A recent line of work initiated by Chiesa and Gur and further developed by Herman and Rothblum investigates the sample and communication complexity of verifying properties of distributions with the assistance of a powerful, knowledgeable, but untrusted prover. In this work, we initiate the study of differentially private (DP) distribution property testing. After all, if we do not trust the prover to help us with verification, why should we trust it with our sensitive sample? We map a landscape of DP prover-aided proofs of properties of distributions. In the non-private case it is known that one-round (two message) private-coin protocols can have substantially lower complexity than public-coin AM protocols, but in the private case, the possibility for improvement depends on the parameter regime and privacy model. Drawing on connections to replicability and techniques for amplification, we show: (1) There exists a reduction from any one-round $(\varepsilon,δ)$-DP private-coin interactive proof to a one-round public-coin DP interactive proof with the same privacy parameters, for the parameter regime $\varepsilon=O(1/\sqrt{n})$ and $δ=O(1/n^{5/2})$, and with the same sample and communication complexities. (2) If the verifier's message in the private-coin interactive proof is $O(1/\sqrt{\log n})$ locally DP -- a far more relaxed privacy parameter regime in a different model -- then applying one additional transformation again yields a one-round public-coin protocol with the same privacy bound and the same sample and computational complexities. (3) However, when the privacy guarantee is very relaxed ($\varepsilon\inΩ(\log n)$), private coins indeed reduce complexity. We also obtain a Merlin-Arthur (one-message) proof for privately testing whether samples are drawn from a product distribution, and prove that its sample complexity is optimal.


翻译:由Chiesa和Gur开创、Herman和Rothblum进一步发展的一系列近期工作,研究了在强大、博学但不可信证明者的协助下,验证分布性质所需的样本与通信复杂度。在本文中,我们首次开展了差分隐私(DP)分布性质测试的研究。毕竟,如果我们不信任证明者帮助我们进行验证,为何要信任它处理我们的敏感样本呢?我们描绘了DP证明者辅助的分布性质证明的图景。在非隐私情形中,已知单轮(两消息)私密币协议可能具有远低于公开币AM协议的复杂度,但在隐私情形中,改进的可能性取决于参数区间与隐私模型。利用可复现性与放大技术之间的联系,我们证明:(1) 对于参数区间$\varepsilon=O(1/\sqrt{n})$且$δ=O(1/n^{5/2})$,存在从任意单轮$(\varepsilon,δ)$-DP私密币交互式证明到具有相同隐私参数的单轮公开币DP交互式证明的归约,且样本与通信复杂度保持不变。(2) 若私密币交互式证明中验证者的消息是$O(1/\sqrt{\log n})$的局部DP——这对应于另一种模型中宽松得多的隐私参数区间——则应用一次额外变换后,同样可得到具有相同隐私界、样本与计算复杂度的单轮公开币协议。(3) 然而,当隐私保证非常宽松时($\varepsilon\inΩ(\log n)$),私密币确实降低了复杂度。我们还得到了用于隐私测试样本是否来自乘积分布的Merlin-Arthur(单消息)证明,并证明了其样本复杂度是最优的。

0
下载
关闭预览

相关内容

差分隐私全指南:从理论基础到用户期望
专知会员服务
13+阅读 · 2025年9月8日
【新书】差分隐私,246页pdf
专知会员服务
27+阅读 · 2025年4月5日
【斯坦福博士论文】有效的差分隐私深度学习,153页pdf
专知会员服务
19+阅读 · 2024年7月10日
「机器学习中差分隐私」最新2022进展综述
专知会员服务
54+阅读 · 2022年9月9日
专知会员服务
41+阅读 · 2020年12月1日
【资源】图像分割/显著性检测数据集列表
专知
13+阅读 · 2019年5月22日
差分隐私保护:从入门到脱坑
FreeBuf
17+阅读 · 2018年9月10日
综述——隐私保护集合交集计算技术研究
计算机研究与发展
22+阅读 · 2017年10月24日
国家自然科学基金
2+阅读 · 2017年12月31日
国家自然科学基金
0+阅读 · 2015年12月31日
国家自然科学基金
2+阅读 · 2015年12月31日
国家自然科学基金
0+阅读 · 2015年12月31日
国家自然科学基金
2+阅读 · 2015年12月31日
国家自然科学基金
7+阅读 · 2015年12月31日
国家自然科学基金
12+阅读 · 2015年12月31日
国家自然科学基金
2+阅读 · 2015年12月31日
国家自然科学基金
3+阅读 · 2014年12月31日
VIP会员
最新内容
俄乌无人机战争的六大启示
专知会员服务
9+阅读 · 8月3日
《无人机空中监控:通信实验洞察》
专知会员服务
7+阅读 · 8月3日
从采集到决策:美军视角下的战术情报范式重构
《履带式无人地面战车技术发展现状》
专知会员服务
7+阅读 · 8月2日
《无人机脆弱性利用:网络空间力量的新域》
专知会员服务
10+阅读 · 8月1日
相关基金
国家自然科学基金
2+阅读 · 2017年12月31日
国家自然科学基金
0+阅读 · 2015年12月31日
国家自然科学基金
2+阅读 · 2015年12月31日
国家自然科学基金
0+阅读 · 2015年12月31日
国家自然科学基金
2+阅读 · 2015年12月31日
国家自然科学基金
7+阅读 · 2015年12月31日
国家自然科学基金
12+阅读 · 2015年12月31日
国家自然科学基金
2+阅读 · 2015年12月31日
国家自然科学基金
3+阅读 · 2014年12月31日
Top
微信扫码咨询专知VIP会员