We study the relationship between adversarial robustness and differential privacy in high-dimensional algorithmic statistics. We give the first black-box reduction from privacy to robustness which can produce private estimators with optimal tradeoffs among sample complexity, accuracy, and privacy for a wide range of fundamental high-dimensional parameter estimation problems, including mean and covariance estimation. We show that this reduction can be implemented in polynomial time in some important special cases. In particular, using nearly-optimal polynomial-time robust estimators for the mean and covariance of high-dimensional Gaussians which are based on the Sum-of-Squares method, we design the first polynomial-time private estimators for these problems with nearly-optimal samples-accuracy-privacy tradeoffs. Our algorithms are also robust to a nearly optimal fraction of adversarially-corrupted samples.
翻译:我们研究高维算法统计中对抗鲁棒性与差分隐私之间的关系。我们首次提出了从隐私性到鲁棒性的黑盒约简方法,能够为包括均值和协方差估计在内的多种基础高维参数估计问题,生成在样本复杂度、精度和隐私性之间达到最优权衡的私有估计器。我们证明在某些重要特殊情况下,该约简可在多项式时间内实现。特别地,通过采用基于平方和方法构建的、具有近最优性能的高斯分布均值与协方差多项式时间鲁棒估计器,我们为这些问题设计了首个具有近最优样本-精度-隐私权衡的多项式时间私有估计器。我们的算法对接近最优比例的对抗污染样本同样具有鲁棒性。