Label Differential Privacy via Aggregation
cs.LG, stat.ML
Submitted: 2023-10-16
Updated: 2026-09-10
License: http://creativecommons.org/licenses/by/4.0/
The gist: This paper explores the use of linear aggregation to protect the privacy of sensitive training labels through the concept of label differential privacy (label-DP) while maintaining regression task
Terminology
Abstract
This paper explores the use of linear aggregation to protect the privacy of sensitive training labels through the concept of label differential privacy (label-DP) while maintaining regression task utility. Our key finding is that weighted linear aggregation of training instances with i.i.d. N(0, 1) weights can achieve (epsilon, δ) -label-DP with m = O (n/((1/δ))). Unlike prior methods, our approach relies on the minimum linear regression loss rather than the minimum singular value of the data matrix, resulting in better practical bounds on real datasets. We also examine real-world mechanisms involving disjoint sets or bags of instances. We demonstrate that aggregating labels from sub-sampled disjoint k-sized bags using i.i.d. N(0,1) weights achieves (epsilon,δ) -label-DP with k at least Ω (((1/epsilon) (1/δ)) 2). In both scenarios, the optimal linear mse-regressor on the aggregated data approximates the original dataset's optimum with high probability, without needing additive label noise. Furthermore, we show that adding N(0,1) noise to any constant fraction of labels allows for similar label-DP guarantees when aggregating labels over random disjoint bags, while preserving the utility of Lipschitz-bounded neural mse-regression tasks.
Sources
- Deep multi-class learning from label proportions
- Regression with Label Differential Privacy
- Note on sampling without replacing from a finite collection of matrices
- Challenges and approaches to privacy preserving post-click conversion prediction
- On Learning from Label Proportions
Related papers
- Polynomial-Augmented Neural Networks (PANNs) with Weak Orthogonality Constraints for Enhanced Function and PDE Approximation
- AIRL-S: Unifying Reinforcement Learning and Search-Based Test-Time Scaling via Adversarial Inverse Reinforcement Learning
- Transformers as Bayesian In-Context Experimenters: Smoothness-Adaptive Efficient ATE Estimation
- Convergence issues in Relational Concept Analysis based on AOC-posets
- Beliefs Beyond Posteriors: Local-Consistency Optimisation for Bayesian Neural Networks
- Understanding Diffusion Models via Ratio-Based Function Approximation with SignReLU Networks