Title: Characterizing Differential Privacy: Analytical and Black-Box Approaches
Date: September 11 (Friday)
Time:10am - 12 pm EST
Location: (In-person) Coda C1008 Bolton
(Virtual) https://teams.microsoft.com/meet/263011129320082?p=eWNP2XKBitnUg9s34M
Yu
Wei
Ph.D. Student - School of Cybersecurity and Privacy
Georgia Institute of Technology
Committee
Members
Dr. Vassilis Zikas
(Advisor) - School of Cybersecurity and Privacy, Georgia Institute of Technology
Dr. Vladimir Kolesnikov - School of Cybersecurity and
Privacy, Georgia Institute of Technology
Dr. Teodora Baluta - School of Cybersecurity and Privacy,
Georgia Institute of Technology
Dr. Alex Ozdemir - School of Cybersecurity and Privacy,
Georgia Institute of Technology
Abstract
Differential privacy provides a rigorous framework for controlling how much the behavior of a randomized computation can change when an individual’s data changes. Yet understanding and deploying differentially private computations raises several fundamental questions: How private is a given computation? Can we design computations with better privacy–utility tradeoffs? And can we verify that a realized computation actually satisfies its claimed privacy guarantee?
This dissertation approaches these questions by interpreting differential privacy through the lens of indistinguishability. Rather than working with a single representation, I characterize this indistinguishability through different views and reductions that make the related privacy questions tractable. These characterizations lead to two complementary approaches. In the black-box approach, I reason from samples of a computation’s observed outputs, using classification and hypothesis testing to estimate and audit its indistinguishability. This line of work develops from black-box estimation of (epsilon, delta)-privacy, to estimation/auditing of the full f-DP curve, to sequential and one-run privacy auditing.
The second is an analytical approach, which exploits distributional structure in the observer’s view to derive tractable characterizations of indistinguishability. I study computations whose observable outputs are Gaussian and develop tools for characterizing their differential privacy guarantees, enabling both privacy analysis and mechanism design. Building on this perspective, I also study additive-noise mechanisms, establishing the asymptotic optimality of Gaussian noise among additive-noise mechanisms in high dimensions and designing improved mechanisms in low dimensions.
Together, this dissertation develops a methodology for studying differential privacy as an indistinguishability notion: characterize indistinguishability through different views, and use the resulting characterizations to address the three fundamental problems in differentially private computations.