acceptodds
Under review as a conference paper at ICLR 2027

Private Evolution for IPM Optimization: Limits and Alternatives

Abstract

Private Evolution (PE) is a framework for differentially private (DP) synthetic data generation. Given a sensitive dataset and a public dataset , PE evolves by generating public variations of and privately selecting from them to reduce a target discrepancy to . Prior work proves that PE converges to in -Wasserstein () distance, but generating DP synthetic data with accuracy suffers from the curse of dimensionality, even outside the evolution framework. The distance is an integral probability metric (IPM), defined by the largest discrepancy over a class of queries. It is known that more structured query classes can produce DP synthetic data that converge faster than existing lower bounds on convergence. We ask whether PE can exploit this structure by optimizing IPMs other than . Our first result is that even simple IPMs induced by linear or convex-quadratic queries can be difficult to optimize directly via evolution. Even without privacy, exponentially many variations may be needed to generate a candidate dataset with strictly smaller target IPM. For linear queries, we recover statistically- and computationally-efficient PE by replacing the target IPM with a surrogate distance that bounds it, and for which polynomial-size Gaussian variation pools decrease the surrogate in expectation. We then use a DP Frank–Wolfe subroutine within PE to efficiently optimize a distribution over the variations and construct to match the mean of it. The resulting PE achieves IPM error and avoids the curse of dimensionality. This works in part because a dataset with a prescribed mean is easy to construct; for richer queries, reconstruction can itself be hard: we prove that matching only two bounded convex quadratic queries with a fixed-size dataset is already NP-hard. Overall, our results disentangle statistical and computational aspects of the three pieces of PE: the IPM, the evolution, and privacy. Our lower bounds show how non-private evolution fails (computationally), even for simple IPMs, while our positive result shows that replacing the target IPM by a compatible surrogate can recover efficient PE in some special cases.

Then back it, or bet against it.

Related papers

Open the market on this paper to see 7 more related papers.