Search arXivSearch

arXiv · 1905.10862

Automatic Discovery of Privacy-Utility Pareto Fronts

Abstract

Differential privacy is a mathematical framework for privacy-preserving data analysis. Changing the hyperparameters of a differentially private algorithm allows one to trade off privacy and utility in a principled way. Quantifying this trade-off in advance is essential to decision-makers tasked with deciding how much privacy can be provided in a particular application while maintaining acceptable utility. Analytical utility guarantees offer a rigorous tool to reason about this trade-off, but are generally only available for relatively simple problems. For more complex tasks, such as training neural networks under differential privacy, the utility achieved by a given algorithm can only be measured empirically. This paper presents a Bayesian optimization methodology for efficiently characterizing the privacy--utility trade-off of any differentially private algorithm using only empirical measurements of its utility. The versatility of our method is illustrated on a number of machine learning tasks involving multiple models, optimizers, and datasets.

Explore related subjects

Keep this discovery

Explore connections, maps & timelines

BibTeXRIS

Brendan Avent, Javier Gonzalez, Tom Diethe, Andrei Paleyes, Borja Balle. 2020-07-21. Automatic Discovery of Privacy-Utility Pareto Fronts. https://arxiv.org/abs/1905.10862

Cite the original work for its findings. Save a collection to share your selection of sources.

KEEP EXPLORING

Related papers

Attack-Resistant Uniform Fairness for Linear and Smooth Contextual Bandits

Modern digital platforms use contextual bandits to allocate valuable exposure and opportunities among competing participants. Fair treatment is therefore an important concern, yet reward maximization alone does not ensure that preferential allocation reflects participants' merits. We develop algorithms for linear and smooth contextual bandits under uniform merit-based fairness, requiring the reward ordering to justify preferential allocation across all contexts and rounds, and study how these guarantees are affected by adversarial reward corruption. Our algorithms achieve \((1-\widetilde O(1/T))\)-fairness, with regret that is minimax optimal among fair policies for linear rewards and nearly minimax optimal for smooth rewards. In the linear setting, matching lower bounds identify the price of fairness exactly: minimax regret increases from \(\log T\) to \(\log^2 T\). For smooth rewards, the cost of fairness is at most polylogarithmic. We further establish a separation between regret and fairness robustness: an \(\widetilde O(1)\) corruption budget can cause substantial fairness violations without worsening the regret order. We therefore develop robust algorithms that adapt sampling, estimation, and fairness certification to corruption, which preserve uniform fairness and achieve minimax-optimal and nearly optimal regrets for linear and smooth rewards, respectively. Numerical and semi-synthetic experiments illustrate these findings.

stat.ML

The Cost of Privacy: Rates of Convergence for Parameter Estimation with Differential Privacy

We study the minimax cost of $(\varepsilon,δ)$-differential privacy for mean estimation and Gaussian linear regression in low and high dimensions. For low-dimensional mean estimation, a resampling reduction to fingerprinting yields the privacy contribution $d^2\log(1/δ)/(n^2\varepsilon^2)$ in the stated polynomial-$δ$ regime. For low-dimensional regression, a tracing argument gives the contribution $d^2/(n^2\varepsilon^2)$ under an explicit approximate-DP remainder condition. For sparse mean estimation and sparse regression, a constant-weight packing and a private Fano lemma produce an effective privacy entropy of order $\min\{s\log(ed/s),[\log((e^\varepsilon-1)/δ)]_+\}$ for $δ>0$, up to universal constants and a fixed threshold; for pure DP it is $s\log(ed/s)$. Thus, when $δ$ is polynomially smaller than $\varepsilon$, the pure-DP dependence is retained up to polylogarithmic factors whenever the effective dimension is polylogarithmic in $n$, including regimes with $\varepsilon=o(1)$. Coordinatewise-clipping estimators for means and split-sample noisy-gradient estimators for regression attain the lower bounds up to explicit logarithmic factors. Simulations and data examples illustrate related implementations.

stat.ML

Robust Mixture Models for Algorithmic Fairness Under Latent Heterogeneity

Machine learning models optimized for average performance can perform poorly on vulnerable subpopulations. Existing approaches often rely on groups specified in advance, yet fairness-relevant subgroup structure may be latent, intersectional, and driven by complex interactions among continuous and discrete attributes. We introduce \textbf{ROME} (\textbf{\underline{RO}}bust \textbf{\underline{M}}ixture \textbf{\underline{E}}nsemble), a framework that learns latent group structure while optimizing worst-group predictive performance. ROME connects latent-variable modeling with distributionally robust optimization (DRO) through two complementary approaches: an Expectation-Maximization formulation with robust aggregation for linear models and a neural Mixture-of-Experts formulation for nonlinear settings. Across simulations and three real-world regression datasets, ROME improves worst-group performance while maintaining competitive overall accuracy, including in comparisons with established group-aware and group-label-free robust learning methods. ROME provides a flexible approach to robust prediction when fairness-relevant attributes are available for subgroup discovery but their direct use in group-specific outcome models is restricted.

stat.ML