Papers
Topics
Authors
Recent
Search
2000 character limit reached

Single-Order RDP Privacy Regions

Updated 6 February 2026
  • The paper introduces single-order RDP privacy regions as optimal privacy-utility trade-offs characterized by bounding Rényi divergence at a fixed order.
  • It reveals that these regions are convex, symmetric, and extremally achieved by two-point mechanisms, simplifying privacy comparisons.
  • The work underpins efficient black-box conversions to f-DP and (ε,δ)-DP, impacting posterior sampling, subsampled Gaussian, and shuffle mechanism analyses.

A single-order RDP privacy region is the locus of optimal privacy-utility trade-offs determined by a mechanism’s Rényi Differential Privacy (RDP) guarantees at a fixed divergence order. It encodes the hypothesis-testing region—specifically, the attainable Type I and II error pairs—imposed by bounding RDP at a particular order and level. The theory of single-order RDP privacy regions provides both a geometric and an operational understanding of how moment-based privacy guarantees constrain statistical distinguishability, and establishes their role as the foundational building blocks in black-box conversions from RDP to more general hypothesis testing (e.g., ff-DP) or classical (ϵ,δ)(\epsilon,\delta)-DP frameworks.

1. Definition and Characterization of Single-Order RDP Privacy Regions

Let τ≥0.5\tau \geq 0.5 denote the Rényi order and ρ≥0\rho \geq 0 the upper bound on the Rényi divergence. For every pair of adjacent databases, a mechanism is said to satisfy (τ,ρ)(\tau, \rho)-RDP if

Dτ(P ∥ Q)≤ρandDτ(Q ∥ P)≤ρD_\tau(P\,\|\,Q) \leq \rho \quad \text{and} \quad D_\tau(Q\,\|\,P) \leq \rho

where PP and QQ are the output distributions under neighboring datasets. In the context of hypothesis testing, for every possible rejection region SS, one considers the induced Type I and II errors:

α=P(S),β=Q(Sc)\alpha = P(S), \qquad \beta = Q(S^c)

The (ϵ,δ)(\epsilon,\delta)0-order RDP privacy region (ϵ,δ)(\epsilon,\delta)1 is

(ϵ,δ)(\epsilon,\delta)2

The lower boundary of this region, parameterized by (ϵ,δ)(\epsilon,\delta)3, is the trade-off function (ϵ,δ)(\epsilon,\delta)4:

(ϵ,δ)(\epsilon,\delta)5

For (ϵ,δ)(\epsilon,\delta)6, explicit analytic constraints are given by:

(ϵ,δ)(\epsilon,\delta)7

with analogous forms for (ϵ,δ)(\epsilon,\delta)8 (KL-divergence) and (ϵ,δ)(\epsilon,\delta)9 (inequalities reverse).

2. Geometric and Structural Properties

The privacy region τ≥0.5\tau \geq 0.50 is always convex and symmetric about the line τ≥0.5\tau \geq 0.51. The map τ≥0.5\tau \geq 0.52 is affine, and the Rényi divergence sublevel sets are convex in distribution space. Symmetry arises because the constraints are invariant under swapping the roles of τ≥0.5\tau \geq 0.53 and τ≥0.5\tau \geq 0.54. The fundamental result is that every boundary point of τ≥0.5\tau \geq 0.55 is realized by a two-point (randomized response) mechanism, highlighting the sufficiency of binary mechanisms for extremal trade-offs and simplifying the analysis of attainable regions (Riess et al., 4 Feb 2026).

3. Role in Black-box Conversions and Optimality

The intersection of single-order RDP privacy regions across all τ≥0.5\tau \geq 0.56, given an RDP profile τ≥0.5\tau \geq 0.57, yields the tightest hypothesis-testing guarantee (in the τ≥0.5\tau \geq 0.58-DP sense) derivable solely from RDP accountants. More precisely, the attainable region is

τ≥0.5\tau \geq 0.59

and the corresponding lower boundary is:

ρ≥0\rho \geq 00

Any black-box method for converting RDP guarantees to ρ≥0\rho \geq 01-DP (or ρ≥0\rho \geq 02-DP) trade-offs cannot uniformly improve upon ρ≥0\rho \geq 03. This optimality is universal and holds in the Blackwell sense (Riess et al., 4 Feb 2026). The result marks the mathematical limit of RDP-to-ρ≥0\rho \geq 04-DP conversion without knowledge of the internal mechanism.

4. Computational Aspects and Applications

Single-order privacy regions reduce the process of privacy accounting to computing explicit trade-off curves ρ≥0\rho \geq 05, which are then combined pointwise over ρ≥0\rho \geq 06. This avoids complex variational calculus or loose union bounds. In practical privacy analysis workflows, the procedure is:

  1. Evaluate (numerically or analytically) ρ≥0\rho \geq 07 for a grid of ρ≥0\rho \geq 08 values.
  2. Take the pointwise maximum to obtain ρ≥0\rho \geq 09.
  3. For (τ,ρ)(\tau, \rho)0-DP conversion, many standard envelopes admit closed-form or efficient numerical evaluation (Mironov, 2017, Koskela et al., 2024).

This approach directly underpins privacy analysis in mechanisms such as:

5. Examples: Mechanisms and Single-Order Curves

In exponential-family posterior sampling, the achievable (τ,ρ)(\tau, \rho)1 points trace out a curve with vertical asymptotes determined by the prior; as the prior strengthens, the privacy region broadens and (τ,ρ)(\tau, \rho)2 decreases. In the sampled Gaussian mechanism, the region is approximately linear: (τ,ρ)(\tau, \rho)3 for small sampling rate (τ,ρ)(\tau, \rho)4 and large scale (τ,ρ)(\tau, \rho)5 (Mironov et al., 2019). For shuffle mechanisms, single-order regions show a strict gain over the standard central Gaussian mechanism, with the RDP curve lying well below the corresponding non-shuffled bound (Liew et al., 2022).

6. Theoretical and Practical Implications

The geometric structure of single-order RDP privacy regions explains why two-point mechanisms are extremal and why cumulant-based summaries (as in moments accountants) are sufficient for privacy composition (Riess et al., 4 Feb 2026). For practitioners, these regions provide both auditing tools (e.g., verifying claims of (τ,ρ)(\tau, \rho)6-DP or (τ,ρ)(\tau, \rho)7-DP) and a pathway to arbitrarily tight numerical evaluation across complex mechanism compositions (Koskela et al., 2024).

Furthermore, the explicit region characterizes the tradeoff between privacy cost and robustness with respect to higher-order moments, facilitating informed choices along the privacy-utility frontier for specific application requirements.

7. Extensions and Future Directions

Recent developments explore:

  • Generalization to hypothesis testing beyond binary decisions and to (τ,ρ)(\tau, \rho)8-DP with arbitrary trade-off functions.
  • Direct profile accounting in large-scale and adaptive mechanisms (e.g., private selection, hyperparameter tuning), where single-order profiles enable substantial improvement over traditional RDP accounting by avoiding conversion-induced slack (Koskela et al., 2024).
  • Adaptive privacy accounting for parallel or data-dependent mechanisms, leveraging the modularity of single-order regions.

A plausible implication is that future mechanism designs may further exploit the modularity and tightness of single-order privacy regions, particularly in interactive or federated settings where compositions and privacy amplification effects are subtle and intricate.


References

Topic to Video (Beta)

No one has generated a video about this topic yet.

Whiteboard

No one has generated a whiteboard explanation for this topic yet.

Follow Topic

Get notified by email when new papers are published related to Single-Order RDP Privacy Regions.