80
11

Canonical Noise Distributions and Private Hypothesis Tests

Abstract

ff-DP has recently been proposed as a generalization of differential privacy allowing a lossless analysis of composition, post-processing, and privacy amplification via subsampling. In the setting of ff-DP, we propose the concept of a canonical noise distribution (CND), the first mechanism designed for an arbitrary ff-DP guarantee. The notion of CND captures whether an additive privacy mechanism perfectly matches the privacy guarantee of a given ff. We prove that a CND always exists, and give a construction that produces a CND for any ff. We show that private hypothesis tests are intimately related to CNDs, allowing for the release of private pp-values at no additional privacy cost as well as the construction of uniformly most powerful (UMP) tests for binary data, within the general ff-DP framework. We apply our techniques to the problem of difference of proportions testing, and construct a UMP unbiased (UMPU) "semi-private" test which upper bounds the performance of any ff-DP test. Using this as a benchmark we propose a private test, based on the inversion of characteristic functions, which allows for optimal inference for the two population parameters and is nearly as powerful as the semi-private UMPU. When specialized to the case of (ϵ,0)(\epsilon,0)-DP, we show empirically that our proposed test is more powerful than any (ϵ/2)(\epsilon/\sqrt 2)-DP test and has more accurate type I errors than the classic normal approximation test.

View on arXiv
Comments on this paper