Standard differential privacy imposes uniform privacy constraints across all features, overlooking the inherent distinction between sensitive and insensitive features in practice. In this paper, we introduce a relaxed definition of differential privacy that accounts for such heterogeneity, allowing certain features to be treated as insensitive even when correlated with sensitive ones. We propose a correlation-aware framework, $\textsf{CorrDP}$, which relaxes privacy for insensitive features while accounting for their correlations with sensitive features, with the correlations quantified using total variation distance. We design algorithms for differentially private empirical risk minimization (DP-ERM) under the $\textsf{CorrDP}$ framework, incorporating distance-dependent noise into gradients for improved theoretical utility guarantees. When the correlation distance is unknown, we estimate it from the dataset and show that it achieves a comparable privacy-utility guarantee. We perform experiments on synthetic and real-world datasets and show that $\textsf{CorrDP}$-based DP-ERM algorithms consistently outperform the standard DP framework in the presence of insensitive features.
翻译:标准差分隐私对所有特征施加统一的隐私约束,忽视了实践中敏感特征与非敏感特征之间的固有区别。本文提出了一种考虑这种异质性的差分隐私松弛定义,允许某些即使与敏感特征相关的特征被视为非敏感特征。我们提出了一种相关性感知框架——$\textsf{CorrDP}$,该框架在考虑非敏感特征与敏感特征相关性的同时,放宽了对非敏感特征的隐私保护,其中相关性通过总变差距离量化。我们设计了$\textsf{CorrDP}$框架下的差分隐私经验风险最小化(DP-ERM)算法,在梯度中引入距离相关噪声以提升理论效用保证。当相关性距离未知时,我们从数据集中估计该距离,并证明其可实现可比的隐私-效用权衡。我们在合成数据集和真实数据集上进行了实验,结果表明,基于$\textsf{CorrDP}$的DP-ERM算法在存在非敏感特征时始终优于标准DP框架。