Search arXiv⌕ Search

arXiv · 2409.09558

A Statistical Viewpoint on Differential Privacy: Hypothesis Testing, Representation and Blackwell's Theorem

Abstract

Differential privacy is widely considered the formal privacy for privacy-preserving data analysis due to its robust and rigorous guarantees, with increasingly broad adoption in public services, academia, and industry. Despite originating in the cryptographic context, in this review paper we argue that, fundamentally, differential privacy can be considered a \textit{pure} statistical concept. By leveraging David Blackwell's informativeness theorem, our focus is to demonstrate based on prior work that all definitions of differential privacy can be formally motivated from a hypothesis testing perspective, thereby showing that hypothesis testing is not merely convenient but also the right language for reasoning about differential privacy. This insight leads to the definition of $f$-differential privacy, which extends other differential privacy definitions through a representation theorem. We review techniques that render $f$-differential privacy a unified framework for analyzing privacy bounds in data analysis and machine learning. Applications of this differential privacy definition to private deep learning, private convex optimization, shuffled mechanisms, and U.S.\ Census data are discussed to highlight the benefits of analyzing privacy bounds under this framework compared to existing alternatives.

Explore related subjects

Keep this discovery

Explore connections, maps & timelines

BibTeXRIS

Weijie J. Su. 2024-10-29. A Statistical Viewpoint on Differential Privacy: Hypothesis Testing, Representation and Blackwell's Theorem. https://arxiv.org/abs/2409.09558

Cite the original work for its findings. Save a collection to share your selection of sources.

KEEP EXPLORING

Related papers

Transitional Conditional Independence

Statistical models contain variables that are not random: parameters, treatments, environments, design points. Ordinary conditional independence cannot express relations involving such variables. To apply it one must first put a distribution on them, and that changes the meaning of the statement. This paper introduces transitional conditional independence. It relates three variables on a Markov kernel $K(W|T)$ with non-stochastic input $T$, and is defined by a single factorization: \[ X\perp\!\!\perp_{K(W|T)} Y |Z \quad :\iff \quad \exists\, Q(X|Z):\; K(X,Y,Z|T) = Q(X|Z)\otimes K(Y,Z|T).\] The relation asserts a Markov kernel $Q(X|Z)$ that is the same for every input $t$. It therefore yields a factorization rather than an almost-sure identity between conditional expectations, and it needs no distribution on the input space. The relation is asymmetric. We show that the asymmetry is essential: symmetrizing it destroys the statements it was built to make. We prove left and right versions of all separoid rules except Symmetry. Ten of them hold on arbitrary measurable spaces, the remaining ones under one condition on the spaces involved, and we give criteria for when Symmetry itself holds. We axiomatize the resulting structure and show that it arises from any symmetric separoid by a shift. We give several applications. Ancillarity, sufficiency and adequacy become factorizations that hold pointwise in the parameter, without a prior and without null sets; the theorems of Fisher--Neyman and of Basu take this form. The invariance hypothesis of invariant prediction, $Y \perp\!\!\perp E | X_S$, receives its intended meaning: one kernel predicts $Y$ from $X_S$ in every environment $E$. And Bayesian networks with non-stochastic input nodes satisfy a directed global Markov property whose graphical id-separation criterion returns a factorization of Markov kernels, on arbitrary input spaces.

math.ST↗

Mean Residual Life Ageing Intensity Function

Ageing intensity is usually formulated through the failure rate, whereas its mean residual life (\(MRL\))-based counterpart has not been systematically developed. This paper introduces the mean residual life ageing intensity (\(MRLAI\)) function as an \(MRL\)-based analogue of the failure-rate-based ageing intensity (\(FRAI\)) function. The proposed function compares the current \(MRL\) with its average over \([0,t]\), providing a relative measure of residual-life ageing behaviour. Basic properties of the \(MRLAI\) function are established, including a characterisation of the exponential distribution. The decreasing and increasing \(MRLAI\) classes are introduced and related to the usual \(MRL\)-based ageing classes. Examples are used to clarify the interplay among \(FRAI\), \(MRLAI\), and \(MRL\) monotonicity. Closure and non-closure properties of the proposed classes are examined under mixtures, convolutions, and system formation. An \(MRLAI\)-based stochastic order is also defined, characterised, and compared with classical stochastic orders, and its preservation properties under selected system operations and transformations are investigated.

math.ST↗

Self-Normalizing Denominators in Rational Covariance Estimators

Many estimators are ratios of coprime polynomials in a sample covariance matrix, and their accuracy depends on the relative fluctuation of the sample denominator. Under Gaussian sampling in fixed dimension, we call a nonconstant polynomial denominator self-normalizing if the first-order variance of its relative error does not depend on the population covariance. We prove that these denominators are exactly the flag powers, nonzero constant multiples of products of positive integer powers of nested generalized variances. Equivalently, the denominator's sample-to-population ratio has a covariance-independent finite-sample law, which we determine explicitly. Sufficiency is classical; the new converse shows that a first-order variance condition forces an exact sampling law. We show that relative stability, meaning bounded first-order relative variance, characterizes uniform tightness of scaled relative errors over positive-definite covariances. It permits replacing the sample denominator by its population value in the limit theory of the ratio. Self-normalization is its rigid core. We locate these classes in applications, where regression on predecessors in a fixed order yields only constant or self-normalizing denominators, instrumental-variable formulas yield relatively unstable ones, and nonparametric identifiability does not guarantee relative stability.

math.ST↗