Privacy Admission from Incomplete Rényi Differential Privacy Histories
Abstract
A privacy accountant must decide whether a proposed release, together with past outputs, meets a total differential privacy budget. We study this decision when the historical record contains only upper bounds at finitely many Rényi differential privacy (RDP) orders, while the proposed request has a known privacy profile. The record defines a class of possible histories. For a request fixed independently of past private outputs and run with fresh randomness, we maximize its composed privacy value over that class while preserving the request as a factor. Retaining only multiplied RDP moments instead permits aggregate laws inconsistent with the specified request. We prove strict randomized-response and Gaussian-DP separations in which this information loss blocks safe admission. Moment duality gives checkable upper bounds with explicit allowances for historical tails and numerical errors. Controlled comparisons recover admissions that the aggregate summary cannot justify and distinguish this information gain from improvements in computed bounds. A second comparison holds the request profile fixed: direct optimization sharpens some admission bounds relative to a reusable historical profile, while reuse trades preparation cost for cheaper subsequent queries.
est. 32% chance this paper gets accepted at ICLR 2027.
What do you think this paper will get?
All positions stay anonymous.