP operations in a whitened space, and dynamically clamping curvature eigen...
-
Free Privacy Protection for Wireless Federated Learning: Enjoy It or Suffer from It?
A bit-flipping mechanism for wireless federated learning claims Rényi differential privacy from channel noise, but the proof uses an expected bit-level distance rather than a worst-case sensitivity, leaving the guaran...
-
Multi-level Certified Defense Against Poisoning Attacks in Offline Reinforcement Learning
A DP-based certified defense provides lower bounds on expected cumulative reward and per-state action stability for offline RL under transition- and trajectory-level poisoning, with larger certified radii than COPA.
-
Comparing privacy notions for protection against reconstruction attacks in machine learning
Bayes' capacity, not the DP epsilon parameter, is shown to track how well Gaussian and von Mises-Fisher noise mechanisms resist gradient-based reconstruction attacks.
-
Achieving Hilbert-Schmidt Independence Under R\'enyi Differential Privacy for Fair and Private Data Generation
FLIP combines a VAE, latent diffusion, Rényi DP, and CKA alignment across protected groups to produce tabular data with substantially reduced predictability of the protected attribute.
-
AVEC: Bootstrapping Privacy for Local LLMs
AVEC is a proposed framework for per-query differential privacy budgeting, entity-level randomized response, and hash-based verification when delegating LLM queries to a remote model.
Discussion (0). Continue with ORCID to comment.