---
title: Differentially Private E-values
url: https://www.emergentmind.com/topics/differentially-private-e-values
type: topic
---

# Differentially Private E-values

Searching arXiv for the specified papers to ground the article in current sources.
Differentially private e-values are nonnegative evidence measures whose release mechanism satisfies a differential privacy constraint while preserving the e-value validity condition \(\mathbb{E}_{H_0}[E]\le 1\). In the recent literature, the topic has developed along three closely connected lines: a general method for converting arbitrary non-private e-values into private ones by biased multiplicative noise [2510.18654]; an optimal theory of private e-power for simple hypothesis testing under pure central \(\varepsilon\)-differential privacy [2605.28952]; and a Gaussian differential privacy framework with canonical multiplicative Gaussian perturbation, sharp threshold calibration, and multiple-testing procedures [2605.29388]. Closely related work on privacy auditing and operational interpretations of \(\epsilon\) is conceptually adjacent, but it does not define formal e-values [2307.11280, 1911.12777].

## 1. Conceptual scope and formal definitions

An e-value is a nonnegative random variable \(E\) satisfying \(\mathbb{E}_{H_0}[E]\le 1\). In the simple-testing formulation, the literature distinguishes between an **e-variable**, meaning the random variable itself, and an **e-value**, meaning a realized value; thresholding at \(1/\alpha\) yields a level-\(\alpha\) test by Markov’s inequality. A differentially private e-value adds a second requirement: the mechanism that outputs the e-value must satisfy a privacy guarantee with respect to neighboring datasets differing in one record. In the pure-DP testing framework, a random variable \(E=M(X)\) is an \(\varepsilon\)-DP e-variable for \(P\) if \(M\) is \(\varepsilon\)-DP and \(\mathbb{E}^{P^n}[M(X)]\le 1\); in the Gaussian-DP framework, the released quantity \(E^{\mathrm{DP}}(\mathcal D)\) must simultaneously satisfy \(\mathbb{E}_{H_0}[E^{\mathrm{DP}}(\mathcal D)]\le 1\) and \(\mu\)-GDP; and in the general RDP framework, the starting point is any valid non-private e-value \(E(D)\), which is then transformed into a private one [2510.18654, 2605.28952, 2605.29388].

| Framework | Privacy regime | Central object |
|---|---|---|
| [2510.18654] | Rényi DP, with appendix results for \((\epsilon,\delta)\)-DP and pure DP | General transformation \(E(D)\mapsto E^*(D)\) |
| [2605.28952] | Pure central \(\varepsilon\)-DP | Optimal e-power for testing \(P^n\) vs. \(Q^n\) |
| [2605.29388] | \(f\)-DP specialized to \(\mu\)-GDP | Canonical multiplicative Gaussian privatization |

This division of labor matters. The RDP paper is distribution-agnostic and mechanism-oriented; the pure-DP paper is decision-theoretic and asks what e-power is achievable under privacy; the GDP paper treats tradeoff-function privacy as the native language and uses it to derive exact threshold calibration and multiple-testing machinery. A plausible synthesis is that “differentially private e-values” is best understood as a family of constructions rather than a single canonical object.

## 2. General privatization by biased multiplicative noise

The general construction starts from a valid non-private e-value \(E(D)\) and releases
\[
E^*(D)=E(D)e^{-\xi},
\]
where \(\xi\) is independent noise. This multiplicative form preserves nonnegativity and is equivalent to adding noise to the log e-value:
\[
\log E^*(D)=\log E(D)-\xi.
\]
Privacy is therefore calibrated through the log-sensitivity
\[
\Delta_{\log}(E)=\sup_{|D\Delta D'|\le 1}\left|\log E(D)-\log E(D')\right|.
\]
Validity is preserved because
\[
\mathbb{E}[E^*(D)]=\mathbb{E}[E(D)]\,\mathbb{E}[e^{-\xi}],
\]
so under the null it is enough that \(\mathbb{E}[e^{-\xi}]\le 1\). The paper proves that if \(\mathbb{E}[E(D)]=1\) and \(E(D)\) is not already differentially private, then a mechanism of this form must satisfy \(\mathbb{E}[\xi]>0\); the bias is therefore necessary rather than cosmetic [2510.18654].

Two concrete RDP mechanisms are developed. The biased Gaussian mechanism takes
\[
\xi \sim \mathcal{N}\!\left(\frac{\alpha[\Delta_{\log}(E)]^2}{4\epsilon},\frac{\alpha[\Delta_{\log}(E)]^2}{2\epsilon}\right),
\]
which yields a valid e-value satisfying \((\alpha,\epsilon)\)-Rényi differential privacy. The biased Laplace mechanism takes
\[
\xi \sim \mathrm{Laplace}\!\bigl(-\log(1-b_{\alpha,\epsilon}^2),\, b_{\alpha,\epsilon}\bigr),
\]
with
\[
b_{\alpha,\epsilon}= \frac{1}{\mathbf h_\alpha^{-1}\!\left((2\alpha-1)e^{(\alpha-1)\epsilon}\right)},
\qquad
\mathbf h_\alpha(t)=\alpha e^{(\alpha-1)\Delta_{\log}(E)t}+(\alpha-1)e^{-\alpha\Delta_{\log}(E)t},
\]
and is valid provided \(b_{\alpha,\epsilon}<1\). Appendix results also give a Gaussian mechanism for \((\epsilon,\delta)\)-DP and a Laplace mechanism for pure \((\epsilon,0)\)-DP [2510.18654].

This framework preserves several core e-value operations. If \(E_1^*(D_1)\) and \(E_2^*(D_2)\) are private e-values on independent datasets, then \(E_1^*(D_1)E_2^*(D_2)\) is again a private e-value; \(1/E^*(D)\) is a post-hoc-valid p-value by post-processing; and convex combinations preserve validity, with a stronger privacy statement for independent datasets than for dependent e-values on the same dataset. The exact growth-rate identity
\[
\mathbb{E}\!\left[\frac1n\log E^*(D)\right]
=
\mathbb{E}\!\left[\frac1n\log E(D)\right]-\frac{\mathbb{E}[\xi]}{n}
\]
shows that the privacy penalty is additive on the normalized log scale. When \(\Delta_{\log}(E)=O(1)\), the Gaussian penalty is \(O(1/n)\), which explains the paper’s asymptotic claim that private e-values are as powerful as their non-private counterparts [2510.18654].

## 3. Optimal private e-power under pure central differential privacy

For simple hypothesis testing
\[
H_0:X\sim P^n
\qquad\text{vs.}\qquad
H_1:X\sim Q^n,
\]
the pure-DP line of work formulates private e-values as an optimization problem. The performance criterion is **e-power**
\[
\mathbb{E}^{Q^n}[\log E],
\]
and the optimal normalized finite-\(n\) rate is
\[
\mathfrak R_{n,\varepsilon}(Q\|P)
=
\sup_{\substack{E\text{ is an }\varepsilon\text{-DP}\\ \text{e-variable for }P}}
\frac{\mathbb E^{Q^n}[\log E]}{n}.
\]
Its asymptotic limit admits an exact variational characterization:
\[
\mathfrak R_\varepsilon(Q\|P)
=
\inf_{Q'}\Big\{\KL(Q'\|P)+\varepsilon\,\TV(Q',Q)\Big\}.
\]
This replaces the non-private rate \(\KL(Q\|P)\) by a privacy-constrained KL+TV expression and makes the privacy loss explicit as a geometric deformation of the classical likelihood-ratio solution [2605.28952].

The optimizer is a clipped likelihood ratio. Writing \(q/p\) for the density ratio, the optimal bounded non-private e-variable has the form
\[
E^*(x)=\min\big(c_2,\max(c_1,q(x)/p(x))\big),
\]
where the clipping interval is calibrated so that \(c_2/c_1=e^\varepsilon\) and the clipped ratio integrates to \(1\) under \(P\). This construction is equivalent to introducing an intermediate distribution \(\widetilde Q\) whose density equals \(q\) on a middle region and equals \(c_1p\) or \(c_2p\) on lower and upper clipping regions. The resulting e-power is exactly
\[
\mathbb E^Q[\log E^*]
=
\KL(\widetilde Q\|P)+\varepsilon\,\TV(\widetilde Q,Q).
\]
Privacy therefore enforces a bounded dynamic range on evidence contributions; the raw likelihood ratio is generally infeasible because its log-sensitivity can be unbounded [2605.28952].

A direct Laplace release of \(\sum_{i=1}^n\log E^*(X_i)\) fails because exponentiation introduces positive bias. The paper instead uses the merged statistic
\[
\Lambda_n(E;\lambda)=\sum_{t=1}^n \log(1-\lambda+\lambda E(X_t)),
\]
privatizes it as
\[
\widetilde\Lambda_n(E;\lambda)
=
\Lambda_n(E;\lambda)+Z_b-\log\mathbb E[e^{Z_b}],
\qquad
Z_b\sim \mathrm{Lap}(b),
\]
and releases
\[
\widetilde E_n=\exp(\widetilde\Lambda_n(E;\lambda)).
\]
For suitable computable \(\lambda\in(0,1)\) and \(b<1\), this yields an \(\varepsilon\)-DP e-variable whose expected log-evidence satisfies
\[
\mathbb E^Q[\widetilde\Lambda_n(E;\lambda)] \ge n\mu-\log(n\mu)-O(1),
\]
where \(\mu=\mathbb E^Q[\log E]\). Applied to the clipped likelihood-ratio statistic, this matches the optimal asymptotic rate up to a lower-order \(O(\log n)\) term [2605.28952].

## 4. Gaussian differential privacy, canonical noise, and sharp calibration

The GDP framework starts from the tradeoff-function formulation of privacy. For neighboring datasets \(\mathcal D,\mathcal D'\), a mechanism is \(f\)-DP if its hypothesis-testing tradeoff function dominates \(f\), and \(\mu\)-GDP is the specialization \(f=G_\mu\), where
\[
G_\mu(\alpha)=\Phi\!\big(\Phi^{-1}(1-\alpha)-\mu\big).
\]
Within this framework, the relevant sensitivity is again log-sensitivity,
\[
\Delta=\sup_{\mathcal D\sim \mathcal D'}\left|\log E(\mathcal D)-\log E(\mathcal D')\right|,
\]
and privatization is multiplicative:
\[
E^{\mathrm{DP}}(\mathcal D)=E(\mathcal D)e^{-\xi}.
\]
Under the assumptions that the noise is independent, symmetric around its expectation, log-concave, multiplicative, and exactly exhausts the GDP budget, the paper proves that \(\xi\) must be Gaussian:
\[
\xi\sim \mathcal N\!\left(\tau,\frac{\Delta^2}{\mu^2}\right).
\]
Validity requires
\[
\mathbb E[e^{-\xi}]
=
\exp\!\left(-\tau+\frac{\Delta^2}{2\mu^2}\right)\le 1,
\]
so the smallest feasible and power-optimal mean is
\[
\tau^*=\frac{\Delta^2}{2\mu^2}.
\]
The canonical private e-value is therefore
\[
E^{\mathrm{DP}}(\mathcal D)
=
E(\mathcal D)e^{-\xi},
\qquad
\xi\sim \mathcal N\!\left(\frac{\Delta^2}{2\mu^2},\frac{\Delta^2}{\mu^2}\right),
\]
which is simultaneously \(\mu\)-GDP and exactly e-valid [2605.29388].

A central advance of this framework is threshold calibration. The universal Markov rule rejects when \(E^{\mathrm{DP}}\ge 1/\alpha\), but this ignores the known Gaussian privatization law. The paper derives a **globally sharp** threshold \(c^*\) such that
\[
\Pr_{H_0}(E^{\mathrm{DP}}\ge c^*)\le \alpha
\]
for every valid e-value, with equality in the worst case:
\[
c^* =
\begin{cases}
\displaystyle \frac{1}{\alpha}\Phi(z^*) \exp\left(-\frac{\Delta^2}{2\mu^2}-\frac{\Delta}{\mu}z^*\right), & \text{if } \alpha \le \Phi(z^*),\\[1em]
\displaystyle \exp\left(-\frac{\Delta^2}{2\mu^2}-\frac{\Delta}{\mu}\Phi^{-1}(\alpha)\right), & \text{if } \alpha > \Phi(z^*),
\end{cases}
\]
where \(z^*\) solves
\[
\frac{\phi(z^*)}{\Phi(z^*)}=\frac{\Delta}{\mu}.
\]
Because \(c^*<1/\alpha\), the calibrated rejection region is strictly larger than the standard private Markov region [2605.29388].

The low-sensitivity asymptotics are unusually sharp. If \(f_E\) denotes the density of the non-private e-value under \(H_1\), then
\[
\Pr_{H_1}\!\left(c^*\le Ee^{-\xi}<\frac1\alpha\right)
\sim
\frac{f_E(1/\alpha)}{\alpha\mu}\Delta\sqrt{-2\log\Delta},
\]
whereas the corresponding noise-induced cost satisfies
\[
\Pr_{H_1}\!\left(E\ge \frac1\alpha,\ Ee^{-\xi}<c^*\right)
\sim
\frac{f_E(1/\alpha)}{2e\alpha\mu^2}\cdot \frac{\Delta^2}{-\log\Delta}.
\]
Since \(\Delta\sqrt{-\log\Delta}\gg \Delta^2/(-\log\Delta)\) as \(\Delta\to0\), the calibrated private test can exceed the non-private baseline \(E\ge 1/\alpha\) in a low-sensitivity regime. The paper explicitly treats this as a threshold-calibration phenomenon, not as a universal claim that privacy helps testing [2605.29388].

## 5. Sequential inference, multiple testing, and applications

The sequential theory under pure \(\varepsilon\)-DP centers on **e-processes**. A sequence \((E_t)\) is an \(\varepsilon\)-DP e-process if it is generated by an \(\varepsilon\)-DP mechanism on the infinite data stream and remains an e-process after privatization. The main lower bound states that for any bounded stopping time \(N\),
\[
\mathbb E^Q[\log E_N]\le \mathbb E^Q[N]\;\mathfrak R_\varepsilon(Q\|P),
\]
and hence any sequential level-\(\alpha\) test with power \(1-\beta\) must satisfy
\[
\mathbb E^Q[N]
\ge
\frac{(1-\beta)\log\frac{1-\beta}{\alpha}+\beta\log\frac{\beta}{1-\alpha}}
{\mathfrak R_\varepsilon(Q\|P)}.
\]
The constructive side uses a batch schedule \(t_1,t_2,\ldots\) and privatized multiplicative updates, yielding an \(\varepsilon\)-DP e-process that matches the universal lower bound up to an arbitrarily small multiplicative factor after a startup phase. In Bernoulli experiments, this private e-process required fewer samples than DP-SPRT across the tested privacy levels and alternatives [2605.28952].

The GDP multiple-testing framework uses a two-part extractor. Selection is performed by a Report Noisy Max step on
\[
L_i=\log E_i+g_i,
\qquad
g_i\overset{\mathrm{i.i.d.}}{\sim}\mathrm{Gumbel}(0,2\Delta/\epsilon),
\]
with
\[
\epsilon=\log\!\left(\frac{\Phi(\mu/(2\sqrt2))}{\Phi(-\mu/(2\sqrt2))}\right),
\]
followed by Gaussian multiplicative release of the selected value,
\[
\tilde E_{j^*}=E_{j^*}e^{-\xi},
\qquad
\xi\sim \mathcal N\!\left(\frac{\Delta^2}{\mu^2},\frac{2\Delta^2}{\mu^2}\right).
\]
Iterating this step produces the recursive GDP \(e\)-Peeling Algorithm, which concentrates privacy budget on the top \(s\) hypotheses. By GDP composition, allocating \(\mu/\sqrt s\) per peeling step yields overall \(\mu\)-GDP. Each output coordinate is either zero or a valid private e-value, so applying e-BH to the output vector controls FDR at level \(\alpha\). The paper also gives an adaptive private choice of \(s\) using privatized margins \(Q_k=L_{(k)}-\log\{m/(\alpha k)\}\) on a geometric grid [2605.29388].

Applications in the general RDP framework illustrate how these constructions interact with domain-specific e-values. For private healthcare inference, the method is applied to mean-betting e-values of the form
\[
E_\theta(D)=\prod_{i=1}^n (1+\lambda_i(Y_i-\theta)),
\]
producing private confidence intervals after discretizing \([0,1]\) and lower-bounding each cellwise e-value by a local Lipschitz correction. For online risk monitoring, batchwise privatized e-values are multiplied across time, preserving anytime-validity under the private optional continuation property. For conformal e-prediction, the exchangeability e-value
\[
E^{\mathrm{exch}}(D;S^{\mathrm{test}})
=
\frac{(n+1)S^{\mathrm{test}}}{\sum_{i=1}^n s(X_i,Y_i)+S^{\mathrm{test}}}
\]
has sensitivity bound
\[
\Delta_{\log}(E^{\mathrm{exch}})\le 2\cdot \frac{b/a}{n+1},
\]
which decays as \(1/n\) and makes privacy comparatively inexpensive asymptotically. In these experiments, biased Gaussian perturbation was broadly applicable, while biased Laplace perturbation sometimes performed better but was often unavailable when its feasibility condition failed [2510.18654].

## 6. Neighboring concepts, misconceptions, and open problems

A recurrent misconception is to conflate any privacy-related scalar beginning with “\(E\)” or “epsilon-like” with a formal e-value. The metric \(\epsilon^*\) from privacy auditing is not an e-value in the statistical sense. It is defined from ROC operating points of a threshold membership inference attack against a fixed trained model instance and takes the form
\[
\epsilon^*
=
\log \Big[\max_i \max\Big(
\frac{1-\delta-\eta_i}{t_i},
\frac{1-\delta-t_i}{\eta_i},
\frac{\eta_i-\delta}{1-t_i},
\frac{t_i-\delta}{1-\eta_i},
1\Big)\Big].
\]
The paper explicitly states that \(\epsilon^*\) is an attack-derived, DP-inspired lower bound on empirical privacy loss, not an e-value: it has no null expectation guarantee of the form \(\mathbb E_{H_0}[E]\le 1\), no martingale or test-supermartingale structure, no sequential validity, and no multiplicative betting interpretation [2307.11280].

A second neighboring line interprets the differential privacy parameter \(\epsilon\) in terms of inferential gain rather than e-values. In the metric-DP framework for guessing sensitive attributes, privacy is translated into a cap on additive posterior improvement,
\[
\Pr(\text{correct after output})-\Pr(\text{correct before output})\le \delta,
\]
using Bayes’ rule and the DP likelihood-ratio bound
\[
\frac{f_Y(y\mid x')}{f_Y(y\mid x)}\le e^{\epsilon d(x,x')}.
\]
This is operationally close to evidence control, but it is not an e-value theory and does not produce safe tests, e-processes, or multiplicative evidence measures [1911.12777].

The present theory also has explicit limitations. The pure-DP optimal-rate results are for simple-vs-simple testing under pure central \(\varepsilon\)-DP; approximate \((\varepsilon,\delta)\)-DP is left open, and exact implementation of the clipped-likelihood-ratio optimizer may be computationally difficult in high dimension. The sequential lower bound is stated for bounded stopping times, and the nearly optimal e-process has startup latency because frequent early releases are noise-dominated [2605.28952]. The GDP optimality theorem assumes symmetry, log-concavity, and exact budget exhaustion, and the optimality question under the weaker condition \(T\ge G_\mu\) is left open; the net power gain over the non-private baseline holds in a low-sensitivity regime and is not a universal dominance theorem [2605.29388]. The general RDP framework requires a usable bound on \(\Delta_{\log}(E)\), the biased Laplace mechanism is only available when \(b_{\alpha,\epsilon}<1\), and confidence-interval constructions over infinite parameter families require discretization and local Lipschitz control [2510.18654].

Taken together, these results establish a coherent modern picture. Differentially private e-values are not merely private releases of preexisting evidence statistics. They are mechanisms designed so that privacy acts on the log evidence while validity survives on the original scale, either through biased multiplicative perturbation, clipped-likelihood-ratio geometry, or Gaussian tradeoff calibration. The main technical themes—bounded log-sensitivity, multiplicative shrinkage, exact null-expectation control, and privacy-aware evidence accumulation—now form the core of the subject [2510.18654, 2605.28952, 2605.29388].

Source: https://www.emergentmind.com/topics/differentially-private-e-values