Skip to yearly menu bar Skip to main content


Poission Subsampled R\'enyi Differential Privacy

Yuqing Zhu · Yu-Xiang Wang

Pacific Ballroom #178

Keywords: [ Privacy-preserving Statistics and Machine Learning ]


We consider the problem of privacy-amplification by under the Renyi Differential Privacy framework. This is the main technique underlying the moments accountants (Abadi et al., 2016) for differentially private deep learning. Unlike previous attempts on this problem which deals with Sampling with Replacement, we consider the Poisson subsampling scheme which selects each data point independently with a coin toss. This allows us to significantly simplify and tighten the bounds for the RDP of subsampled mechanisms and derive numerically stable approximation schemes. In particular, for subsampled Gaussian mechanism and subsampled Laplace mechanism, we prove an analytical formula of their RDP that exactly matches the lower bound. The result is the first of its kind and we numerically demonstrate an order of magnitude improvement in the privacy-utility tradeoff.

Live content is unavailable. Log in and register to view live content