Papers
Topics
Authors
Recent
Search
2000 character limit reached

Sliced Rényi Pufferfish Privacy

Updated 7 December 2025
  • Sliced Rényi Pufferfish Privacy (SRPP) generalizes Pufferfish privacy by using one-dimensional directional Rényi divergences for tractable, geometry-aware privacy guarantees.
  • It defines Ave-SRPP and Joint-SRPP aggregations that enable closed-form anisotropic noise calibration, addressing challenges in high-dimensional optimal transport.
  • SRPP introduces practical composition methods such as the History-Uniform Cap and ms-HUC to support iterative learning while balancing privacy and utility.

Sliced Rényi Pufferfish Privacy (SRPP) generalizes the Pufferfish privacy framework by leveraging directional (sliced) Rényi divergences for privacy accounting. SRPP addresses two central obstacles in Renyi Pufferfish Privacy (RPP): the prohibitive complexity of high-dimensional optimal transport and the lack of a mechanism-agnostic composition rule for iterative learning. SRPP achieves tractable, geometry-aware privacy guarantees by replacing high-dimensional comparisons with a collection of one-dimensional directional comparisons, under a set of unit vectors (“slice profile”). It enables closed-form, statistically stable, and anisotropic noise calibrations for privatization mechanisms, and offers rigorous composition for iterative deep learning via the introduction of the History-Uniform Cap (HUC) and its mean-square variant (ms-HUC) (Zhang et al., 30 Nov 2025).

1. Formal Definition and Divergence Framework

Given probability measures P,QP, Q on Rd\mathbb{R}^d with respective densities p,qp, q, and a unit vector uSd1u \in S^{d-1}, the order-α\alpha (α>1)(\alpha > 1) directional Rényi divergence is defined by

Dα(u)(PQ)=1α1logRpu(t)αqu(t)1αdtD^{(u)}_{\alpha}(P \Vert Q) = \frac{1}{\alpha-1} \log \int_{\mathbb{R}} p_u(t)^\alpha \cdot q_u(t)^{1-\alpha} dt

where pu,qup_u, q_u are the push-forward densities under projection xx,ux \mapsto \langle x, u \rangle.

Aggregating these divergences over a slice profile U={u1,...,um}Sd1\mathcal{U} = \{u_1, ..., u_m\} \subset S^{d-1}, with weights Rd\mathbb{R}^d0, two aggregation schemes are introduced:

  • Ave-SRPP (Average Sliced Rényi Pufferfish Privacy):

Rd\mathbb{R}^d1

  • Joint-SRPP (Joint Log-Moment Sliced Rényi Pufferfish Privacy):

Rd\mathbb{R}^d2

A mechanism Rd\mathbb{R}^d3 satisfies Rd\mathbb{R}^d4-Ave-SRPP if, for all secret-pairs Rd\mathbb{R}^d5 and priors Rd\mathbb{R}^d6,

Rd\mathbb{R}^d7

and similarly for Joint-SRPP using Rd\mathbb{R}^d8.

Ordering is established by

Rd\mathbb{R}^d9

where p,qp, q0 is the standard order-p,qp, q1 Rényi divergence (Zhang et al., 30 Nov 2025).

2. Slicing Geometry and Slice Profile

The slice profile p,qp, q2 is typically composed of p,qp, q3 directions drawn independently and uniformly from the unit sphere p,qp, q4. Typical practice uses p,qp, q5 to balance approximation fidelity against computational cost. Increasing p,qp, q6 provides a closer approximation to the continuous setting, whereas low p,qp, q7 can undersample critical geometric features. Weights p,qp, q8 may be uniform or adapted to data geometry, further enabling geometry-aware privacy calibration.

3. Sliced Wasserstein Mechanisms and Noise Calibration

To privatize a p,qp, q9-dimensional numerical query uSd1u \in S^{d-1}0, SRPP mechanisms avoid computing high-dimensional Wasserstein sensitivities. Instead, each direction uSd1u \in S^{d-1}1 is assigned a one-dimensional sensitivity:

uSd1u \in S^{d-1}2

where uSd1u \in S^{d-1}3 denotes the uSd1u \in S^{d-1}4-Wasserstein distance on uSd1u \in S^{d-1}5. Concretely, for uSd1u \in S^{d-1}6 and uSd1u \in S^{d-1}7, uSd1u \in S^{d-1}8.

Additive Gaussian Noise Calibration: For uSd1u \in S^{d-1}9, α\alpha0 is α\alpha1. The per-direction "shift-Rényi envelope" for the α\alpha2-D Gaussian case is

α\alpha3

Two sensitivity aggregations are defined:

  • Average squared sensitivity α\alpha4
  • Worst-slice sensitivity α\alpha5

Mechanism calibration theorems:

Mechanism Noise Variance Condition SRPP Type
Ave-SRPE Gaussian α\alpha6 (α, ε, ω)-Ave-SRPP Envelope
Joint-SRPE Gaussian α\alpha7 (α, ε, ω)-Joint-SRPP

If these conditions are satisfied, the corresponding (Ave or Joint) SRPP guarantee is realized (Zhang et al., 30 Nov 2025).

4. SRPP Envelope (SRPE): Upper Bounds and Implementability

A per-slice shift-Rényi envelope is defined by

α\alpha8

where α\alpha9 is the law of (α>1)(\alpha > 1)0. For any additive (α>1)(\alpha > 1)1 and slice (α>1)(\alpha > 1)2,

(α>1)(\alpha > 1)3

Aggregating, the SRPP Envelopes (abbreviated as SRPE) are:

  • Ave-SRPE:

(α>1)(\alpha > 1)4

  • Joint-SRPE:

(α>1)(\alpha > 1)5

If (α>1)(\alpha > 1)6, the mechanism satisfies (α>1)(\alpha > 1)7-Ave-SRPE; similarly for the Joint variant.

5. Iterative Learning and SRPP-SGD

SRPP-SGD specializes to iterative learning by privatizing each SGD update via gradient clipping and Gaussian noise. Compositional privacy accounting is achieved using the History-Uniform Cap (HUC).

History-Uniform Cap (HUC): For a slice profile (α>1)(\alpha > 1)8, the vector (α>1)(\alpha > 1)9 is a HUC at iteration Dα(u)(PQ)=1α1logRpu(t)αqu(t)1αdtD^{(u)}_{\alpha}(P \Vert Q) = \frac{1}{\alpha-1} \log \int_{\mathbb{R}} p_u(t)^\alpha \cdot q_u(t)^{1-\alpha} dt0 if, for all secret-pairs, prior Dα(u)(PQ)=1α1logRpu(t)αqu(t)1αdtD^{(u)}_{\alpha}(P \Vert Q) = \frac{1}{\alpha-1} \log \int_{\mathbb{R}} p_u(t)^\alpha \cdot q_u(t)^{1-\alpha} dt1, any trajectory Dα(u)(PQ)=1α1logRpu(t)αqu(t)1αdtD^{(u)}_{\alpha}(P \Vert Q) = \frac{1}{\alpha-1} \log \int_{\mathbb{R}} p_u(t)^\alpha \cdot q_u(t)^{1-\alpha} dt2, and any coupling of Dα(u)(PQ)=1α1logRpu(t)αqu(t)1αdtD^{(u)}_{\alpha}(P \Vert Q) = \frac{1}{\alpha-1} \log \int_{\mathbb{R}} p_u(t)^\alpha \cdot q_u(t)^{1-\alpha} dt3,

Dα(u)(PQ)=1α1logRpu(t)αqu(t)1αdtD^{(u)}_{\alpha}(P \Vert Q) = \frac{1}{\alpha-1} \log \int_{\mathbb{R}} p_u(t)^\alpha \cdot q_u(t)^{1-\alpha} dt4

almost surely over Dα(u)(PQ)=1α1logRpu(t)αqu(t)1αdtD^{(u)}_{\alpha}(P \Vert Q) = \frac{1}{\alpha-1} \log \int_{\mathbb{R}} p_u(t)^\alpha \cdot q_u(t)^{1-\alpha} dt5. This is equivalent to the existence of a positive semidefinite matrix Dα(u)(PQ)=1α1logRpu(t)αqu(t)1αdtD^{(u)}_{\alpha}(P \Vert Q) = \frac{1}{\alpha-1} \log \int_{\mathbb{R}} p_u(t)^\alpha \cdot q_u(t)^{1-\alpha} dt6 with Dα(u)(PQ)=1α1logRpu(t)αqu(t)1αdtD^{(u)}_{\alpha}(P \Vert Q) = \frac{1}{\alpha-1} \log \int_{\mathbb{R}} p_u(t)^\alpha \cdot q_u(t)^{1-\alpha} dt7 and Dα(u)(PQ)=1α1logRpu(t)αqu(t)1αdtD^{(u)}_{\alpha}(P \Vert Q) = \frac{1}{\alpha-1} \log \int_{\mathbb{R}} p_u(t)^\alpha \cdot q_u(t)^{1-\alpha} dt8 for all Dα(u)(PQ)=1α1logRpu(t)αqu(t)1αdtD^{(u)}_{\alpha}(P \Vert Q) = \frac{1}{\alpha-1} \log \int_{\mathbb{R}} p_u(t)^\alpha \cdot q_u(t)^{1-\alpha} dt9.

Existence via Gradient Clipping and Lipschitz Regularity: When per-example gradients are pu,qup_u, q_u0-clipped at pu,qup_u, q_u1, batch-size is pu,qup_u, q_u2, at most pu,qup_u, q_u3 samples differ, and per-step map pu,qup_u, q_u4 is slicewise-Lipschitz with constant pu,qup_u, q_u5, then a HUC is given by

pu,qup_u, q_u6

Mean-square HUC (ms-HUC): Replacing the worst-case pu,qup_u, q_u7 with mean-square bound pu,qup_u, q_u8 yields

pu,qup_u, q_u9

Moments-accountant composition: For xx,ux \mapsto \langle x, u \rangle0,

xx,ux \mapsto \langle x, u \rangle1

The total per-slice cost after xx,ux \mapsto \langle x, u \rangle2 steps is xx,ux \mapsto \langle x, u \rangle3. The noise scale conditions across xx,ux \mapsto \langle x, u \rangle4 steps are:

  • Ave-SRPP-SGD: xx,ux \mapsto \langle x, u \rangle5
  • Joint-SRPP-SGD: xx,ux \mapsto \langle x, u \rangle6

These results extend to mean-squared settings for ms-SRPP-SGD (Zhang et al., 30 Nov 2025).

6. Composition Properties

If xx,ux \mapsto \langle x, u \rangle7 mechanisms xx,ux \mapsto \langle x, u \rangle8, each on the same dataset and each satisfying xx,ux \mapsto \langle x, u \rangle9-Ave-SRPP (or Joint, ms-Ave, ms-Joint) for the same slice profile U={u1,...,um}Sd1\mathcal{U} = \{u_1, ..., u_m\} \subset S^{d-1}0, are released independently, then their product U={u1,...,um}Sd1\mathcal{U} = \{u_1, ..., u_m\} \subset S^{d-1}1 satisfies U={u1,...,um}Sd1\mathcal{U} = \{u_1, ..., u_m\} \subset S^{d-1}2-SRPP of the same type. This holds by tensorization of Rényi divergence (per slice or sliced channel) and aggregation via averaging or log-moment (Zhang et al., 30 Nov 2025).

7. Experimental Validation and Empirical Behavior

Experiments were conducted both for static query privatization and iterative learning.

  • Static queries (Adult, Cleveland Heart, Student Performance): Using both Ave-SRPE and Joint-SRPE mechanisms (U={u1,...,um}Sd1\mathcal{U} = \{u_1, ..., u_m\} \subset S^{d-1}3, U={u1,...,um}Sd1\mathcal{U} = \{u_1, ..., u_m\} \subset S^{d-1}4 random slices, and calibrated U={u1,...,um}Sd1\mathcal{U} = \{u_1, ..., u_m\} \subset S^{d-1}5 as above), privatized queries included per-secret statistics and model parameters (e.g., means, variances, logistic regression parameters). As U={u1,...,um}Sd1\mathcal{U} = \{u_1, ..., u_m\} \subset S^{d-1}6 increases, mean squared error (MSE) decreases and attacker accuracy improves, but privacy degrades. For small U={u1,...,um}Sd1\mathcal{U} = \{u_1, ..., u_m\} \subset S^{d-1}7, MAP attacker accuracy remains near the prior baseline; the Joint mechanism is consistently more conservative than Ave (higher MSE, lower attack accuracy).
  • Iterative learning (CIFAR-10, ResNet-22): The secret is label presence (“cat”), with two scenarios differing by U={u1,...,um}Sd1\mathcal{U} = \{u_1, ..., u_m\} \subset S^{d-1}8 examples. The DP-SGD pipeline applied gradient clipping U={u1,...,um}Sd1\mathcal{U} = \{u_1, ..., u_m\} \subset S^{d-1}9 and Gaussian noise by the SRPP-SGD and ms-SRPP-SGD formulas (Rd\mathbb{R}^d00). ms-SRPP-SGD required less noise for equivalent Rd\mathbb{R}^d01 and achieved higher test accuracy than group-DP-SGD and (worst-case) SRPP-SGD. Overfitting experiments show ms-SRPP-SGD limits membership inference (ROC AUC approaches Rd\mathbb{R}^d02) under strong privacy budgets (Zhang et al., 30 Nov 2025).
Mechanism Static Query Utility Iterative Test Acc. Attacker Advantage
Ave-SRPE Lower MSE Intermediate Higher
Joint-SRPE Higher MSE More conservative Lower
ms-SRPP-SGD Highest Highest Smallest
group-DP-SGD Most conservative Lowest Smallest

Summary

Sliced Rényi Pufferfish Privacy replaces high-dimensional RPP benchmarks with aggregated directional Rényi divergences, enabling tractable, geometry-aware privacy guarantees and closed-form, anisotropic noise calibration. SRPP supports practical privacy composition for both static and iterative (SGD) settings, yielding quantifiable utility gains over conventional high-dimensional Pufferfish and group DP methods (Zhang et al., 30 Nov 2025).

Definition Search Book Streamline Icon: https://streamlinehq.com
References (1)

Topic to Video (Beta)

No one has generated a video about this topic yet.

Whiteboard

No one has generated a whiteboard explanation for this topic yet.

Follow Topic

Get notified by email when new papers are published related to Sliced Renyi Pufferfish Privacy (SRPP).