arXiv:cs.LG· Nikita P. Kalinin, Rasmus Pagh·· 2 天前AI 评分36
面向随机性高效差分隐私的抖动高斯机制
Dithered Gaussian Mechanism for Randomness-Efficient Differential Privacy
AI 导读
研究者提出抖动高斯机制(dithered Gaussian mechanism),通过对私有输出而非噪声分布本身进行离散化,直接继承标准高斯机制的隐私保证,并规避有限精度浮点输出带来的漏洞。该机制将随机性拆分为隐私关键采样所需的高质量随机源与可公开的高性能随机源,使所需高质量随机比特数显著减少且与噪声水平无关。在 DP-SGD 模型训练中,该方案以适度的实际开销实现密码学安全噪声生成。
正文
Abstract:We present the dithered Gaussian mechanism, an alternative to the discrete Gaussian mechanism for differential privacy that discretizes the private output rather than the noise distribution itself. By interpreting this discretization as post-processing of the Gaussian mechanism, our construction directly inherits the privacy guarantees of the standard Gaussian mechanism while avoiding vulnerabilities caused by finite-precision floating-point outputs. In addition, the mechanism is provably randomness-efficient: by sampling the discretized output values directly, the number of high-quality random bits required for privacy can be reduced significantly and made independent of the noise level. This is achieved by separating the randomness into two sources: a high-quality source used for the privacy-critical sampling step, and a high-performance public source, possibly known to the adversary, that supplies the additional randomness needed for randomized discretization. This separation enables the use of cryptographically secure randomness without substantial performance loss. As an application, we study model training with DP-SGD and show that cryptographically secure noise generation with reduced exposure to floating-point vulnerabilities can be achieved with modest practical overhead.
| Comments: | Improved Sampling Algorithm + Numerical Comparison with Baselines |
| Subjects: | Cryptography and Security (cs.CR); Machine Learning (cs.LG) |
| Cite as: | arXiv:2607.06320 [cs.CR] |
| (or arXiv:2607.06320v3 [cs.CR] for this version) | |
| https://doi.org/10.48550/arXiv.2607.06320 arXiv-issued DOI via DataCite |
Submission history
From: Nikita P. Kalinin [view email]
[v1]
Tue, 7 Jul 2026 14:20:00 UTC (141 KB)
[v2]
Mon, 28 Sep 2026 12:03:47 UTC (173 KB)
[v3]
Thu, 1 Oct 2026 12:54:05 UTC (173 KB)
来源:arXiv:cs.LG · arxiv.org