Search papers, labs, and topics across Lattice.
This paper investigates the conditions under which natural privacy filters, which allow for exact composition of differentially private (DP) mechanisms with adaptive privacy characteristics, can be implemented without incurring additional privacy cost. The authors demonstrate that, unlike other DP composition methods, natural privacy filters are not universally "free." They prove that only well-ordered families of privacy mechanisms, when composed, admit free natural privacy filters.
Natural privacy filters, despite their promise for tighter privacy accounting, aren't universally "free," limiting their applicability to specific families of differentially private mechanisms.
We study natural privacy filters, which enable the exact composition of differentially private (DP) mechanisms with adaptively chosen privacy characteristics. Earlier privacy filters consider only simple privacy parameters such as Rényi-DP or Gaussian DP parameters. Natural filters account for the entire privacy profile of every query, promising greater utility for a given privacy budget. We show that, contrary to other forms of DP, natural privacy filters are not free in general. Indeed, we show that only families of privacy mechanisms that are well-ordered when composed admit free natural privacy filters.