{"title": "Privacy Amplification by Subsampling: Tight Analyses via Couplings and Divergences", "book": "Advances in Neural Information Processing Systems", "page_first": 6277, "page_last": 6287, "abstract": "Differential privacy comes equipped with multiple analytical tools for the\ndesign of private data analyses. One important tool is the so-called \"privacy\namplification by subsampling\" principle, which ensures that a differentially\nprivate mechanism run on a random subsample of a population provides higher\nprivacy guarantees than when run on the entire population. Several instances\nof this principle have been studied for different random subsampling methods,\neach with an ad-hoc analysis.  In this paper we present a general method that\nrecovers and improves prior analyses, yields lower bounds and derives new\ninstances of privacy amplification by subsampling. Our method leverages a\ncharacterization of differential privacy as a divergence which emerged in the\nprogram verification community. Furthermore, it introduces new tools,\nincluding advanced joint convexity and privacy profiles, which might be of\nindependent interest.", "full_text": "PrivacyAmpli\ufb01cationbySubsampling:TightAnalysesviaCouplingsandDivergencesBorjaBalleAmazonResearchpigem@amazon.co.ukGillesBartheIMDEASoftwareInstitutegilles.barthe@imdea.orgMarcoGaboardiUniversityatBuffalo,SUNYgaboardi@buffalo.eduAbstractDifferentialprivacycomesequippedwithmultipleanalyticaltoolsforthedesignofprivatedataanalyses.Oneimportanttoolistheso-called\u201cprivacyampli\ufb01cationbysubsampling\u201dprinciple,whichensuresthatadifferentiallyprivatemechanismrunonarandomsubsampleofapopulationprovideshigherprivacyguaranteesthanwhenrunontheentirepopulation.Severalinstancesofthisprinciplehavebeenstudiedfordifferentrandomsubsamplingmethods,eachwithanad-hocanalysis.Inthispaperwepresentageneralmethodthatrecoversandimprovesprioranalyses,yieldslowerboundsandderivesnewinstancesofprivacyampli\ufb01cationbysubsampling.Ourmethodleveragesacharacterizationofdifferentialprivacyasadivergencewhichemergedintheprogramveri\ufb01cationcommunity.Furthermore,itintroducesnewtools,includingadvancedjointconvexityandprivacypro\ufb01les,whichmightbeofindependentinterest.1IntroductionSubsamplingisafundamentaltoolinthedesignandanalysisofdifferentiallyprivatemechanisms.Broadlyspeaking,theintuitionbehindthe\u201cprivacyampli\ufb01cationbysubsampling\u201dprincipleisthattheprivacyguaranteesofadifferentiallyprivatemechanismcanbeampli\ufb01edbyapplyingittoasmallrandomsubsampleofrecordsfromagivendataset.Inmachinelearning,manyclassesofalgorithmsinvolvesamplingoperations,e.g.stochasticoptimizationmethodsandBayesianinferencealgorithms,anditisnotsurprisingthatresultsquantifyingtheprivacyampli\ufb01cationobtainedviasubsamplingplayakeyroleindesigningdifferentiallyprivateversionsoftheselearningalgorithms[Bassilyetal.,2014,Wangetal.,2015,Abadietal.,2016,J\u00e4lk\u00f6etal.,2017,Parketal.,2016b,a].Additionally,fromapracticalstandpointsubsamplingprovidesastraightforwardmethodtoobtainprivacyampli\ufb01cationwhenthe\ufb01nalmechanismisonlyavailableasablack-box.Forexample,inApple\u2019siOSandGoogle\u2019sChromedeploymentsofdifferentialprivacyfordatacollectiontheprivacyparametersarehard-codedintotheimplementationandcannotbemodi\ufb01edbytheuser.Inthistypeofsettings,ifthedefaultprivacyparametersarenotsatisfactoryonecouldachieveastrongerprivacyguaranteebydevisingastrategythatonlysubmitstothemechanismarandomsampleofthedata.Despitethepracticalimportanceofsubsampling,existingtoolstoboundprivacyampli\ufb01cationonlyworkforspeci\ufb01cformsofsubsamplingandtypicallycomewithcumbersomeproofsprovidingnoinformationaboutthetightnessoftheresultingbounds.Inthispaperweremedythissituationbypro-vidingageneralframeworkforderivingtightprivacyampli\ufb01cationresultsthatcanbeappliedtoanyofthesubsamplingstrategiesconsideredintheliterature.Ourframeworkbuildsonacharacterizationofdifferentialprivacyintermsof\u03b1-divergences[BartheandOlmedo,2013].Thischaracterizationhasbeenusedbeforeforprogramveri\ufb01cation[Bartheetal.,2012,2016],whileweuseithereforthe\ufb01rsttimeinthecontextofalgorithmanalysis.Inordertodothis,wedevelopseveralnovelanalyticaltools,includingadvancedjointconvexity\u2013apropertyof\u03b1-divergencewithrespectto32ndConferenceonNeuralInformationProcessingSystems(NeurIPS2018),Montr\u00e9al,Canada.\fmixturedistributions\u2013andprivacypro\ufb01les\u2013ageneraltooldescribingtheprivacyguaranteesthatprivatealgorithmsprovide.Oneofourmotivationstoinitiateasystematicstudyofprivacyampli\ufb01cationbysubsamplingisthatthisisanimportantprimitiveforthedesignofdifferentiallyprivatealgorithmswhichhasreceivedlessattentionthanotherbuildingblockslikecompositiontheorems[Dworketal.,2010,Kairouzetal.,2017,MurtaghandVadhan,2016].Giventherelevanceofsamplingoperationsinmachinelearning,itisimportanttounderstandwhatarethelimitationsofprivacyampli\ufb01cationanddevelopa\ufb01ne-grainedunderstandingofitstheoreticalproperties.Ourresultsprovidea\ufb01rststepinthisdirectionbyshowinghowprivacyampli\ufb01cationresultingfromdifferentsamplingtechniquescanbeanalyzedbymeansofsinglesetoftools,andbyshowinghowthesetoolscanbeusedforprovinglowerbounds.Ouranalysesalsohighlighttheimportanceofchoosingasamplingtechniquethatiswell-adaptedtothenotionofneighbouringdatasetsunderconsideration.Asecondmotivationisthatsubsamplingprovidesanaturalexampleofmechanismswheretheoutputdistributionisamixture.Becausemixtureshaveanadditivestructureanddifferentialprivacyisde\ufb01nedintermsofamultiplicativeguarantee,analyzingtheprivacyguaranteesofmechanismswhoseoutputdistributionisamixtureisingeneralachallengingtask.Althoughouranalysesarespecializedtomixturesarisingfromsubsampling,webelievethetoolswedevelopintermsofcouplingsanddivergenceswillalsobeusefultoanalyzeothertypesofmechanismsinvolvingmixturedistributions.Finally,wewanttoremarkthatprivacyampli\ufb01cationresultsalsoplayaroleinanalyzingthegeneralizationandsamplecomplexitypropertiesofprivatelearningalgorithms[Kasiviswanathanetal.,2011,Beimeletal.,2013,Bunetal.,2015,Wangetal.,2016];anin-depthunderstandingoftheinterplaybetweensamplinganddifferentialprivacymightalsohaveapplicationsinthisdirection.2ProblemStatementandMethodologyOverviewAmechanismM:X\u2192P(Z)withinputspaceXandoutputspaceZisarandomizedalgorithmthatoninputxoutputsasamplefromthedistributionM(x)overZ.HereP(Z)denotesthesetofprobabilitymeasuresontheoutputspaceZ.WeimplicitlyassumeZisequippedwithasigma-algebraofmeasurablesubsetsandabasemeasure,inwhichcaseP(Z)isrestrictedtoprobabilitymeasuresthatareabsolutelycontinuouswithrespecttothebasemeasure.InmostcasesofinterestZiseitheradiscretespaceequippedwiththecountingmeasureoranEuclideanspaceequippedwiththeLebesguemeasure.WealsoassumeXisequippedwithabinarysymmetricrelation\u2019Xde\ufb01ningthenotionofneighbouringinputs.Let\u03b5\u22650and\u03b4\u2208[0,1].AmechanismMissaidtobe(\u03b5,\u03b4)-differentiallyprivatew.r.t.\u2019Xifforeverypairofinputsx\u2019Xx0andeverymeasurablesubsetE\u2286ZwehavePr[M(x)\u2208E]\u2264e\u03b5Pr[M(x0)\u2208E]+\u03b4.(1)Forourpurposes,itwillbemoreconvenienttoexpressdifferentialprivacyintermsof\u03b1-divergences1.Concretely,the\u03b1-divergence(\u03b1\u22651)betweentwoprobabilitymeasures\u00b5,\u00b50\u2208P(Z)isde\ufb01nedas2D\u03b1(\u00b5k\u00b50)=supE(\u00b5(E)\u2212\u03b1\u00b50(E))=ZZ(cid:20)d\u00b5d\u00b50(z)\u2212\u03b1(cid:21)+d\u00b50(z)=Xz\u2208Z[\u00b5(z)\u2212\u03b1\u00b50(z)]+,(2)whereErangesoverallmeasurablesubsetsofZ,[\u2022]+=max{\u2022,0},andthelastequalityisaspecializationfordiscreteZ.Itiseasytosee[BartheandOlmedo,2013]thatMis(\u03b5,\u03b4)-differentiallyprivateifandonlyifDe\u03b5(M(x)kM(x0))\u2264\u03b4foreveryxandx0suchthatx\u2019Xx0.InordertoemphasizetherelevantpropertiesofMfromaprivacyampli\ufb01cationpointofview,weintroducetheconceptsofprivacypro\ufb01leandgroup-privacypro\ufb01les.Theprivacypro\ufb01le\u03b4MofamechanismMisafunctionassociatingtoeachprivacyparameter\u03b1=e\u03b5aboundonthe\u03b1-divergencebetweentheresultsofrunningthemechanismontwoadjacentdatasets,i.e.\u03b4M(\u03b5)=supx\u2019Xx0De\u03b5(M(x)kM(x0))(wewilldiscussthepropertiesofthistoolinmoredetailsinthenextsection).Informallyspeaking,theprivacypro\ufb01lerepresentsthesetofallofprivacyparametersunder1Alsoknownintheliteratureaselementarydivergences[\u00d6sterreicher,2002]andhockey-stickdivergences[SasonandVerd\u00fa,2016].2Hered\u00b5/d\u00b50denotestheRadon-Nikodymderivativebetween\u00b5and\u00b50.Inparticular,if\u00b5and\u00b50havedensitiesp=d\u00b5/d\u03bdandp0=d\u00b50/d\u03bdwithrespecttosomebasemeasure\u03bd,thend\u00b5/d\u00b50=p/p0.2\fwhichamechanismprovidesdifferentialprivacy.Inparticular,recallthatan(\u03b5,\u03b4)-DPmechanismMisalso(\u03b50,\u03b40)-DPforany\u03b50\u2265\u03b5andany\u03b40\u2265\u03b4.Theprivacypro\ufb01le\u03b4Mde\ufb01nesacurvein[0,\u221e)\u00d7[0,1]thatseparatesthespaceofprivacyparametersintotworegions:theonesforwhichMsatis\ufb01esdifferentialprivacyandtheonesforwhichitdoesnot.ThiscurveexistsforeverymechanismM,evenformechanismsthatsatisfypureDPforsomevalueof\u03b5.Whenthemechanismisclearfromthecontextwemightslightlyabuseournotationandwrite\u03b4(\u03b5)or\u03b4forthecorrespondingprivacypro\ufb01le.Tode\ufb01negroup-privacypro\ufb01les\u03b4M,k(k\u22651)weusethepath-distancedinducedby\u2019X:d(x,x0)=min{k:\u2203x1,...,xk\u22121,x\u2019Xx1,x1\u2019Xx2,...,xk\u22121\u2019Xx0}.Withthisnotation,wede\ufb01ne\u03b4M,k(\u03b5)=supd(x,x0)\u2264kDe\u03b5(M(x)kM(x0)).Notethat\u03b4M=\u03b4M,1.ProblemStatementAwell-knownmethodforincreasingprivacyofamechanismistoapplythemechanismtoarandomsubsampleoftheinputdatabase,ratherthanonthedatabaseitself.Intuitively,themethoddecreasesthechancesofleakinginformationaboutaparticularindividualbecausenothingaboutthatindividualcanbeleakedinthecaseswheretheindividualisnotincludedinthesubsample.Thequestionaddressedinthispaperistodevisemethodsforquantifyingampli\ufb01cationandforprovingoptimalityofthebounds.Thisturnsouttobeasurprisinglysubtleproblem.Formally,letXandYbetwosetsequippedwithneighbouringrelations\u2019Xand\u2019Yrespectively.WeassumethatbothXandYcontaindatabases(modelledassets,multisets,ortuples)overauniverseUthatrepresentsallpossiblerecordscontainedinadatabase.AsubsamplingmechanismisarandomizedalgorithmS:X\u2192P(Y)thattakesasinputadatabasexandoutputsa\ufb01nitelysupporteddistributionoverdatasets.Notethatwe\ufb01nditconvenienttodistinguishbetweenXandYbecausexandymightnotalwayshavethesametype.Forexample,samplingwithreplacementfromasetxyieldsamultisety.Theproblemofprivacyampli\ufb01cationcannowbestatedasfollows:letM:Y\u2192P(Z)beamechanismwithprivacypro\ufb01le\u03b4Mwithrespectto\u2019Y,andletSbeasubsamplingmechanism.ConsiderthesubsampledmechanismMS:X\u2192P(Z)givenbyMS(x)=M(S(x)),wherethecompositionnotationmeanswefeedasamplefromS(x)intoM.Thegoalistorelatetheprivacypro\ufb01lesofMandMS,viaaninequalityoftheform:forevery\u03b5\u22650,thereexists0\u2264\u03b50\u2264\u03b5suchthat\u03b4MS(\u03b50)\u2264h(\u03b4M(\u03b5)),wherehissomefunctiontobedetermined.Intermsofdifferentialprivacy,onecanbereadassayingthatifMis(\u03b5,\u03b4)-DP,thenthesubsampledmechanismMSis(\u03b50,h(\u03b4))-DPforsome\u03b50\u2264\u03b5.Thisisaprivacyampli\ufb01cationstatementbecausethenewmechanismhasbetterprivacyparametersthantheoriginalone.Afullspeci\ufb01cationofthisproblemrequiresformalizingthefollowingthreeingredients:(i)datasetrepresentationspecifyingwhethertheinputstothemechanismaresets,multisets,ortuples;(ii)neighbouringrelationsinXandY,includingtheusualremove/add-one\u2019randsubstitute-one\u2019srelations;(iii)subsamplingmethodanditsparameters,withthemostcommonlyusedbeingsubsamplewithoutreplacement,subsamplingwithreplacement,andPoissonsubsampling.Regardlessofthespeci\ufb01csettingbeingconsidered,themainchallengeintheanalysisofprivacyampli\ufb01cationbysubsamplingresidesinthefactthattheoutputdistributionofthemechanism\u00b5=MS(x)\u2208P(Z)isamixturedistribution.Inparticular,writing\u00b5y=M(y)\u2208P(Z)foranyy\u2208Yandtaking\u03c9=S(x)\u2208P(Y)tobethe(\ufb01nitelysupported)distributionoversubsamplesfromxproducedbythesubsamplingmechanism,wecanwrite\u00b5=Py\u03c9(y)\u00b5y=\u03c9M,whereMdenotestheMarkovkerneloperatingonmeasuresde\ufb01nedbyM.Consequently,provingprivacyampli\ufb01cationsresultsrequiresreasoningaboutthemixturesobtainedwhensamplingfromtwoneighbouringdatasetsx\u2019Xx0,andhowtheprivacyparametersareaffectedbythemixture.OurContributionWeprovideauni\ufb01edmethodforderivingprivacyampli\ufb01cationbysubsamplingbounds(Section3).Ourmethodrecoversallexistingresultsintheliteratureandallowustoderivenovelampli\ufb01cationbounds(Section4).Inmostcasesourmethodalsoprovidesoptimalconstantswhichareshowntobetightbyagenericlowerbound(Section5).Ouranalysisreliesonpropertiesofdivergencesandprivacypro\ufb01les,togetherwithtwoadditionalingredients.The\ufb01rstingredientisanoveladvancedjointconvexitypropertyprovidingupperboundsonthe\u03b1-divergencebetweenoverlappingmixturedistributions.Inthespeci\ufb01ccontextofdifferentialprivacythisresultyieldsforeveryx\u2019Xx0:De\u03b50(MS(x)kMS(x0))\u2264\u03b7\u00b7((1\u2212\u03b2)De\u03b5(\u00b51k\u00b50)+\u03b2De\u03b5(\u00b51k\u00b501)),(3)3\fSubsampling\u2019Y\u2019X\u03b7\u03b40TheoremPoisson(\u03b3)RR\u03b3\u03b3\u03b48WOR(n,m)SSmnmn\u03b49WR(n,m)SS1\u2212(cid:0)1\u22121n(cid:1)mPmk=1(cid:0)mk(cid:1)(cid:0)1n(cid:1)k(cid:0)1\u22121n(cid:1)m\u2212k\u03b4k10WR(n,m)SR1\u2212(cid:0)1\u22121n(cid:1)mPmk=1(cid:0)mk(cid:1)(cid:0)1n(cid:1)k(cid:0)1\u22121n(cid:1)m\u2212k\u03b4k11Table1:Summaryofprivacyampli\ufb01cationbounds.Ampli\ufb01cationparameter\u03b7:e\u03b50=1+\u03b7(e\u03b5\u22121).Typesofsubsampling:withoutreplacement(WOR)andwithreplacement(WR).Neighbouringrelations:remove/add-one(R)andsubstituteone(S).fore\u03b50=1+\u03b7(e\u03b5\u22121),some\u03b2\u2208[0,1],and\u03b7=TV(S(x),S(x0))beingthetotalvariationdistancebetweenthedistributionsoversubsamples.Here\u00b50,\u00b51,\u00b501\u2208P(Z)aresuitablemeasuresobtainedfromMS(x)andMS(x0)throughacouplingandprojectionoperation.Inparticular,theproofofadvancedjointconvexityusesideasfromprobabilisticcouplings,andmorespeci\ufb01callythemaximalcouplingconstruction(seeTheorem2anditsproofformoredetails).Itisalsointerestingtonotethatthenon-linearrelation\u03b50=log(1+\u03b7(e\u03b5\u22121))alreadyappearsinsomeexistingprivacyampli\ufb01cationresults(e.g.Lietal.[2012]).Althoughforsmall\u03b5and\u03b7thisrelationyields\u03b50=O(\u03b7\u03b5),ourresultsshowthatthemorecomplicatednon-linearrelationisinfactafundamentalaspectofprivacyampli\ufb01cationbysubsampling.Thesecondingredientinouranalysisestablishesanupperboundforthedivergencesoccurringintherighthandsideof(3)intermsofgroup-privacypro\ufb01les.Itstatesthatundersuitableconditions,wehaveDe\u03b5(\u03bdMk\u03bd0M)\u2264Pk\u22651\u03bbk(\u03bd)\u03b4M,k(e\u03b5)forsuitablechoicesof\u03bbk.Again,theproofoftheinequalityusestoolsfromprobabilisticcouplings.Thecombinationoftheseresultsyieldsaboundoftheprivacypro\ufb01leofMSasafunctionofthegroup-privacypro\ufb01lesofM.Basedonthisinequality,wewillestablishseveralprivacyampli\ufb01cationresultandprovetightnessresults.Thismethodologycanbeappliedtoanyofthesettingsdiscussedaboveintermsofdatasetrepresentation,neighbouringrelation,andtypeofsubsampling.Table1summarizesseveralresultsthatcanbeobtainedwithourmethod(seeSection4fordetails).Thesupplementarymaterialalsocontainsplotsillustratingourbounds(Figure1)andproofsofalltheresultspresentedinthepaper.3Tools:Couplings,DivergencesandPrivacyPro\ufb01lesWenextintroduceseveraltoolsthatwillbeusedtosupportouranalyses.The\ufb01rstandsecondtoolsareknown,whereastheremainingtoolsarenewandofindependentinterest.DivergencesThefollowingcharacterizationfollowsimmediatelyfromthede\ufb01nitionof\u03b1-divergenceintermsofthesupremumoverE.Theorem1([BartheandOlmedo,2013]).AmechanismMis(\u03b5,\u03b4)-differentiallyprivatewithrespectto\u2019Xifandonlyifsupx\u2019Xx0De\u03b5(M(x)kM(x0))\u2264\u03b4.Notethatinthestatementofthetheoremwetake\u03b1=e\u03b5.Throughoutthepaperwesometimesusethesetwonotationsinterchangeablytomakeexpressionsmorecompact.Wenowstateconsequencesofthede\ufb01nitionof\u03b1-divergence:(i)0\u2264D\u03b1(\u00b5k\u00b50)\u22641;(ii)thefunction\u03b17\u2192D\u03b1(\u00b5k\u00b50)ismonotonicallydecreasing;(iii)thefunction(\u00b5,\u00b50)7\u2192D\u03b1(\u00b5k\u00b50)isjointlyconvex.Furthermore,onecanshowthatlim\u03b1\u2192\u221eD\u03b1(\u00b5k\u00b50)=0ifandonlyifsupp(\u00b5)\u2286supp(\u00b50).CouplingsCouplingsareastandardtoolforderivingupperboundsforthestatisticaldistancebetweendistributions.Concretely,itiswell-knownthatthetotalvariationdistancebetweentwodistributions\u03bd,\u03bd0\u2208P(Y)satis\ufb01esTV(\u03bd,\u03bd0)\u2264Pr\u03c0[y6=y0]foranycoupling\u03c0,whereequalityisattainedbytakingtheso-calledmaximalcoupling.Werecallthede\ufb01nitionofcouplingandprovideaconstructionofthemaximalcoupling,whichweshalluseinlatersections.4\fAcouplingbetweentwodistributions\u03bd,\u03bd0\u2208P(Y)isadistribution\u03c0\u2208P(Y\u00d7Y)whosemarginalsalongtheprojections(y,y0)7\u2192yand(y,y0)7\u2192y0are\u03bdand\u03bd0respectively.Couplingsalwaysexist,andfurthermore,thereexistsamaximalcoupling,whichexactlycharacterizesthetotalvariationdistancebetween\u03bdand\u03bd0.Let\u03bd0(y)=min{\u03bd(y),\u03bd0(y)}andlet\u03b7=TV(\u03bd,\u03bd0)=1\u2212Py\u2208Y\u03bd0(y),whereTVdenotesthetotalvariationdistance.Themaximalcouplingbetween\u03bdand\u03bd0isde\ufb01nedasthemixture\u03c0=(1\u2212\u03b7)\u03c00+\u03b7\u03c01,where\u03c00(y,y0)=\u03bd0(y)1[y=y0]/(1\u2212\u03b7),and\u03bd1(y,y0)=(\u03bd(y)\u2212\u03bd0(y))(\u03bd0(y0)\u2212\u03bd0(y0))/\u03b7.Projectingthemaximalcouplingalongthemarginalsyieldstheoverlappingmixturedecompositions\u03bd=(1\u2212\u03b7)\u03bd0+\u03b7\u03bd1and\u03bd0=(1\u2212\u03b7)\u03bd0+\u03b7\u03bd01.AdvancedJointConvexityTheprivacyampli\ufb01cationphenomenonistightlyconnectedtoaninterestingnewformofjointconvexityfor\u03b1-divergences,whichwecalladvancedjointconvexity.Theorem2(AdvancedJointConvexityofD\u03b13).Let\u00b5,\u00b50\u2208P(Z)bemeasuressatisfying\u00b5=(1\u2212\u03b7)\u00b50+\u03b7\u00b51and\u00b50=(1\u2212\u03b7)\u00b50+\u03b7\u00b501forsome\u03b7,\u00b50,\u00b51,and\u00b501.Given\u03b1\u22651,let\u03b10=1+\u03b7(\u03b1\u22121)and\u03b2=\u03b10/\u03b1.Thenthefollowingholds:D\u03b10(\u00b5k\u00b50)=\u03b7D\u03b1(\u00b51k(1\u2212\u03b2)\u00b50+\u03b2\u00b501).(4)Notethatwriting\u03b1=e\u03b5and\u03b10=e\u03b50intheabovelemmawegettherelation\u03b50=log(1+\u03b7(e\u03b5\u22121)).Applyingstandardjointconvexitytotherighthandsideaboveweconclude:D\u03b10(\u00b5k\u00b50)\u2264(1\u2212\u03b2)\u03b7D\u03b1(\u00b51k\u00b50)+\u03b2\u03b7D\u03b1(\u00b51k\u00b501).NotethatapplyingjointconvexitydirectlyonD\u03b10(\u00b5k\u00b50)insteadofadvancedjointcomplexityyieldsaweakerboundwhichimpliesampli\ufb01cationforthe\u03b4privacyparameter,butnotforthe\u03b5privacyparameter.Whenusingadvancedjointconvexitytoanalyzeprivacyampli\ufb01cationweconsidertwoelementsxandx0and\ufb01xthefollowingnotation.Let\u03c9=S(x)and\u03c90=S(x0)and\u00b5=\u03c9Mand\u00b50=\u03c90M,whereweusethenotationMtodenotetheMarkovkernelassociatedwithmechanismMoperatingonmeasuresoverY.Wethenconsiderthemixturefactorizationof\u03c9and\u03c90obtainedbytakingthedecompositionsinducedbyprojectingthemaximalcoupling\u03c0=(1\u2212\u03b7)\u03c00+\u03b7\u03c01onthe\ufb01rstandsecondmarginals:\u03c9=(1\u2212\u03b7)\u03c90+\u03b7\u03c91and\u03c90=(1\u2212\u03b7)\u03c90+\u03b7\u03c901.Itiseasytoseefromtheconstructionofthemaximalcouplingthat\u03c91and\u03c901havedisjointsupportsand\u03b7isthesmallestprobabilitysuchthatthisconditionholds.Inthiswayweobtainthecanonicalmixturedecompositions\u00b5=(1\u2212\u03b7)\u00b50+\u03b7\u00b51and\u00b50=(1\u2212\u03b7)\u00b50+\u03b7\u00b501,where\u00b50=\u03c90M,\u00b51=\u03c91Mand\u00b501=\u03c901M.PrivacyPro\ufb01lesWestatesomeimportantpropertiesofprivacypro\ufb01les.Our\ufb01rstresultillustratesourclaimthatthe\u201cprivacycurve\u201dexistsforeverymechanismMinthecontextoftheLaplaceoutputperturbationmechanism.Theorem3.Letf:X\u2192Rbeafunctionwithglobalsensitivity\u2206=supx\u2019Xx0|f(x)\u2212f(x0)|.SupposeM(x)=f(x)+Lap(b)isaLaplaceoutputperturbationmechanismwithnoiseparameterb.Theprivacypro\ufb01leofMisgivenby\u03b4M(\u03b5)=[1\u2212exp(\u03b5\u2212\u03b82)]+,where\u03b8=\u2206/b.Thewell-knownfactthattheLaplacemechanismwithb\u2265\u2206/\u03b5is(\u03b5,0)-DPfollowsfromthisresultbynotingthat\u03b4M(\u03b5)=0forany\u03b5\u2265\u03b8.However,Theorem3alsoprovidesmoreinformation:itshowsthatfor\u03b5<\u2206/btheLaplacemechanismwithnoiseparameterbsatis\ufb01es(\u03b5,\u03b4)-DPwith\u03b4=\u03b4M(\u03b5).FormechanismsthatonlysatisfyapproximateDP,theprivacypro\ufb01leprovidesinformationaboutthebehaviourof\u03b4M(\u03b5)asweincrease\u03b5\u2192\u221e.TheclassicalanalysisfortheGaussianoutputperturbationmechanismprovidessomeinformationinthisrespect.Recallthatforafunctionf:X\u2192RdwithL2globalsensitivity\u2206=supx\u2019Xx0kf(x)\u2212f(x)k2themechanismM(x)=f(x)+N(0,\u03c32I)satis\ufb01es(\u03b5,\u03b4)-DPif\u03c32\u22652\u22062log(1.25/\u03b4)/\u03b52and\u03b5\u2208(0,1)(cf.[DworkandRoth,2014,TheoremA.1]).Thiscanberewrittenas\u03b4M(\u03b5)\u22641.25e\u2212\u03b52/2\u03b82for\u03b5\u2208(0,1),where\u03b8=\u2206/\u03c3.Recently,[BalleandWang,2018]gaveanewanalysisoftheGaussianmechanismthatisvalidforallvaluesof\u03b5.Theiranalysiscanbeinterpretedasprovidinganexpressionfortheprivacypro\ufb01leoftheGaussianmechanismintermsoftheCDFofastandardnormaldistribution\u03a6(t)=(2\u03c0)\u22121/2Rt\u2212\u221ee\u2212r2/2dr.Theorem4([BalleandWang,2018]).Letf:X\u2192RdbeafunctionwithL2globalsensitivity\u2206.Forany\u03c3>0let\u03b8=\u2206/\u03c3.Theprivacypro\ufb01leoftheGaussianmechanismM(x)=f(x)+N(0,\u03c32I)isgivenby\u03b4M(e\u03b5)=\u03a6(\u03b8/2\u2212\u03b5/\u03b8)\u2212e\u03b5\u03a6(\u2212\u03b8/2\u2212\u03b5/\u03b8).3Proofsofallourresultsarepresentedintheappendix.5\fInterestingly,theproofofTheorem4implicitlyprovidesacharacterizationofprivacypro\ufb01lesintermsofprivacylossrandomvariablesthatholdsforanymechanism.RecallthattheprivacylossrandomvariableofamechanismMoninputsx\u2019Xx0isde\ufb01nedasLx,x0M=log(d\u00b5/d\u00b50)(z),where\u00b5=M(x),\u00b50=M(x0),andz\u223c\u00b5.Theorem5([BalleandWang,2018]).Theprivacypro\ufb01leofanymechanismMsatis\ufb01es\u03b4M(\u03b5)=supx\u2019Xx0(cid:16)Pr[Lx,x0M>\u03b5]\u2212e\u03b5Pr[Lx0,xM<\u2212\u03b5](cid:17).Thecharacterizationabovegeneralizesthewell-knowninequality\u03b4M(\u03b5)\u2264supx\u2019Xx0Pr[Lx,x0M>\u03b5](eg.see[DworkandRoth,2014]).Thisboundisoftenusedtoderive(\u03b5,\u03b4)-DPguaranteesfromothernotionsofprivacyde\ufb01nedintermsofthemomentgeneratingfunctionoftheprivacylossrandomvariable,includingconcentratedDP[DworkandRothblum,2016],zero-concentratedDP[BunandSteinke,2016],R\u00e9nyiDP[Mironov,2017],andtruncatedconcentratedDP[Bunetal.,2018].Wenowshowareverseimplicationalsoholds.Namely,thatprivacypro\ufb01lescanbeusedtorecoveralltheinformationprovidedbythemomentgeneratingfunctionoftheprivacylossrandomvariable.Theorem6.GivenamechanismMandinputsx\u2019Xx0let\u00b5=M(x)and\u00b50=M(x0).Fors\u22650,de\ufb01nethemomentgeneratingfunction\u03d5x,x0M(s)=E[exp(sLx,x0M)].Thenwehave\u03d5x,x0M(s)=1+s(s+1)Z\u221e0(cid:16)es\u03b5De\u03b5(\u00b5k\u00b50)+e\u2212(s+1)\u03b5De\u03b5(\u00b50k\u00b5)(cid:17)d\u03b5.Inparticular,ifDe\u03b5(\u00b5k\u00b50)=De\u03b5(\u00b50k\u00b5)holds4foreveryx\u2019Xx0,thensupx\u2019Xx0\u03d5x,x0M(s)=1+s(s+1)R\u221e0(es\u03b5+e\u2212(s+1)\u03b5)\u03b4M(\u03b5)d\u03b5.Group-privacyPro\ufb01lesRecallthekthgroupprivacypro\ufb01leofamechanismMisde\ufb01nedas\u03b4M,k(\u03b5)=supd(x,x0)\u2264kDe\u03b5(M(x)kM(x0)).Astandardgroupprivacyanalysis5immediatelyyields\u03b4M,k(\u03b5)\u2264(e\u03b5\u22121)\u03b4M(\u03b5/k)/(e\u03b5/k\u22121).However,\u201cwhite-box\u201dapproachesbasedonfullknowledgeoftheprivacypro\ufb01leofMcanbeusedtoimprovethisresultforspeci\ufb01cmechanisms.Forexample,itisnothardtoseethat,combiningtheexpressionsfromTheorems3and4withthetriangleinequalityontheglobalsensitivityofchangingkrecordsinadataset,oneobtainsboundsthatimproveonthe\u201cblack-box\u201dapproachforallrangesofparametersfortheLaplaceandGaussianmechanisms.Thisisoneofthereasonswhywestateourboundsdirectlyintermsof(group-)privacypro\ufb01les(anumericalcomparisoncanbefoundinthesupplementarymaterial).Distance-compatibleCouplingThelasttoolweneedtoprovegeneralprivacyampli\ufb01cationboundsbasedon\u03b1-divergencesistheexistenceofacertaintypeofcouplingsbetweentwodistribu-tionsliketheonesoccurringintherighthandsideof(4).Recallthatanycoupling\u03c0betweentwodistributions\u03bd,\u03bd0\u2208P(Y)canbeusedtorewritethemixturedistributions\u02dc\u00b5=\u03bdMand\u02dc\u00b50=\u03bd0Mas\u02dc\u00b5=Py,y0\u03c0y,y0M(y)and\u02dc\u00b50=Py,y0\u03c0y,y0M(y0).UsingthejointconvexityofD\u03b1andthede\ufb01nitionofgroup-privacypro\ufb01lestogettheboundDe\u03b5(\u02dc\u00b5k\u02dc\u00b50)\u2264Xy,y0\u03c0y,y0De\u03b5(M(y)kM(y0))\u2264Xy,y0\u03c0y,y0\u03b4M,dY(y,y0)(\u03b5).(5)Sincethisboundholdsforanycoupling\u03c0,onecansetouttooptimizeitby\ufb01ndingacouplingtheminimizestherighthandsideof(5).WeshowthattheexistenceofcouplingswhosesupportiscontainedinsideacertainsubsetofY\u00d7Yisenoughtoobtainanoptimalbound.Furthermore,weshowthatwhenthisconditionissatis\ufb01edtheresultingbounddependsonlyon\u03bdandthegroup-privacypro\ufb01lesofM.Wesaythattwodistributions\u03bd,\u03bd0\u2208P(Y)aredY-compatibleifthereexistsacoupling\u03c0between\u03bdand\u03bd0suchforany(y,y0)\u2208supp(\u03c0)wehavedY(y,y0)=dY(y,supp(\u03bd0)),wherethedistancebetweenapointyandthesetsupp(\u03bd0)isde\ufb01nedasthedistancebetweenyandtheclosestpointinsupp(\u03bd0).4Forexample,thisissatis\ufb01edbyalloutputperturbationmechanismswithsymmetricnoisedistributions.5IfMis(\u03b5,\u03b4)-DPwithrespectto\u2019Y,thenitis(k\u03b5,((ek\u03b5\u22121)/(e\u03b5\u22121))\u03b4)-DPwithrespectto\u2019kY,cf.[Vadhan,2017,Lemma2.2]6\fTheorem7.LetC(\u03bd,\u03bd0)bethesetofallcouplingsbetween\u03bdand\u03bd0andfork\u22651letYk={y\u2208supp(\u03bd):dY(y,supp(\u03bd0))=k}.If\u03bdand\u03bd0aredY-compatible,thenthefollowingholds:min\u03c0\u2208C(\u03bd,\u03bd0)Xy,y0\u03c0y,y0\u03b4M,dY(y,y0)(\u03b5)=Xk\u22651\u03bd(Yk)\u03b4M,k(\u03b5).(6)Applyingthisresulttotheboundresultingfromtherighthandsideof(4)yieldsmostoftheconcreteprivacyampli\ufb01cationresultspresentedinthenextsection.4PrivacyAmpli\ufb01cationBoundsInthissectionweprovideexplicitprivacyampli\ufb01cationboundsforthemostcommonsubsamplingmethodsandneighbouringrelationsfoundintheliteratureondifferentialprivacy,andprovidepointerstoexistingboundsandotherrelatedwork.Forouranalysisweworkwithorder-independentrepresentationsofdatasetswithoutrepetitions,i.e.sets.Thisismostlyfortechnicalconvenience,sinceallourresultsalsoholdifoneconsidersdatasetsrepresentedastuplesormultisets.Notehoweverthatsubsamplingwithreplacementforasetcanyieldamultiset;henceweintroducesuitablenotationsforsetsandmultisets.FixauniverseofrecordsUandlet2={0,1}.Wewrite2UandNUforthespacesofallsetsandmultisetswithrecordsfromU.Noteeverysetisalsoamultiset.Forn\u22650wealsowrite2UnandNUnforthespacesofallsetsandmultisetscontainingexactlynrecords6fromU.Givenx\u2208NUwewritexuforthenumberofoccurrencesofu\u2208Uinx.Thesupportofamultisetxisthede\ufb01nedasthesetsupp(x)={u\u2208U:xu>0}ofelementsthatoccuratleastonceinx.Givenmultisetsx,x0\u2208NUwewritex0\u2286xtodenotethatx0u\u2264xuforallu\u2208U.Fororder-independentdatasetsrepresentedasmultisetsitisnaturaltoconsiderthetwofollowingneighbouringrelations.Theremove/add-onerelationisobtainedbylettingx\u2019rx0holdwheneverx\u2286x0with|x|=|x0|\u22121orx0\u2286xwith|x|=|x0|+1;i.e.x0isobtainedbyremovingoraddingasingleelementtox.Thesubstitute-onerelationisobtainedbylettingx\u2019sx0holdwheneverkx\u2212x0k1=2and|x|=|x0|;i.e.x0isobtainedbyreplacinganelementinxwithadifferentelementfromU.Notehow\u2019rrelatespairsofdatasetswithdifferentsizes,while\u2019sonlyrelatespairsofdatasetswiththesamesize.PoissonSubsamplingPerhapsthemostwell-knownprivacyampli\ufb01cationresultreferstotheanalysisofPoissonsubsamplingwithrespecttotheremove/add-onerelation.InthiscasethesubsamplingmechanismSpo\u03b3:2U\u2192P(2U)takesasetxandoutputsasampleyfromthedistribution\u03c9=Spo\u03b3(x)supportedonallsety\u2286xgivenby\u03c9(y)=\u03b3|y|(1\u2212\u03b3)|x|\u2212|y|.Thiscorrespondstoindependentlyaddingtoywithprobability\u03b3eachelementfromx.Now,givenamechanismM:2U\u2192P(Z)withprivacypro\ufb01le\u03b4Mwithrespectto\u2019r,weareinterestedinboundingtheprivacypro\ufb01leofthesubsampledmechanismMSwo\u03b3withrespectto\u2019r.Theorem8.LetM0=MSpo\u03b3.Forany\u03b5\u22650wehave\u03b4M0(\u03b50)\u2264\u03b3\u03b4M(\u03b5),where\u03b50=log(1+\u03b3(e\u03b5\u22121)).Privacyampli\ufb01cationwithPoissonsamplingwasusedin[ChaudhuriandMishra,2006,Beimeletal.,2010,Kasiviswanathanetal.,2011,Beimeletal.,2014],whichconsideredloosebounds.Aproofofthistightresultintermsof(\u03b5,\u03b4)-DPwas\ufb01rstgivenin[Lietal.,2012].Inthecontextofthemomentsaccountanttechniquebasedonthemomentgeneratingfunctionoftheprivacylossrandomvariable,[Abadietal.,2016]provideanampli\ufb01cationresultforGaussianoutputperturbationmechanismsunderPoissonsubsampling.SamplingWithoutReplacementAnotherknownresultsonprivacyampli\ufb01cationcorrespondstotheanalysisofsamplingwithoutreplacementwithrespecttothesubstitutionrelation.InthiscaseoneconsidersthesubsamplingmechanismSwom:2Un\u2192P(2Um)thatgivenasetx\u22082Unofsizenoutputsasamplefromtheuniformdistribution\u03c9=Swom(x)overallsubsetsy\u2286xofsizem\u2264n.Then,foragivenamechanismM:2Um\u2192P(Z)withprivacypro\ufb01le\u03b4Mwithrespecttothesubstitutionrelation\u2019sonsetsofsizem,weareinterestedinboundingtheprivacypro\ufb01leofthemechanismMSwomwithrespecttothesubstitutionrelationonsetsofsizen.6Inthecaseofmultisetsrecordsarecountedwithmultiplicity.7\fTheorem9.LetM0=MSwom.Forany\u03b5\u22650wehave\u03b4M0(\u03b50)\u2264(m/n)\u03b4M(\u03b5),where\u03b50=log(1+(m/n)(e\u03b5\u22121)).Thissettinghasbeenusedin[Beimeletal.,2013,Bassilyetal.,2014,Wangetal.,2016]withnon-tightbounds.Aproofofthistightboundformulatedintermsof(\u03b5,\u03b4)-DPcanbedirectlyrecoveredfromUllman\u2019sclassnotes[Ullman,2017],althoughthestatedboundisweaker.R\u00e9nyiDPampli\ufb01cationboundsforsubsamplingwithoutreplacementweredevelopedin[Wangetal.,2019].SamplingWithReplacementNextweconsiderthecaseofsamplingwithreplacementwithrespecttothesubstitutionrelation\u2019s.ThesubsamplingwithreplacementmechanismSwrm:2Un\u2192P(NUm)takesasetxofsizenandoutputsasamplefromthemultinomialdistribution\u03c9=Swrm(x)overallmultisetsyofsizem\u2264nwithsupp(y)\u2286x,givenby\u03c9(y)=(m!/nm)Qu\u2208Uxu/(yu!).InthiscasewesupposethebasemechanismM:NUm\u2192P(Z)isde\ufb01nedonmultisetsandhasprivacypro\ufb01le\u03b4Mwithrespectto\u2019s.Weareinterestedinboundingtheprivacypro\ufb01leofthesubsampledmechanismMSwrm:2Un\u2192P(Z)withrespectto\u2019s.Theorem10.LetM0=MSwrm.Given\u03b5\u22650and\u03b50=log(1+(1\u2212(1\u22121/n)m)(e\u03b5\u22121))wehave\u03b4M0(\u03b50)\u2264mXk=1(cid:18)mk(cid:19)(cid:18)1n(cid:19)k(cid:18)1\u22121n(cid:19)m\u2212k\u03b4M,k(\u03b5).Notethatifm=\u03b3n,then1\u2212(1\u22121/n)m\u2248\u03b3.Aversionofthisboundintermsof(\u03b5,\u03b4)-DPthatimplicitlyusesthegroupprivacypropertycanbefoundin[Bunetal.,2015].Ourboundmatchestheasymptoticsof[Bunetal.,2015]whileprovidingoptimalconstantsandallowingforwhite-boxgroupprivacybounds.HybridNeighbouringRelationsUsingourmethoditisalsopossibletoanalyzenewsettingswhichhavenotbeenconsideredbefore.Oneinterestingexampleoccurswhenthereisamismatchbetweenthetwoneighbouringrelationsarisingintheanalysis.Forexample,supposeoneknowsthegroup-privacypro\ufb01les\u03b4M,kofabasemechanismM:NUm\u2192P(Z)withrespecttothesubstitutionrelation\u2019s.Inthiscaseonecouldaskwhetheritmakessensetostudytheprivacypro\ufb01leofthesubsampledmechanismMSwrm:2U\u2192P(Z)withrespecttotheremove/addrelation\u2019r.Inprinciple,thismakessenseinsettingswherethesizeoftheinputstoMisrestrictedduetoimplementationconstraints(eg.limitedbythememoryavailableinaGPUusedtorunaprivatemechanismthatcomputesagradientonamini-batchofsizem).Inthiscaseonemightstillbeinterestedinanalyzingtheprivacylossincurredfromreleasingsuchstochasticgradientsundertheremove/addrelation.Notethatthissettingcannotbeimplementedusingsamplingwithoutreplacementsinceundertheremove/addrelationwecannotaprioriguaranteethattheinputdatasetwillhaveatleastsizembecausethesizeofthedatasetmustbekeptprivate[Vadhan,2017].Furthermore,onecannothopetogetameaningfulresultabouttheprivacypro\ufb01leofthesubsampledmechanismacrossallinputssetsin2U;insteadtheprivacyguaranteewilldependonthesizeoftheinputdatasetasshowninthefollowingresult.Theorem11.LetM0=MSwrm.Forany\u03b5\u22650andn\u22650wehavesupx\u22082Un,x\u2019rx0De\u03b50(M0(x)kM0(x0))\u2264mXk=1(cid:18)mk(cid:19)(cid:18)1n(cid:19)k(cid:18)1\u22121n(cid:19)m\u2212k\u03b4M,k(\u03b5),where\u03b50=log(1+(1\u2212(1\u22121/n)m)(e\u03b5\u22121)).WhentheNeighbouringRelationis\u201cIncompatible\u201dNowweconsiderasimpleexamplewheredistance-compatiblecouplingsarenotavailable:Poissonsubsamplingwithrespecttothesubstitutionrelation.Supposex,x0\u22082Unaresetsofsizenrelatedbythesubstitutionrelation\u2019s.Let\u03c9=Spo\u03b7(x)and\u03c90=Spo\u03b7(x0)andnotethatTV(\u03c9,\u03c90)=\u03b7.Letx0=x\u2229x0andv=x\\x0,v0=x0\\x0.Inthiscasethefactorizationinducedbythemaximalcouplingisobtainedbytaking\u03c90=Spo\u03b7(x0),\u03c91(y\u222a{v})=\u03c90(y),and\u03c901(y\u222a{v0})=\u03c90(y).Nowthesupportof\u03c90containssetsofsizesbetween0andn\u22121,whilethesupportsof\u03c91and\u03c91containsetsofsizesbetween1andn.Fromthisobservationonecandeducethat\u03c91and\u03c90arenotd\u2019s-compatible,and\u03c91and\u03c901arenotd\u2019r-compatible.8\fThisargumentshowsthatthemethodweusedtoanalyzetheprevioussettingscannotbeextendedtoanalyzePoissonsubsamplingunderthesubstitutionrelation,regardlessofwhethertheprivacypro\ufb01leofthebasemechanismisgivenintermsofthereplacement/additionorthesubstitutionrelation.Thisobservationissayingthatsomepairingsbetweensubsamplingmethodandneighbouringrelationaremorenaturalthanothers.Nonetheless,evenwithoutdistance-compatiblecouplingsitispossibletoprovideprivacyampli\ufb01cationboundsforPoissonsubsamplingwithrespecttothesubstitutionrelation,althoughtheresultingboundisquitecumbersome.Thecorrespondingstatementandanalysiscanbefoundinthesupplementarymaterial.5LowerBoundsInthissectionweshowthatmanyoftheresultsgivenintheprevioussectionaretightbyconstructingarandomizedmembershipmechanismthatattainstheseupperbounds.Forthesakeofgenerality,westatethemainconstructionintermsoftuplesinsteadofmultisets.Infact,weproveagenerallemmathatcanbeusedtoobtaintightnessresultsforanysubsamplingmechanismandanyneighbouringrelationsatisfyingtwonaturalassumptions.Forp\u2208[0,1]letRp:{0,1}\u2192P({0,1})betherandomizedresponsemechanismthatgivenb\u2208{0,1}returnsbwithprobabilitypand1\u2212bwithprobability1\u2212p.Notethatforp=(e\u03b5+\u03b4)/(e\u03b5+1)thismechanismis(\u03b5,\u03b4)-DP.Let\u03bd0=Rp(0)and\u03bd1=Rp(1).Forany\u03b5\u22650andp\u2208[0,1]de\ufb01ne\u03c8p(\u03b5)=[p\u2212e\u03b5(1\u2212p)]+.ItiseasytoverifythatDe\u03b5(\u03bd0k\u03bd1)=De\u03b5(\u03bd1k\u03bd0)=\u03c8p(\u03b5).NowletUbeauniversecontainingatleasttwoelements.Forv\u2208Uandp\u2208[0,1]wede\ufb01netherandomizedmembershipmechanismMv,pthatgivenatuplex=(u1,...,un)\u2208U?returnsMv,p(x)=Rp(I[v\u2208x]).WesaythatasubsamplingmechanismS:X\u2192P(U?)de\ufb01nedonsomesetX\u2286U?isnaturalifthefollowingtwoconditionsaresatis\ufb01ed:(1)foranyx\u2208Xandu\u2208U,ifu\u2208xthenthereexistsy\u2208supp(S(x))suchthatu\u2208y;(2)foranyx\u2208Xandu\u2208U,ifu/\u2208xthenwehaveu/\u2208yforeveryy\u2208supp(S(x)).Lemma12.LetX\u2286U?beequippedwithaneighbouringrelation\u2019Xsuchthatthereexistx\u2019Xx0withv\u2208xandv/\u2208x0.SupposeS:X\u2192P(U?)isanaturalsubsamplingmechanismandlet\u03b7=supx\u2019Xx0TV(S(x),S(x0)).Forany\u03b5\u22650and\u03b50=log(1+\u03b7(e\u03b5\u22121))wehave\u03b4MSv,p(\u03b50)=supx\u2019Xx0De\u03b50(MSv,p(x)kMSv,p(x0))=\u03b7\u03c8p(\u03b5).Wecannowapplythislemmatoshowthatthe\ufb01rstthreeresultsfromprevioussectionaretight.Thisrequiresspecializingfromtuplesto(multi)sets,andplugginginthede\ufb01nitionsofneighbouringrelation,subsamplingmechanism,and\u03b7usedineachofthesetheorems.Theorem13.ThemechanismMv,pattainstheboundsinTheorems8,9,10foranypand\u03b7.6ConclusionsWehavedevelopedageneralmethodforreasoningaboutprivacyampli\ufb01cationbysubsampling.Ourmethodisapplicabletomanydifferentsettings,somewhichhavealreadybeenstudiedintheliterature,andotherswhicharenew.Technically,ourmethodleveragestwonewtoolsofindependentinterest:advancedjointconvexityandprivacypro\ufb01les.Inthefuture,itwouldbeinterestingtostudywhetherourtoolscanbeextendedtogiveconcreteboundsonprivacyampli\ufb01cationforotherprivacynotionssuchasconcentratedDP[DworkandRothblum,2016],zero-concentratedDP[BunandSteinke,2016],R\u00e9nyiDP[Mironov,2017],andtruncatedconcentratedDP[Bunetal.,2018].AgoodstartingpointisTheorem6establishingrelationsbetweenprivacypro\ufb01lesandmomentgeneratingfunctionsoftheprivacylossrandomvariable.AnalternativeapproachistoextendtherecentresultsforR\u00e9nyiDPampli\ufb01cationbysubsamplingwithoutreplacementgivenin[Wangetal.,2019]tomoregeneralnotionsofsubsamplingandneighbouringrelations.AcknowledgmentsThisresearchwasinitiatedduringthe2017ProbabilisticProgrammingLanguagesworkshophostedbyMcGillUniversity\u2019sBellairsResearchInstitute.9\fReferencesMart\u00ednAbadi,AndyChu,IanGoodfellow,HBrendanMcMahan,IlyaMironov,KunalTalwar,andLiZhang.Deeplearningwithdifferentialprivacy.InProceedingsofthe2016ACMSIGSACConferenceonComputerandCommunicationsSecurity,pages308\u2013318.ACM,2016.BorjaBalleandYu-XiangWang.Improvingthegaussianmechanismfordifferentialprivacy:Analyticalcalibrationandoptimaldenoising.InProceedingsofthe35thInternationalConferenceonMachineLearning,ICML,2018.GillesBartheandFedericoOlmedo.Beyonddifferentialprivacy:Compositiontheoremsandrelationallogicforf-divergencesbetweenprobabilisticprograms.InInternationalColloquiumonAutomata,Languages,andProgramming,pages49\u201360.Springer,2013.GillesBarthe,BorisK\u00f6pf,FedericoOlmedo,andSantiagoZanellaB\u00e9guelin.Probabilisticrelationalreasoningfordifferentialprivacy.InSymposiumonPrinciplesofProgrammingLanguages(POPL),pages97\u2013110,2012.GillesBarthe,MarcoGaboardi,BenjaminGr\u00e9goire,JustinHsu,andPierre-YvesStrub.Provingdifferentialprivacyviaprobabilisticcouplings.InSymposiumonLogicinComputerScience(LICS),pages749\u2013758,2016.RaefBassily,AdamSmith,andAbhradeepThakurta.Privateempiricalriskminimization:Ef\ufb01cientalgorithmsandtighterrorbounds.InFoundationsofComputerScience(FOCS),2014IEEE55thAnnualSymposiumon,pages464\u2013473.IEEE,2014.AmosBeimel,ShivaPrasadKasiviswanathan,andKobbiNissim.Boundsonthesamplecomplexityforprivatelearningandprivatedatarelease.InTheoryofCryptographyConference,pages437\u2013454.Springer,2010.AmosBeimel,KobbiNissim,andUriStemmer.Characterizingthesamplecomplexityofprivatelearners.InProceedingsofthe4thconferenceonInnovationsinTheoreticalComputerScience,pages97\u2013110.ACM,2013.AmosBeimel,HaiBrenner,ShivaPrasadKasiviswanathan,andKobbiNissim.Boundsonthesamplecomplexityforprivatelearningandprivatedatarelease.Machinelearning,94(3):401\u2013437,2014.MarkBunandThomasSteinke.Concentrateddifferentialprivacy:Simpli\ufb01cations,extensions,andlowerbounds.InTheoryofCryptography-14thInternationalConference,TCC2016-B,Beijing,China,October31-November3,2016,Proceedings,PartI,pages635\u2013658,2016.MarkBun,KobbiNissim,UriStemmer,andSalilVadhan.Differentiallyprivatereleaseandlearningofthresholdfunctions.InFoundationsofComputerScience(FOCS),2015IEEE56thAnnualSymposiumon,pages634\u2013649.IEEE,2015.MarkBun,CynthiaDwork,GuyRothblum,andThomasSteinke.Composableandversatileprivacyviatruncatedcdp.InSymposiumonTheoryofComputing,STOC,2018.KamalikaChaudhuriandNinaMishra.Whenrandomsamplingpreservesprivacy.InAnnualInternationalCryptologyConference,pages198\u2013213.Springer,2006.CynthiaDworkandAaronRoth.Thealgorithmicfoundationsofdifferentialprivacy.FoundationsandTrendsinTheoreticalComputerScience,9(3-4):211\u2013407,2014.CynthiaDworkandGuyNRothblum.Concentrateddifferentialprivacy.arXivpreprintarXiv:1603.01887,2016.CynthiaDwork,GuyNRothblum,andSalilVadhan.Boostinganddifferentialprivacy.InFoundationsofComputerScience(FOCS),201051stAnnualIEEESymposiumon,pages51\u201360.IEEE,2010.JoonasJ\u00e4lk\u00f6,AnttiHonkela,andOnurDikmen.Differentiallyprivatevariationalinferencefornon-conjugatemodels.InProceedingsoftheThirty-ThirdConferenceonUncertaintyinArti\ufb01cialIntelligence,UAI2017,Sydney,Australia,August11-15,2017,2017.10\fPeterKairouz,SewoongOh,andPramodViswanath.Thecompositiontheoremfordifferentialprivacy.IEEETransactionsonInformationTheory,63(6):4037\u20134049,2017.ShivaPrasadKasiviswanathan,HominKLee,KobbiNissim,SofyaRaskhodnikova,andAdamSmith.Whatcanwelearnprivately?SIAMJournalonComputing,40(3):793\u2013826,2011.NinghuiLi,WahbehQardaji,andDongSu.Onsampling,anonymization,anddifferentialprivacyor,k-anonymizationmeetsdifferentialprivacy.InProceedingsofthe7thACMSymposiumonInformation,ComputerandCommunicationsSecurity,pages32\u201333.ACM,2012.IlyaMironov.R\u00e9nyidifferentialprivacy.In30thIEEEComputerSecurityFoundationsSymposium,CSF2017,SantaBarbara,CA,USA,August21-25,2017,pages263\u2013275,2017.JackMurtaghandSalilVadhan.Thecomplexityofcomputingtheoptimalcompositionofdifferentialprivacy.InTheoryofCryptographyConference,pages157\u2013175.Springer,2016.Ferdinand\u00d6sterreicher.Csisz\u00e1r\u2019sf-divergences-basicproperties.RGMIARes.Rep.Coll,2002.MijungPark,JamesR.Foulds,KamalikaChaudhuri,andMaxWelling.Privatetopicmodeling.CoRR,abs/1609.04120,2016a.MijungPark,JamesR.Foulds,KamalikaChaudhuri,andMaxWelling.Variationalbayesinprivatesettings(VIPS).CoRR,abs/1611.00340,2016b.IgalSasonandSergioVerd\u00fa.f-divergenceinequalities.IEEETransactionsonInformationTheory,62(11):5973\u20136006,2016.JonathanUllman.Cs7880:Rigorousapproachestodataprivacy.http://www.ccs.neu.edu/home/jullman/PrivacyS17/HW1sol.pdf,2017.SalilP.Vadhan.Thecomplexityofdifferentialprivacy.InTutorialsontheFoundationsofCryptogra-phy.,pages347\u2013450.2017.Yu-XiangWang,StephenFienberg,andAlexSmola.Privacyforfree:Posteriorsamplingandstochasticgradientmontecarlo.InProceedingsofthe32ndInternationalConferenceonMachineLearning(ICML),pages2493\u20132502,2015.Yu-XiangWang,JingLei,andStephenE.Fienberg.Learningwithdifferentialprivacy:Stability,learnabilityandthesuf\ufb01ciencyandnecessityofermprinciple.JournalofMachineLearningResearch,17(183):1\u201340,2016.Yu-XiangWang,BorjaBalle,andShivaKasiviswanathan.Subsampledr\u00e9nyidifferentialprivacyandanalyticalmomentsaccountant.InProceedingsofthe22ndInternationalConferenceonArti\ufb01cialIntelligenceandStatistics(AISTATS),2019.11\f", "award": [], "sourceid": 3097, "authors": [{"given_name": "Borja", "family_name": "Balle", "institution": "Amazon Research Cambridge"}, {"given_name": "Gilles", "family_name": "Barthe", "institution": "IMDEA Software Institute"}, {"given_name": "Marco", "family_name": "Gaboardi", "institution": "Univeristy at Buffalo"}]}