Individual privacy accounting enables bounding differential privacy (DP) loss individually for each participant involved in the analysis. This can be informative as often the individual privacy losses are considerably smaller than those indicated by the DP bounds that are based on considering worst-case bounds at each data access. In order to account for the individual privacy losses in a principled manner, we need a privacy accountant for adaptive compositions of randomised mechanisms, where the loss incurred at a given data access is allowed to be smaller than the worst-case loss. This kind of analysis has been carried out for the R\'enyi differential privacy (RDP) by Feldman and Zrnic (2021), however not yet for the so-called optimal privacy accountants. We make first steps in this direction by providing a careful analysis using the Gaussian differential privacy which gives optimal bounds for the Gaussian mechanism, one of the most versatile DP mechanisms. This approach is based on determining a certain supermartingale for the hockey-stick divergence and on extending the R\'enyi divergence-based fully adaptive composition results by Feldman and Zrnic. We also consider measuring the individual $(\varepsilon,\delta)$-privacy losses using the so-called privacy loss distributions. With the help of the Blackwell theorem, we can then make use of the RDP analysis to construct an approximative individual $(\varepsilon,\delta)$-accountant.
翻译:个体隐私核算能够对分析中涉及的每个参与者分别界定差分隐私(DP)损失。这具有重要信息价值,因为个体隐私损失通常远小于基于每次数据访问中最坏情况边界得出的差分隐私界限。为了以严谨方式核算个体隐私损失,我们需要针对随机机制的自适应组合设计隐私核算器,其中允许给定数据访问产生的损失小于最坏情况损失。Feldman与Zrnic(2021)已针对Rényi差分隐私(RDP)开展了此类分析,但尚未涉及所谓的"最优隐私核算器"。我们通过采用高斯差分隐私进行精细分析,在这一方向上迈出了初步步骤——高斯机制作为最通用的差分隐私机制之一,该方法能为其提供最优边界。本方法基于确定hockey-stick散度的特定上鞅,并扩展了Feldman与Zrnic基于Rényi散度的完全自适应组合结果。我们还利用所谓的隐私损失分布来度量个体$(\varepsilon,\delta)$-隐私损失。借助Blackwell定理,可进一步利用RDP分析构建近似个体$(\varepsilon,\delta)$-核算器。