Differential Privacy (DP) mechanisms usually {force} reduction in data utility by producing ``out-of-bound'' noisy results for a tight privacy budget. We introduce the Budget Recycling Differential Privacy (BR-DP) framework, designed to provide soft-bounded noisy outputs for a broad range of existing DP mechanisms. By ``soft-bounded," we refer to the mechanism's ability to release most outputs within a predefined error boundary, thereby improving utility and maintaining privacy simultaneously. The core of BR-DP consists of two components: a DP kernel responsible for generating a noisy answer per iteration, and a recycler that probabilistically recycles/regenerates or releases the noisy answer. We delve into the privacy accounting of BR-DP, culminating in the development of a budgeting principle that optimally sub-allocates the available budget between the DP kernel and the recycler. Furthermore, we introduce algorithms for tight BR-DP accounting in composition scenarios, and our findings indicate that BR-DP achieves reduced privacy leakage post-composition compared to DP. Additionally, we explore the concept of privacy amplification via subsampling within the BR-DP framework and propose optimal sampling rates for BR-DP across various queries. We experiment with real data, and the results demonstrate BR-DP's effectiveness in lifting the utility-privacy tradeoff provided by DP mechanisms.
翻译:差分隐私(DP)机制通常因严格的隐私预算而产生“超出边界”的噪声结果,从而强制降低数据效用。我们提出预算回收差分隐私(BR-DP)框架,旨在为现有广泛DP机制提供软边界噪声输出。所谓“软边界”,指该机制能在预设误差边界内释放大部分输出,从而同时提升效用并保持隐私。BR-DP的核心包含两个组件:一个负责每次迭代生成噪声答案的DP内核,以及一个以概率方式回收/再生或释放噪声答案的回收器。我们深入研究了BR-DP的隐私核算,最终提出了一种最优地在DP内核与回收器之间子分配可用预算的预算原则。此外,我们引入了组合场景下BR-DP紧密核算的算法,研究结果表明,与DP相比,BR-DP在组合后能实现更低的隐私泄露。我们还探索了BR-DP框架下通过子采样实现隐私放大的概念,并针对不同查询提出了BR-DP的最优采样率。我们使用真实数据进行实验,结果证明了BR-DP在提升DP机制提供的效用-隐私权衡方面的有效性。