Pith. sign in

A Randomized Approach for Tight Privacy Accounting

1 Pith paper cite this work. Polarity classification is still indexing.

1 Pith paper citing it
abstract

Bounding privacy leakage over compositions, i.e., privacy accounting, is a key challenge in differential privacy (DP). The privacy parameter ($\eps$ or $\delta$) is often easy to estimate but hard to bound. In this paper, we propose a new differential privacy paradigm called estimate-verify-release (EVR), which addresses the challenges of providing a strict upper bound for privacy parameter in DP compositions by converting an estimate of privacy parameter into a formal guarantee. The EVR paradigm first estimates the privacy parameter of a mechanism, then verifies whether it meets this guarantee, and finally releases the query output based on the verification result. The core component of the EVR is privacy verification. We develop a randomized privacy verifier using Monte Carlo (MC) technique. Furthermore, we propose an MC-based DP accountant that outperforms existing DP accounting techniques in terms of accuracy and efficiency. Our empirical evaluation shows the newly proposed EVR paradigm improves the utility-privacy tradeoff for privacy-preserving machine learning.

citation-role summary

background 1

citation-polarity summary

fields

cs.CR 1

years

2025 1

verdicts

CONDITIONAL 1

roles

background 1

polarities

unclear 1

representative citing papers

Machine Learning with Privacy for Protected Attributes

cs.CR · 2025-06-24 · conditional · novelty 7.0

Feature differential privacy is a relaxation of DP that guards selected features only, and the paper's two-batch algorithm recovers subsampling amplification and improves utility over standard DP when public features exist.

citing papers explorer

Showing 1 of 1 citing paper.

  • Machine Learning with Privacy for Protected Attributes cs.CR · 2025-06-24 · conditional · none · ref 32 · internal anchor

    Feature differential privacy is a relaxation of DP that guards selected features only, and the paper's two-batch algorithm recovers subsampling amplification and improves utility over standard DP when public features exist.