Local Pan-Privacy for Federated Analytics

Fuente: arXiv
Salvato in:
Dettagli Bibliografici
Autori principali: Feldman, Vitaly, McMillan, Audra, Rothblum, Guy N., Talwar, Kunal
Natura: Preprint
Pubblicazione: 2025
Soggetti:
Accesso online:
Tags: Aggiungi Tag
Nessun Tag, puoi essere il primo ad aggiungerne!!
_version_ 1866929761441284096
author Feldman, Vitaly
McMillan, Audra
Rothblum, Guy N.
Talwar, Kunal
author_facet Feldman, Vitaly
McMillan, Audra
Rothblum, Guy N.
Talwar, Kunal
contents Pan-privacy was proposed by Dwork et al. as an approach to designing a private analytics system that retains its privacy properties in the face of intrusions that expose the system's internal state. Motivated by federated telemetry applications, we study local pan-privacy, where privacy should be retained under repeated unannounced intrusions on the local state. We consider the problem of monitoring the count of an event in a federated system, where event occurrences on a local device should be hidden even from an intruder on that device. We show that under reasonable constraints, the goal of providing information-theoretic differential privacy under intrusion is incompatible with collecting telemetry information. We then show that this problem can be solved in a scalable way using standard cryptographic primitives.
format Preprint
id arxiv_https___arxiv_org_abs_2503_11850
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle Local Pan-Privacy for Federated Analytics
Feldman, Vitaly
McMillan, Audra
Rothblum, Guy N.
Talwar, Kunal
Cryptography and Security
Data Structures and Algorithms
Machine Learning
Pan-privacy was proposed by Dwork et al. as an approach to designing a private analytics system that retains its privacy properties in the face of intrusions that expose the system's internal state. Motivated by federated telemetry applications, we study local pan-privacy, where privacy should be retained under repeated unannounced intrusions on the local state. We consider the problem of monitoring the count of an event in a federated system, where event occurrences on a local device should be hidden even from an intruder on that device. We show that under reasonable constraints, the goal of providing information-theoretic differential privacy under intrusion is incompatible with collecting telemetry information. We then show that this problem can be solved in a scalable way using standard cryptographic primitives.
title Local Pan-Privacy for Federated Analytics
topic Cryptography and Security
Data Structures and Algorithms
Machine Learning
url https://arxiv.org/abs/2503.11850