Best Arm Identification (BAI) problems are progressively used for data-sensitive applications, such as designing adaptive clinical trials, tuning hyper-parameters, and conducting user studies. Motivated by the data privacy concerns invoked by these applications, we study the problem of BAI with fixed confidence in both the local and central models, i.e. $ε$-local and $ε$-global Differential Privacy (DP). First, to quantify the cost of privacy, we derive lower bounds on the sample complexity of any $δ$-correct BAI algorithm satisfying $ε$-global DP or $ε$-local DP. Our lower bounds suggest the existence of two privacy regimes. In the high-privacy regime, the hardness depends on a coupled effect of privacy and novel information-theoretic quantities involving the Total Variation. In the low-privacy regime, the lower bounds reduce to the non-private lower bounds. We propose $ε$-local DP and $ε$-global DP variants of a Top Two algorithm, namely CTB-TT and AdaP-TT*, respectively. For $ε$-local DP, CTB-TT is asymptotically optimal by plugging in a private estimator of the means based on Randomised Response. For $ε$-global DP, our private estimator of the mean runs in arm-dependent adaptive episodes and adds Laplace noise to ensure a good privacy-utility trade-off. By adapting the transportation costs, the expected sample complexity of AdaP-TT* reaches the asymptotic lower bound up to multiplicative constants.
翻译:最佳臂识别(Best Arm Identification, BAI)问题正越来越多地应用于数据敏感场景,例如设计自适应临床试验、调整超参数以及开展用户研究。受这些应用引发的数据隐私问题驱动,我们研究了在局部模型和全局模型(即ε-局部差分隐私和ε-全局差分隐私)下具有固定置信度的BAI问题。首先,为量化隐私成本,我们推导了满足ε-全局DP或ε-局部DP的任何δ-正确BAI算法样本复杂度的下界。我们的下界表明存在两种隐私机制:在高隐私机制下,问题难度取决于隐私与涉及全变差的新型信息论量之间的耦合效应;在低隐私机制下,下界退化为非隐私情形下的下界。我们分别提出了Top Two算法的ε-局部DP变体CTB-TT和ε-全局DP变体AdaP-TT*。针对ε-局部DP,CTB-TT通过基于随机化响应(Randomised Response)的均值私有估计器实现了渐近最优性。针对ε-全局DP,我们的均值私有估计器以臂相关的自适应回合运行,并添加拉普拉斯噪声以确保良好的隐私-效用权衡。通过调整传输成本,AdaP-TT*的期望样本复杂度在乘法常数意义上达到了渐近下界。