We study a new framework for designing differentially private (DP) mechanisms via randomized graph colorings, called rainbow differential privacy. In this framework, datasets are nodes in a graph, and two neighboring datasets are connected by an edge. Each dataset in the graph has a preferential ordering for the possible outputs of the mechanism, and these orderings are called rainbows. Different rainbows partition the graph of connected datasets into different regions. We show that if a DP mechanism at the boundary of such regions is fixed and it behaves identically for all same-rainbow boundary datasets, then a unique optimal $(\epsilon,\delta)$-DP mechanism exists (as long as the boundary condition is valid) and can be expressed in closed-form. Our proof technique is based on an interesting relationship between dominance ordering and DP, which applies to any finite number of colors and for $(\epsilon,\delta)$-DP, improving upon previous results that only apply to at most three colors and for $\epsilon$-DP. We justify the homogeneous boundary condition assumption by giving an example with non-homogeneous boundary condition, for which there exists no optimal DP mechanism.
翻译:我们研究了一种通过随机图着色设计差分隐私(DP)机制的新框架,称为彩虹差分隐私。在该框架中,数据集被表示为图中的节点,两个相邻数据集由一条边连接。图中每个数据集对机制的可能输出具有优先顺序,这些顺序被称为彩虹。不同的彩虹将连通数据集的图划分为不同区域。我们证明,如果这种区域的边界上的DP机制是固定的,且对所有同彩虹边界数据集表现一致,那么存在唯一的最优$(\epsilon,\delta)$-DP机制(只要边界条件有效),且该机制可表示为闭式解。我们的证明技术基于占优序与DP之间的有趣关系,该关系适用于任意有限数量的颜色以及$(\epsilon,\delta)$-DP,改进了先前仅适用于最多三种颜色及$\epsilon$-DP的结果。我们通过一个非齐次边界条件的例子证明了齐次边界条件假设的合理性,在该例子中不存在最优DP机制。