Papers
Topics
Authors
Recent
Search
2000 character limit reached

Sliced Rényi Pufferfish Privacy

Updated 7 December 2025
  • Sliced Rényi Pufferfish Privacy (SRPP) generalizes Pufferfish privacy by using one-dimensional directional Rényi divergences for tractable, geometry-aware privacy guarantees.
  • It defines Ave-SRPP and Joint-SRPP aggregations that enable closed-form anisotropic noise calibration, addressing challenges in high-dimensional optimal transport.
  • SRPP introduces practical composition methods such as the History-Uniform Cap and ms-HUC to support iterative learning while balancing privacy and utility.

Sliced Rényi Pufferfish Privacy (SRPP) generalizes the Pufferfish privacy framework by leveraging directional (sliced) Rényi divergences for privacy accounting. SRPP addresses two central obstacles in Renyi Pufferfish Privacy (RPP): the prohibitive complexity of high-dimensional optimal transport and the lack of a mechanism-agnostic composition rule for iterative learning. SRPP achieves tractable, geometry-aware privacy guarantees by replacing high-dimensional comparisons with a collection of one-dimensional directional comparisons, under a set of unit vectors (“slice profile”). It enables closed-form, statistically stable, and anisotropic noise calibrations for privatization mechanisms, and offers rigorous composition for iterative deep learning via the introduction of the History-Uniform Cap (HUC) and its mean-square variant (ms-HUC) (Zhang et al., 30 Nov 2025).

1. Formal Definition and Divergence Framework

Given probability measures P,QP, Q on Rd\mathbb{R}^d with respective densities p,qp, q, and a unit vector u∈Sd−1u \in S^{d-1}, the order-α\alpha (α>1)(\alpha > 1) directional Rényi divergence is defined by

Dα(u)(P∥Q)=1α−1log⁡∫Rpu(t)α⋅qu(t)1−αdtD^{(u)}_{\alpha}(P \Vert Q) = \frac{1}{\alpha-1} \log \int_{\mathbb{R}} p_u(t)^\alpha \cdot q_u(t)^{1-\alpha} dt

where pu,qup_u, q_u are the push-forward densities under projection x↦⟨x,u⟩x \mapsto \langle x, u \rangle.

Aggregating these divergences over a slice profile U={u1,...,um}⊂Sd−1\mathcal{U} = \{u_1, ..., u_m\} \subset S^{d-1}, with weights Rd\mathbb{R}^d0, two aggregation schemes are introduced:

  • Ave-SRPP (Average Sliced Rényi Pufferfish Privacy):

Rd\mathbb{R}^d1

  • Joint-SRPP (Joint Log-Moment Sliced Rényi Pufferfish Privacy):

Rd\mathbb{R}^d2

A mechanism Rd\mathbb{R}^d3 satisfies Rd\mathbb{R}^d4-Ave-SRPP if, for all secret-pairs Rd\mathbb{R}^d5 and priors Rd\mathbb{R}^d6,

Rd\mathbb{R}^d7

and similarly for Joint-SRPP using Rd\mathbb{R}^d8.

Ordering is established by

Rd\mathbb{R}^d9

where p,qp, q0 is the standard order-p,qp, q1 Rényi divergence (Zhang et al., 30 Nov 2025).

2. Slicing Geometry and Slice Profile

The slice profile p,qp, q2 is typically composed of p,qp, q3 directions drawn independently and uniformly from the unit sphere p,qp, q4. Typical practice uses p,qp, q5 to balance approximation fidelity against computational cost. Increasing p,qp, q6 provides a closer approximation to the continuous setting, whereas low p,qp, q7 can undersample critical geometric features. Weights p,qp, q8 may be uniform or adapted to data geometry, further enabling geometry-aware privacy calibration.

3. Sliced Wasserstein Mechanisms and Noise Calibration

To privatize a p,qp, q9-dimensional numerical query u∈Sd−1u \in S^{d-1}0, SRPP mechanisms avoid computing high-dimensional Wasserstein sensitivities. Instead, each direction u∈Sd−1u \in S^{d-1}1 is assigned a one-dimensional sensitivity:

u∈Sd−1u \in S^{d-1}2

where u∈Sd−1u \in S^{d-1}3 denotes the u∈Sd−1u \in S^{d-1}4-Wasserstein distance on u∈Sd−1u \in S^{d-1}5. Concretely, for u∈Sd−1u \in S^{d-1}6 and u∈Sd−1u \in S^{d-1}7, u∈Sd−1u \in S^{d-1}8.

Additive Gaussian Noise Calibration: For u∈Sd−1u \in S^{d-1}9, α\alpha0 is α\alpha1. The per-direction "shift-Rényi envelope" for the α\alpha2-D Gaussian case is

α\alpha3

Two sensitivity aggregations are defined:

  • Average squared sensitivity α\alpha4
  • Worst-slice sensitivity α\alpha5

Mechanism calibration theorems:

Mechanism Noise Variance Condition SRPP Type
Ave-SRPE Gaussian α\alpha6 (α, ε, ω)-Ave-SRPP Envelope
Joint-SRPE Gaussian α\alpha7 (α, ε, ω)-Joint-SRPP

If these conditions are satisfied, the corresponding (Ave or Joint) SRPP guarantee is realized (Zhang et al., 30 Nov 2025).

4. SRPP Envelope (SRPE): Upper Bounds and Implementability

A per-slice shift-Rényi envelope is defined by

α\alpha8

where α\alpha9 is the law of (α>1)(\alpha > 1)0. For any additive (α>1)(\alpha > 1)1 and slice (α>1)(\alpha > 1)2,

(α>1)(\alpha > 1)3

Aggregating, the SRPP Envelopes (abbreviated as SRPE) are:

  • Ave-SRPE:

(α>1)(\alpha > 1)4

  • Joint-SRPE:

(α>1)(\alpha > 1)5

If (α>1)(\alpha > 1)6, the mechanism satisfies (α>1)(\alpha > 1)7-Ave-SRPE; similarly for the Joint variant.

5. Iterative Learning and SRPP-SGD

SRPP-SGD specializes to iterative learning by privatizing each SGD update via gradient clipping and Gaussian noise. Compositional privacy accounting is achieved using the History-Uniform Cap (HUC).

History-Uniform Cap (HUC): For a slice profile (α>1)(\alpha > 1)8, the vector (α>1)(\alpha > 1)9 is a HUC at iteration Dα(u)(P∥Q)=1α−1log⁡∫Rpu(t)α⋅qu(t)1−αdtD^{(u)}_{\alpha}(P \Vert Q) = \frac{1}{\alpha-1} \log \int_{\mathbb{R}} p_u(t)^\alpha \cdot q_u(t)^{1-\alpha} dt0 if, for all secret-pairs, prior Dα(u)(P∥Q)=1α−1log⁡∫Rpu(t)α⋅qu(t)1−αdtD^{(u)}_{\alpha}(P \Vert Q) = \frac{1}{\alpha-1} \log \int_{\mathbb{R}} p_u(t)^\alpha \cdot q_u(t)^{1-\alpha} dt1, any trajectory Dα(u)(P∥Q)=1α−1log⁡∫Rpu(t)α⋅qu(t)1−αdtD^{(u)}_{\alpha}(P \Vert Q) = \frac{1}{\alpha-1} \log \int_{\mathbb{R}} p_u(t)^\alpha \cdot q_u(t)^{1-\alpha} dt2, and any coupling of Dα(u)(P∥Q)=1α−1log⁡∫Rpu(t)α⋅qu(t)1−αdtD^{(u)}_{\alpha}(P \Vert Q) = \frac{1}{\alpha-1} \log \int_{\mathbb{R}} p_u(t)^\alpha \cdot q_u(t)^{1-\alpha} dt3,

Dα(u)(P∥Q)=1α−1log⁡∫Rpu(t)α⋅qu(t)1−αdtD^{(u)}_{\alpha}(P \Vert Q) = \frac{1}{\alpha-1} \log \int_{\mathbb{R}} p_u(t)^\alpha \cdot q_u(t)^{1-\alpha} dt4

almost surely over Dα(u)(P∥Q)=1α−1log⁡∫Rpu(t)α⋅qu(t)1−αdtD^{(u)}_{\alpha}(P \Vert Q) = \frac{1}{\alpha-1} \log \int_{\mathbb{R}} p_u(t)^\alpha \cdot q_u(t)^{1-\alpha} dt5. This is equivalent to the existence of a positive semidefinite matrix Dα(u)(P∥Q)=1α−1log⁡∫Rpu(t)α⋅qu(t)1−αdtD^{(u)}_{\alpha}(P \Vert Q) = \frac{1}{\alpha-1} \log \int_{\mathbb{R}} p_u(t)^\alpha \cdot q_u(t)^{1-\alpha} dt6 with Dα(u)(P∥Q)=1α−1log⁡∫Rpu(t)α⋅qu(t)1−αdtD^{(u)}_{\alpha}(P \Vert Q) = \frac{1}{\alpha-1} \log \int_{\mathbb{R}} p_u(t)^\alpha \cdot q_u(t)^{1-\alpha} dt7 and Dα(u)(P∥Q)=1α−1log⁡∫Rpu(t)α⋅qu(t)1−αdtD^{(u)}_{\alpha}(P \Vert Q) = \frac{1}{\alpha-1} \log \int_{\mathbb{R}} p_u(t)^\alpha \cdot q_u(t)^{1-\alpha} dt8 for all Dα(u)(P∥Q)=1α−1log⁡∫Rpu(t)α⋅qu(t)1−αdtD^{(u)}_{\alpha}(P \Vert Q) = \frac{1}{\alpha-1} \log \int_{\mathbb{R}} p_u(t)^\alpha \cdot q_u(t)^{1-\alpha} dt9.

Existence via Gradient Clipping and Lipschitz Regularity: When per-example gradients are pu,qup_u, q_u0-clipped at pu,qup_u, q_u1, batch-size is pu,qup_u, q_u2, at most pu,qup_u, q_u3 samples differ, and per-step map pu,qup_u, q_u4 is slicewise-Lipschitz with constant pu,qup_u, q_u5, then a HUC is given by

pu,qup_u, q_u6

Mean-square HUC (ms-HUC): Replacing the worst-case pu,qup_u, q_u7 with mean-square bound pu,qup_u, q_u8 yields

pu,qup_u, q_u9

Moments-accountant composition: For x↦⟨x,u⟩x \mapsto \langle x, u \rangle0,

x↦⟨x,u⟩x \mapsto \langle x, u \rangle1

The total per-slice cost after x↦⟨x,u⟩x \mapsto \langle x, u \rangle2 steps is x↦⟨x,u⟩x \mapsto \langle x, u \rangle3. The noise scale conditions across x↦⟨x,u⟩x \mapsto \langle x, u \rangle4 steps are:

  • Ave-SRPP-SGD: x↦⟨x,u⟩x \mapsto \langle x, u \rangle5
  • Joint-SRPP-SGD: x↦⟨x,u⟩x \mapsto \langle x, u \rangle6

These results extend to mean-squared settings for ms-SRPP-SGD (Zhang et al., 30 Nov 2025).

6. Composition Properties

If x↦⟨x,u⟩x \mapsto \langle x, u \rangle7 mechanisms x↦⟨x,u⟩x \mapsto \langle x, u \rangle8, each on the same dataset and each satisfying x↦⟨x,u⟩x \mapsto \langle x, u \rangle9-Ave-SRPP (or Joint, ms-Ave, ms-Joint) for the same slice profile U={u1,...,um}⊂Sd−1\mathcal{U} = \{u_1, ..., u_m\} \subset S^{d-1}0, are released independently, then their product U={u1,...,um}⊂Sd−1\mathcal{U} = \{u_1, ..., u_m\} \subset S^{d-1}1 satisfies U={u1,...,um}⊂Sd−1\mathcal{U} = \{u_1, ..., u_m\} \subset S^{d-1}2-SRPP of the same type. This holds by tensorization of Rényi divergence (per slice or sliced channel) and aggregation via averaging or log-moment (Zhang et al., 30 Nov 2025).

7. Experimental Validation and Empirical Behavior

Experiments were conducted both for static query privatization and iterative learning.

  • Static queries (Adult, Cleveland Heart, Student Performance): Using both Ave-SRPE and Joint-SRPE mechanisms (U={u1,...,um}⊂Sd−1\mathcal{U} = \{u_1, ..., u_m\} \subset S^{d-1}3, U={u1,...,um}⊂Sd−1\mathcal{U} = \{u_1, ..., u_m\} \subset S^{d-1}4 random slices, and calibrated U={u1,...,um}⊂Sd−1\mathcal{U} = \{u_1, ..., u_m\} \subset S^{d-1}5 as above), privatized queries included per-secret statistics and model parameters (e.g., means, variances, logistic regression parameters). As U={u1,...,um}⊂Sd−1\mathcal{U} = \{u_1, ..., u_m\} \subset S^{d-1}6 increases, mean squared error (MSE) decreases and attacker accuracy improves, but privacy degrades. For small U={u1,...,um}⊂Sd−1\mathcal{U} = \{u_1, ..., u_m\} \subset S^{d-1}7, MAP attacker accuracy remains near the prior baseline; the Joint mechanism is consistently more conservative than Ave (higher MSE, lower attack accuracy).
  • Iterative learning (CIFAR-10, ResNet-22): The secret is label presence (“cat”), with two scenarios differing by U={u1,...,um}⊂Sd−1\mathcal{U} = \{u_1, ..., u_m\} \subset S^{d-1}8 examples. The DP-SGD pipeline applied gradient clipping U={u1,...,um}⊂Sd−1\mathcal{U} = \{u_1, ..., u_m\} \subset S^{d-1}9 and Gaussian noise by the SRPP-SGD and ms-SRPP-SGD formulas (Rd\mathbb{R}^d00). ms-SRPP-SGD required less noise for equivalent Rd\mathbb{R}^d01 and achieved higher test accuracy than group-DP-SGD and (worst-case) SRPP-SGD. Overfitting experiments show ms-SRPP-SGD limits membership inference (ROC AUC approaches Rd\mathbb{R}^d02) under strong privacy budgets (Zhang et al., 30 Nov 2025).
Mechanism Static Query Utility Iterative Test Acc. Attacker Advantage
Ave-SRPE Lower MSE Intermediate Higher
Joint-SRPE Higher MSE More conservative Lower
ms-SRPP-SGD Highest Highest Smallest
group-DP-SGD Most conservative Lowest Smallest

Summary

Sliced Rényi Pufferfish Privacy replaces high-dimensional RPP benchmarks with aggregated directional Rényi divergences, enabling tractable, geometry-aware privacy guarantees and closed-form, anisotropic noise calibration. SRPP supports practical privacy composition for both static and iterative (SGD) settings, yielding quantifiable utility gains over conventional high-dimensional Pufferfish and group DP methods (Zhang et al., 30 Nov 2025).

Definition Search Book Streamline Icon: https://streamlinehq.com
References (1)

Topic to Video (Beta)

No one has generated a video about this topic yet.

Whiteboard

No one has generated a whiteboard explanation for this topic yet.

Follow Topic

Get notified by email when new papers are published related to Sliced Renyi Pufferfish Privacy (SRPP).