Frequency Estimation in the Shuffle Model with Almost a Single Message

We present a protocol in the shuffle model of differential privacy (DP) for the \textit{frequency estimation} problem that achieves error , almost matching the central-DP accuracy, with messages per user. This exhibits a sharp transition phenomenon, as there is a lower bound of if each user is allowed to send only one message. Previously, such a result is only known when the domain size is . For a large domain, we also need an efficient method to identify the \textit{heavy hitters} (i.e., elements that are frequent enough). For this purpose, we design a shuffle-DP protocol that uses messages per user and can identify all heavy hitters in time polylogarithmic in . Finally, by combining our frequency estimation and the heavy hitter detection protocols, we show how to solve the -dimensional \textit{1-sparse vector summation} problem in the high-dimensional setting , achieving the optimal central-DP MSE with messages per user. In addition to error and message number, our protocols improve in terms of message size and running time as well. They are also very easy to implement. The experimental results demonstrate order-of-magnitude improvement over prior work.
View on arXiv