AIセキュリティポータル K Program
Score Attack: A Lower Bound Technique for Optimal Differentially Private Learning
Share
Abstract
Achieving optimal statistical performance while ensuring the privacy of personal data is a challenging yet crucial objective in modern data analysis. However, characterizing the optimality, particularly the minimax lower bound, under privacy constraints is technically difficult. To address this issue, we propose a novel approach called the score attack, which provides a lower bound on the differential-privacy-constrained minimax risk of parameter estimation. The score attack method is based on the tracing attack concept in differential privacy and can be applied to any statistical model with a well-defined score statistic. It can optimally lower bound the minimax risk of estimating unknown model parameters, up to a logarithmic factor, while ensuring differential privacy for a range of statistical problems. We demonstrate the effectiveness and optimality of this general method in various examples, such as the generalized linear model in both classical and high-dimensional sparse settings, the Bradley-Terry-Luce model for pairwise comparisons, and nonparametric regression over the Sobolev class.
Deep learning with differential privacy
Martin Abadi, Andy Chu, Ian Goodfellow, H Brendan McMahan, Ilya Mironov, Kunal Talwar, Li Zhang
Published: 2016
Differentially private testing of identity and closeness of discrete distributions
Jayadev Acharya, Ziteng Sun, Huanyu Zhang
Published: 2018
Differentially Private Assouad, Fano, and Le Cam
J. Acharya, Z. Sun, H. Zhang
Published: 2021
Fast global convergence rates of gradient methods for high-dimensional statistical recovery
Alekh Agarwal, Sahand Negahban, Martin J Wainwright
Published: 2010
Tutorial on large deviations for the binomial distribution
R. Arratia, L. Gordon
Published: 1989
Privacy-preserving parametric inference: a case for robust statistics
Marco Avella-Medina
Published: 2021
Two of a kind or the ratings game? adaptive pairwise preferences and latent factor models
Suhrid Balakrishnan, Sumit Chopra
Published: 2012
Share