We study a protocol for distributed computation called shuffled check-in, which achieves strong privacy guarantees without requiring any further trust assumptions beyond a trusted shuffler. Unlike most existing work, shuffled check-in allows clients to make independent and random decisions to participate in the computation, removing the need for server-initiated subsampling. Leveraging differential privacy, we show that shuffled check-in achieves tight privacy guarantees through privacy amplification, with a novel analysis based on R{\'e}nyi differential privacy that improves privacy accounting over existing work. We also introduce a numerical approach to track the privacy of generic shuffling mechanisms, including Gaussian mechanism, which is the first evaluation of a generic mechanism under the distributed setting within the local/shuffle model in the literature. Empirical studies are also given to demonstrate the efficacy of the proposed approach.
翻译:我们研究了一种名为“混入检查”的分布式计算协议,该协议在仅依赖可信混洗器而无其他信任假设的条件下,实现了强大的隐私保障。与现有大多数工作不同,混入检查允许客户端独立随机决定是否参与计算,从而无需服务器发起的子采样。基于差分隐私技术,我们证明混入检查通过隐私放大实现了严格的隐私保障,并基于雷尼差分隐私提出了一种新颖的分析方法,相较于现有工作改进了隐私核算。此外,我们引入了一种数值方法以追踪通用混洗机制的隐私性,包括高斯机制——这是文献中首次在本地/混洗模型下的分布式场景中对通用机制进行的评估。我们还通过实证研究验证了所提方法的有效性。