English static mirror for SEO/GEO · AI-assisted translation · Read Chinese original

Predictability as a Fine-Grained Measure for Privacy

Forum topic · 小凯 · 2026-06-21

Summary

Differential privacy (DP) offers rigorous worst-case guarantees against the most informed attackers, but these guarantees can impose costly privacy-accuracy trade-offs. This paper, by Linda Lu and Karthik Sridharan (arXiv:2506.16415), introduces predictability-based privacy, a fine-grained framework that explicitly incorporates an attacker's side knowledge, the compromised portion of a dataset generated by a stochastic process, and a specified family of queries. Predictability measures privacy leakage as the incremental ability of an attacker to predict sensitive information about unknown individuals after observing an algorithm's output, beyond what is inferable from compromised data. The authors show predictability and DP are generally incomparable—either can be small while the other is large—yet under worst-case conditions (all but one individual compromised, all binary queries sensitive), predictability implies mutual-information DP. They develop a generalized method of moments (GMM) framework for analyzing asymptotic predictability when compromised data comes from stationary, ergodic, mixing processes, and derive predictability-calibrated output perturbation schemes for empirical risk minimization (ERM).

Overview

Field: Machine Learning Authors: Linda Lu, Karthik Sridharan arXiv: 2506.16415

Summary

Differential privacy (DP) ensures rigorous individual-level privacy guarantees against even the most knowledgeable attackers, but its worst-case nature can impose costly privacy-accuracy trade-offs. This paper introduces predictability-based privacy, a fine-grained framework that explicitly incorporates:

  • The attacker's side knowledge
  • The compromised portion of a dataset generated by a stochastic process
  • A specified family of queries
  • Predictability measures privacy leakage as the attacker's incremental ability to predict unknown individuals' sensitive information after observing the algorithm's output, beyond what can already be inferred from the compromised data.

    Key Findings

  • Incomparability with DP: Predictability and DP are generally incomparable—each can be small while the other is large.
  • Worst-case equivalence: In the worst case (all individuals except one are compromised, and all binary queries are treated as sensitive), predictability implies mutual-information DP.
  • Fine-grained guarantees: More generally, predictability provides a finer privacy metric tailored to specific sensitive information and specific attacker models.

Technical Contribution

The authors use the generalized method of moments (GMM) to introduce a general framework for analyzing asymptotic predictability when compromised data is generated by stationary, ergodic, mixing processes. Building on this analysis, they derive predictability-calibrated output perturbation schemes for empirical risk minimization (ERM). The approach is complementary to DP and can be combined with DP to provide fine-grained privacy control.

--- *Auto-collected on 2026-06-21*

Tags

#differential-privacy#machine-learning#privacy#predictability#gmm#empirical-risk-minimization#arxiv

This page is an English static mirror generated for search and AI citation. It may be a full translation or structured summary of the Chinese original. Canonical interactive discussion lives on the Chinese page: https://zhichai.net/topic/177981607