Rényi Differential Privacy

Ilya Mironov
DOI: https://doi.org/10.1109/CSF.2017.11
2017-02-24
Abstract:We propose a natural relaxation of differential privacy based on the Rényi divergence. Closely related notions have appeared in several recent papers that analyzed composition of differentially private mechanisms. We argue that the useful analytical tool can be used as a privacy definition, compactly and accurately representing guarantees on the tails of the privacy loss.We demonstrate that the new definition shares many important properties with the standard definition of differential privacy, while additionally allowing tighter analysis of composite heterogeneous mechanisms.
Mathematics,Computer Science
What problem does this paper attempt to address?
### What problem does this paper attempt to solve? This paper primarily explores an improved version of Differential Privacy (DP) known as Rényi Differential Privacy (RDP). Specifically: 1. **Shortcomings of Differential Privacy**: - The existing `(ε, δ)` definition of differential privacy has limitations when dealing with the Gaussian Noise Mechanism and composite mechanisms. - The Gaussian Noise Mechanism cannot be accurately described by a single `(ε, δ)` parameter in terms of its privacy guarantee. - In composite mechanisms, `(ε, δ)` differential privacy leads to a combinatorial explosion of parameters. 2. **Introduction of Rényi Differential Privacy**: - A new definition based on Rényi divergence is proposed to overcome the aforementioned shortcomings. - The new definition more accurately represents the tail distribution of privacy loss and is more compact and precise in the analysis of composite mechanisms. 3. **Advantages of Rényi Differential Privacy**: - Compared to `(ε, δ)` differential privacy, Rényi Differential Privacy is a stronger privacy definition. - It provides a convenient and quantitatively accurate method to track cumulative privacy loss in both independent and composite mechanisms. - It can be combined with the intuitive concept of privacy budget and the application of advanced composition theorems. Through these improvements, Rényi Differential Privacy can better apply to various privacy-preserving algorithms and their combinations.