From Robustness to Privacy and Back

02/03/2023
by   Hilal Asi, et al.
0

We study the relationship between two desiderata of algorithms in statistical inference and machine learning: differential privacy and robustness to adversarial data corruptions. Their conceptual similarity was first observed by Dwork and Lei (STOC 2009), who observed that private algorithms satisfy robustness, and gave a general method for converting robust algorithms to private ones. However, all general methods for transforming robust algorithms into private ones lead to suboptimal error rates. Our work gives the first black-box transformation that converts any adversarially robust algorithm into one that satisfies pure differential privacy. Moreover, we show that for any low-dimensional estimation task, applying our transformation to an optimal robust estimator results in an optimal private estimator. Thus, we conclude that for any low-dimensional task, the optimal error rate for ε-differentially private estimators is essentially the same as the optimal error rate for estimators that are robust to adversarially corrupting 1/ε training samples. We apply our transformation to obtain new optimal private estimators for several high-dimensional tasks, including Gaussian (sparse) linear regression and PCA. Finally, we present an extension of our transformation that leads to approximate differentially private algorithms whose error does not depend on the range of the output space, which is impossible under pure differential privacy.

READ FULL TEXT

page 1

page 2

page 3

page 4

research
06/02/2020

Designing Differentially Private Estimators in High Dimensions

We study differentially private mean estimation in a high-dimensional se...
research
12/09/2022

Robustness Implies Privacy in Statistical Estimation

We study the relationship between adversarial robustness and differentia...
research
05/27/2022

DP-PCA: Statistically Optimal and Differentially Private PCA

We study the canonical statistical task of computing the principal compo...
research
11/22/2019

Privacy-preserving parametric inference: a case for robust statistics

Differential privacy is a cryptographically-motivated approach to privac...
research
07/10/2020

Differentially Private Simple Linear Regression

Economics and social science research often require analyzing datasets o...
research
11/04/2021

Universal Private Estimators

We present universal estimators for the statistical mean, variance, and ...
research
10/31/2020

Strongly universally consistent nonparametric regression and classification with privatised data

In this paper we revisit the classical problem of nonparametric regressi...

Please sign up or login with your details

Forgot password? Click here to reset