{"id":"6d1ea25e-93fe-4749-947a-30e728e2e3b7","arxiv_id":"2411.09142","paper_version":1,"verdict":"CONDITIONAL","confidence":"MODERATE","novelty_score":5.0,"correctness_risk":"medium","formal_verification":"none","parameter_count":0,"one_line_summary":"Privacy profiles and Rényi divergences are Laplace transforms of the same privacy loss distribution, yielding an exactly tight continuous adaptive composition rule for (ε,δ)-DP.","lead":"Differential privacy guarantees can be read as Laplace transforms of the privacy loss distribution, which lets the authors derive a continuous, exactly tight composition rule for (ε,δ)-differential privacy and connect Rényi and privacy-profile curves. The paper gives privacy accountants a tighter analytical bound than pointwise conversions and links several DP formalisms into one toolkit.","discovery_kind":"new_method","skeptic_critique":{"model":"deepseek-v4-flash","headline":"Theorem 4.2's claimed extension to δ_i>0 is false as stated: the kernel δ̈−δ̇ omits the point mass at +∞ in randomized response, so the proof of Theorem 4.6 is invalid even though recursion (62) may be correct.","rationale":"The paper's Section 3 Laplace identities are mostly standard for absolutely continuous pairs, and the numerical alignment with PLDAccountant/PRVAccountant and with Kairouz et al.'s discrete values is real independent support for the recursive formula. I do not claim Theorem 4.6 is numerically wrong; in fact recursion (62) is exactly what one obtains by convolving the PLDs of randomized response, including their atom at +∞. The problem is that the proof as written does not establish this: it passes through Theorem 4.2, whose formula (47) is false for these profiles because the ordinary generalized derivative δ̈−δ̇ on R cannot represent the mass at +∞. This is why Remark 4.3's 'challenging problem' is not merely cosmetic; the stated path genuinely fails. The fix is a direct time-domain proof of the recursion, which would preserve the paper's main contribution. Therefore the reader's CONDITIONAL verdict is appropriate; I would not reject the paper outright, but the missing proof is load-bearing and should be supplied before the composition theorem is accepted as proven.","tokens_in":29186,"tokens_out":25393,"duration_ms":365855,"concrete_test":"Take P1=Q1 (so δ_{P1|Q1}=δ0) and P2,Q2 = M_{1,0.1}^{RR}(0), M_{1,0.1}^{RR}(1). Compute both sides of (47) at t=0: the RHS via the explicit δ̈−δ̇ from (163)–(167) equals 0.416, while the LHS δ_{P|Q}(0) from definition (6) over the 4×4 output space equals 0.516. If (47) gives the smaller value, the claimed extension to non-absolutely-continuous profiles is false, and Theorem 4.6 needs a different proof, e.g., direct PLD convolution including the +∞ atom.","verdict_should_be":"UNCHANGED","load_bearing_attack":"Theorem 4.6 is the paper's central applied claim, and its proof (Appendix A.3) is built on Theorem 4.2, which the paper extends beyond absolute continuity (Remark 4.3). For randomized response with δ>0, this extension is not merely unproved: it is false. The PLD of M_{ε,δ}^{RR} has a point mass δ at +∞ (the (0,⊥) atom P=δ, Q=0 in Theorem 3.4). Consequently the true composed profile is δ_{P|Q}(t)=E_{Z2}[(1-e^{t-Z1-Z2})_+] and contains an explicit δ_l term when Z2=+∞. But a direct calculation of δ̈_{RR}−δ̇_{RR} on R gives only the two finite Dirac masses (1−δ)/(1+e^ε)δ_{t=−ε} + e^ε(1−δ)/(1+e^ε)δ_{t=ε}; the point mass at +∞ is absent because the ordinary distributional derivative of a function with limit δ at +∞ carries no atom at infinity. Applying (47) to δ0 and δ_RR with ε=1, δ=0.1 at t=0 yields 0.416, while δ_RR(0)=0.516; the missing 0.1 is exactly δ. Thus the inequality δ_{P1:l|Q1:l} ≤ δ_{⊗l−1} ⊛ (δ̈_RR−δ̇_RR) used in the induction is backwards. The recursive formula (62) itself is, however, the correct PLD-convolution recurrence (including the +∞ atom) and agrees with Kairouz et al., so the final claim is likely salvageable by a direct time-domain proof; the paper as written does not provide it.","agreement_with_reader":"agree"},"referee_report":{"model":"deepseek-v4-flash","summary":"This paper proposes interpreting privacy profiles δ_{P|Q}(ε) and Rényi divergence R_q(P||Q) as (two-sided) Laplace transforms of the privacy loss distribution. Theorems 3.2 and 3.3 record identities connecting δ, R_q, and E_q; Eq. (37) gives an inverse-Laplace expression for δ in terms of complex-order Rényi divergence. Section 4 derives Theorem 4.2, an exactly tight convolution-type composition rule for privacy profiles under product distributions, and uses it to prove Theorem 4.6, a recursive adaptive composition theorem for (ε_i,δ_i)-DP point guarantees claimed to match Kairouz et al. in constants and to yield a continuous optimal curve. Section 5 argues that symmetrization in f-DP subsampling breaks equivalence across functional DP notions and proposes a skew convention.","tokens_in":29663,"tokens_out":10867,"duration_ms":113441,"significance":"If the main results were fully proved, the paper would make a useful contribution: it unifies several DP formalisms through standard transform calculus, extends Rényi divergence to complex orders in a natural ROC-based way, and offers a closed-form continuous composition curve that aligns with numerical accountants. The identities in Theorems 3.2 and 3.3 are standard integration-by-parts calculations and check out for absolutely continuous pairs; the recursive formula (62) is explicit, has no fitted parameters, and is directly checkable against numerical PLD accountants, which is a strength. However, the proof of the central composition theorem for the practically relevant δ_i>0 case rests on an unsupported and in fact false extension of Theorem 4.2 to non-absolutely-continuous profiles. The contribution is therefore conditional on a repaired proof; the final recursion is likely correct, but the manuscript as written does not prove it.","major_comments":[{"comment":"The induction step applies Theorem 4.2 to the randomized-response profile δ_{ε_l,δ_l}^{RR} with δ_l>0. This violates Theorem 4.2's hypothesis, which requires absolute continuity in at least one direction, and Remark 4.3 concedes that the extension is unproved. The extension is in fact false: the PLD of M_{ε,δ}^{RR} has a point mass δ at +∞, whereas the kernel δ̈_{RR}−δ̇_{RR} computed in Eqs. (163)-(177) contains only the two finite atoms (1−δ)e^ε/(e^ε+1) δ_{t=ε} and (1−δ)/(e^ε+1) δ_{t=−ε}, with the J2 and J3 terms vanishing under convolution. Consequently inequality (160) is false: with ε=1, δ=0.1 and δ⊗0(t)=[1−e^t]_+, the right-hand side at t=0 equals 0.416, while the actual randomized-response profile from Theorem 3.4 gives δ_RR(0)=0.516, the difference being exactly δ. The proof of Theorem 4.6 therefore does not establish recursion (62) for δ_i>0. The recursion itself is consistent with the PLD-convolution recurrence that includes the +∞ atom and with Kairouz et al.'s optimal composition, so a direct time-domain proof is likely to salvage the theorem, but it is not in the manuscript.","section":"Appendix A.3, proof of Theorem 4.6, Eqs. (159)-(177)"},{"comment":"The second part of Theorem 3.6 is proved by visual inspection of Figure 1: the text says 'From the leftmost plot, we can see...' and 'their privacy profiles cross one another.' A logical implication should not rest on a plot; the authors should provide a closed-form expression for the crossing point or an analytic inequality. This is a local proof gap rather than a challenge to the conclusion, but it should be fixed for the theorem to be considered proved.","section":"Section 3.1, proof of Theorem 3.6"},{"comment":"The paragraph after Theorem 4.2 states that 'even when the Laplace transform is undefined everywhere, the frequency-domain manipulations performed on it still correspond to valid manipulation steps in the time domain.' This assertion is the entire basis for applying Theorem 4.2 to randomized-response profiles with δ_i>0, and it is contradicted by the concrete counterexample above: the ordinary distributional derivative of δ_RR carries no atom at +∞, so the missing point mass of the PLD is lost. The paper should either remove this assertion and prove Theorem 4.6 by a separate time-domain argument, or restrict Theorem 4.6 to the case where the relevant Laplace transforms have nonempty ROC.","section":"Section 4 and Remark 4.3"}],"minor_comments":[{"comment":"Typos and name errors should be corrected: 'Heaveside' should be 'Heaviside' (Appendix A.3), 'Frenchel duality' should be 'Fenchel duality' (Section 4.1), 'Kairozu' should be 'Kairouz' (Figure 2 caption), and 'Oppenhiem' should be 'Oppenheim' (references).","section":"Throughout"},{"comment":"The inverse-Laplace formula writes the exponential factor as esε; this should be e^{sε} or exp(sε) to avoid ambiguity with a product of e, s, and ε.","section":"Section 3, Eq. (37)"},{"comment":"The 'generalized density' f_X is defined informally through Dirac deltas. Since later proofs perform distributional differentiation and convolution of such objects, the authors should state precisely in what space these manipulations are carried out and cite the relevant distributional calculus.","section":"Section 3, Definition 3.1 and Theorem 3.2"},{"comment":"The extension from real q to complex orders is justified only by the sentence 'From dominated convergence theorem the theorem statement holds for complex orders as well.' This is too terse; the authors should invoke analyticity of both sides on the ROC strip or give a dominated-convergence argument with the strip made explicit.","section":"Section 3, Theorem 3.5 proof"},{"comment":"The text says the bound 'surpasses the optimal composition result in Kairouz et al.' Because the recursion is claimed to match the existing discrete optimal points and merely adds intermediate ε values, 'surpasses' is misleading; 'extends to a continuous curve while matching the discrete optimal points' would be accurate once a proof is supplied.","section":"Section 4.1, comparison claims"},{"comment":"The statement that Gopi et al. 'seem to incorrectly assert their Theorem 5.5 to be valid under adaptivity' is a strong claim about a published result and is not substantiated. The authors should either provide a precise counterexample or soften the remark.","section":"Remark 4.1"},{"comment":"The comparison with Google's PLDAccountant and Microsoft's PRVAccountant reports numerical gaps, but the manuscript does not state the discretization parameters or provide code. Adding this information would make the numerical comparisons reproducible.","section":"Figures 2 and 4"}],"recommendation":"major_revision","confidential_remarks":"To the editor: the reader's stress-test concern lands. The paper's core Laplace identities are sound for absolutely continuous pairs, and the recursive formula (62) is likely correct, but the proof of Theorem 4.6 as written relies on a false extension of Theorem 4.2 to randomized-response profiles with δ_i>0. This is a load-bearing gap that can be fixed with a direct PLD-convolution proof, so I recommend major revision rather than rejection. I would also ask the authors to formalize the proof of Theorem 3.6 and to soften or substantiate the claims about 'surpassing' Kairouz et al. and about Gopi et al.'s adaptivity assertion."},"author_rebuttal":null,"desk_editor":{"model":"deepseek-v4-flash","letter":"Plain take: useful Laplace-transform toolkit for DP, and the continuous composition recursion is likely correct and worth having, but the proof of the headline composition theorem is not valid for δ>0 as written because it drops the +∞ atom of the randomized-response privacy loss.\n\nWhat is actually new: the paper shows the privacy profile and Rényi divergence are bilateral Laplace/inverse-Laplace transforms of each other, which justifies complex-order Rényi and gives a neat inversion formula. The dominance counterexample (Rényi dominance does not imply privacy-profile dominance) is clean. The subsampling asymmetry discussion is useful, though more opinion-and-example than formal. Credit where due: the authors are upfront that the bare Laplace integrals appear in earlier work, and they do not overclaim the identity part. There are no fitted parameters or self-citations to worry about.\n\nSoft spots. The central applied claim is Theorem 4.6, and its proof rests on Theorem 4.2, which is only proved under absolute continuity in one direction. The paper then applies it to randomized response with δ>0, whose privacy profile is not absolutely continuous and whose PLD has a point mass at +∞. The stress-test calculation lands: for the RR profile, δ̈−δ̇ on R gives only the two finite Dirac masses; the +∞ atom is invisible to ordinary distributional differentiation. So the inequality used in the induction, δ_{P1:l|Q1:l} ≤ δ_{⊗l−1} ⊛ (δ̈_RR−δ̇_RR), is not established for the case that matters. The paper itself flags this in Remark 4.3, which is honest, but it doesn't resolve it. The recursion (62) itself is consistent with the correct PLD convolution (including the +∞ atom) and matches Kairouz et al., so I suspect the theorem is salvageable by a direct time-domain proof; the paper as written just doesn't contain one. The f-DP symmetry part is interesting but asserted rather than formally closed.\n\nWho it's for: privacy accounting researchers who want a closed-form alternative to numerical accountants. Worth a serious referee, but the referee should focus on Theorem 4.2's extension or demand a proof of Theorem 4.6 that doesn't route through the invalid distributional step. I would not cite the composition result in its current form.","headline":"A useful Laplace-transform toolkit for DP, but the headline exactly-tight composition theorem is unproven as written for δ>0 because the proof applies a distributional identity that drops the +∞ atom of the randomized-response privacy loss.","tokens_in":30104,"tokens_out":3808,"would_cite":false,"duration_ms":40471,"reading_group":"maybe","serious_thinker":"yes","would_accept_peer_review":true},"rs_alignment":null,"lean_confirmation":null,"pith_extraction":{"msc":[],"pacs":[],"model":"deepseek-v4-flash","headline":"This paper shows that a mechanism's privacy profile and Rényi divergence curve determine each other through Laplace and inverse-Laplace transforms, yielding an exactly tight adaptive composition theorem for (ε,δ)-DP for every ε.","keywords":["differential privacy","Laplace transform","privacy profile","Rényi divergence","adaptive composition","privacy loss distribution","randomized response","functional differential privacy"],"falsifier":"For two independent randomized-response mechanisms, each $(0.1,10^{-8})$-DP, compute the exact privacy profile of their product by direct convolution of the privacy loss distributions (which is well-defined even though the Laplace transforms diverge) and compare it pointwise with the recursive $\\delta_{\\otimes 2}(t)$ from Theorem 4.6; if the recursion is not pointwise equal to this exact profile, the claim of constant-tightness for $\\delta_i>0$ is false.","tokens_in":29026,"feed_emoji":"🔒","tokens_out":8508,"duration_ms":82665,"temperature":0.7,"pith_summary":"This paper argues that the privacy profile and the Rényi divergence curve are two views of the same object: the privacy loss distribution, read through its bilateral Laplace transform. Recognizing familiar integral expressions as Laplace transforms lets the paper connect the two curves exactly, show that the Rényi order $q$ can be complex, and derive a composition rule for privacy profiles that is exactly tight. The main payoff is an adaptive composition theorem for $(\\varepsilon,\\delta)$-DP: any sequence of mechanisms each satisfying $(\\varepsilon_i,\\delta_i)$-DP satisfies a continuous curve $\\delta_{\\otimes k}(\\varepsilon)$ given by a simple recursion, reproducing the known optimal discrete guarantees and filling in the curve between them. The paper also argues that symmetrizing $f$-DP under subsampling breaks equivalence among functional notions, and proposes keeping the natural asymmetry instead.","feed_headline":"Laplace transforms make adaptive DP composition exactly tight","feed_subtitle":"One transform identity ties privacy profiles to Rényi curves and delivers a continuous, exactly tight composition bound.","key_machinery":"The machinery is the bilateral Laplace transform of the privacy loss distribution (PLD), the distribution of $Z = \\log(P(\\Theta)/Q(\\Theta))$ for $\\Theta\\sim P$. The paper reads the standard expectation formulas for the privacy profile and the Rényi exponential as $\\mathcal{B}\\{f_Z\\}(s)$ evaluated at specific complex frequencies, then uses Laplace uniqueness, convolution, and derivative properties to move between time-domain curves and frequency-domain curves. The load-bearing identity is $e^{(q-1)R_q} = q(q-1)\\mathcal{B}\\{\\delta_{P|Q}\\}(1-q)$; its inverse form $\\delta_{P|Q}(\\varepsilon) = \\mathcal{L}^{-1}\\{e^{-sR_{1-s}(P\\|Q)}/(s(s-1))\\}(\\varepsilon)$ is what turns a Rényi curve back into a privacy profile.","core_discovery":"The paper's central claim is that the privacy profile $\\delta_{P|Q}(\\varepsilon)$ and the Rényi divergence curve $R_q(P\\|Q)$ are the same information viewed in the time and frequency domains. Through Laplace-transform identities, $\\delta_{P|Q}(\\varepsilon) = \\mathcal{L}\\{1-F_Z(t+\\varepsilon)\\}(1)$ and $e^{(q-1)R_q(P\\|Q)} = \\mathcal{B}\\{f_Z\\}(1-q)$, the two are shown to invert one another via $e^{(q-1)R_q(P\\|Q)} = q(q-1)\\mathcal{B}\\{\\delta_{P|Q}(t)\\}(1-q)$, so that $R_q$ exists for complex orders on the region of convergence and $\\delta_{P|Q}$ can be recovered by inverse Laplace transform. On composition, the privacy profile of a product distribution is the convolution $\\delta_{P|Q} = \\delta_{P_1|Q_1} \\circledast (\\ddot{\\delta}_{P_2|Q_2} - \\dot{\\delta}_{P_2|Q_2})$, which yields the recursive exactly tight composition bound $\\delta_{\\otimes l}(t) = \\delta_l + \\frac{1-\\delta_l}{e^{\\varepsilon_l}+1}[e^{\\varepsilon_l}\\delta_{\\otimes l-1}(t-\\varepsilon_l) + \\delta_{\\otimes l-1}(t+\\varepsilon_l)]$ for any sequence of $(\\varepsilon_i,\\delta_i)$-DP mechanisms. The paper also claims that preserving the natural asymmetry in $f$-DP subsampling, rather than symmetrizing, keeps all functional DP notions equivalent.","pith_inferences":["If the distributional step for $\\delta_i>0$ is formalized, the Laplace toolkit should extend to exact composition of arbitrary functional curves beyond the randomized-response worst case, potentially replacing numerical PLD accountants with closed-form recursions.","The failure of Rényi dominance to imply privacy-profile dominance suggests that accounting should be done in the privacy-profile domain whenever the final guarantee is $(\\varepsilon,\\delta)$, because converting through real-order Rényi bounds provably loses tightness.","A testable extension is to use the inverse-Laplace formula with complex-order Rényi curves as a definition for profiles that are not absolutely continuous, and check whether it reproduces known profiles for mixtures such as subsampled mechanisms."],"forward_implications":["The recursive bound $\\delta_{\\otimes k}(\\varepsilon)$ is a continuous curve, so for any target $\\delta$ budget the tightest $\\varepsilon$ can be read off directly, whereas the earlier optimal discrete theorem only gives a finite set of points.","The same composition is exactly tight for adaptive and heterogeneous mechanisms under the standard worst-case conditional-profile domination assumption.","For homogeneous composition, the closed form $\\delta_{\\otimes k}(t) = 1-(1-\\delta)^k(1 - \\mathbb{E}_{Y\\sim\\mathrm{Binomial}(k,p)}[1 - e^{t-\\varepsilon(2Y-k)}]_+)$ gives an analytical accountant.","Complex-order Rényi divergence is well-defined on the region of convergence, so the privacy profile can be reconstructed from the Rényi curve along a vertical line in the complex plane rather than only from real orders $q>1$.","Keeping asymmetry in functional DP avoids the slack introduced by symmetrization and keeps $f$-DP, privacy profiles, privacy loss distributions, and Rényi curves equivalent under subsampling."],"supporting_citations":[{"why":"Supplies the privacy-profile formalism and the randomized-response profile for the pure-DP case that the paper extends.","marker":"[5]"},{"why":"Defines f-DP, the trade-off curve, and the subsampling symmetrization whose slack the paper removes.","marker":"[11]"},{"why":"Provides the numerical PLD/PRV accountant baseline and the claim about adaptive composition that the paper contrasts with its own result.","marker":"[18]"},{"why":"Supplies the prior optimal composition theorem and the worst-case randomized-response profile used in the dominating-profile argument.","marker":"[19]"},{"why":"Introduces Rényi differential privacy and its additive composition, the frequency-domain property the paper mirrors in the time domain.","marker":"[23]"},{"why":"Introduces the privacy loss distribution formalism and its reversal property that underlies the Laplace expressions.","marker":"[29]"},{"why":"Supplies the decomposition lemma used to prove that every $(\\varepsilon,\\delta)$-DP profile is dominated by the randomized-response profile.","marker":"[30]"},{"why":"Introduces the characteristic-function transform link between DP notions and the adaptive domination lemma reused in the composition proof.","marker":"[32]"}],"fun_headline_variants":["Laplace transforms link Rényi and privacy profiles","Exact DP composition via Laplace transform duality","Laplace transform reveals exact DP composition","Rényi and DP curves are Laplace pairs","Laplace view makes adaptive DP composition tight"],"cache_read_input_tokens":3200,"weakest_assumption_plain":"The load-bearing premise is that the convolution identity for privacy profiles remains valid for randomized-response profiles with $\\delta_i>0$, where the Laplace transforms diverge; Theorem 4.2 is stated under absolute continuity in at least one direction, and the paper notes in Remark 4.3 that formally proving this extension appears challenging.","fun_headline_variants_meta":{"raw":{"variants":["Laplace transforms link Rényi and privacy profiles","Exact DP composition via Laplace transform duality","Laplace transform reveals exact DP composition","Rényi and DP curves are Laplace pairs","Laplace view makes adaptive DP composition tight"]},"model":"deepseek-v4-flash","effort":"low","cost_usd":0.000387,"raw_usage":{"total_tokens":2108,"prompt_tokens":1075,"completion_tokens":1033,"prompt_tokens_details":{"cached_tokens":384},"prompt_cache_hit_tokens":384,"prompt_cache_miss_tokens":691,"completion_tokens_details":{"reasoning_tokens":965}},"tokens_in":691,"tokens_out":1033,"duration_ms":7841,"temperature":1.0,"reasoning_tokens":965,"cache_read_input_tokens":384,"cache_creation_input_tokens":0},"cache_creation_input_tokens":0},"created_at":"2026-08-12T21:00:07.660331+00:00","model_set":{"reader":"deepseek-v4-flash"},"falsifier":"For two independent randomized-response mechanisms, each $(0.1,10^{-8})$-DP, compute the exact privacy profile of their product by direct convolution of the privacy loss distributions (which is well-defined even though the Laplace transforms diverge) and compare it pointwise with the recursive $\\delta_{\\otimes 2}(t)$ from Theorem 4.6; if the recursion is not pointwise equal to this exact profile, the claim of constant-tightness for $\\delta_i>0$ is false.","supporting_citations":[{"cited_title":"Balle, G","cited_arxiv_id":null,"evidence_quote":"Supplies the privacy-profile formalism and the randomized-response profile for the pure-DP case that the paper extends."},{"cited_title":null,"cited_arxiv_id":null,"evidence_quote":"Provides the numerical PLD/PRV accountant baseline and the claim about adaptive composition that the paper contrasts with its own result."},{"cited_title":"Kairouz, S","cited_arxiv_id":null,"evidence_quote":"Supplies the prior optimal composition theorem and the worst-case randomized-response profile used in the dominating-profile argument."},{"cited_title":null,"cited_arxiv_id":null,"evidence_quote":"Introduces Rényi differential privacy and its additive composition, the frequency-domain property the paper mirrors in the time domain."},{"cited_title":"Sommer, S","cited_arxiv_id":null,"evidence_quote":"Introduces the privacy loss distribution formalism and its reversal property that underlies the Laplace expressions."},{"cited_title":"e(q−1)t q − 1 − eqt q #−ε −∞ + 1 1 + eε","cited_arxiv_id":null,"evidence_quote":"Introduces the characteristic-function transform link between DP notions and the adaptive domination lemma reused in the composition proof."}],"review_version":1}