Differential privacy mechanisms using exact real arithmetic
Using exact real arithmetic with Cauchy sequences in differential privacy mechanisms addresses vulnerabilities in existing methods, ensuring robust privacy by generating statistical noise resistant to precision-based attacks and allowing customizable result granularity.
Patent Information
- Application Number
- PCT/EP2024/050656
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2024-01-12
- Publication Date
- 2025-07-17
AI Technical Summary
Existing differential privacy mechanisms are vulnerable to attacks that exploit vulnerabilities in floating-point representations, compromising privacy guarantees.
Implementing differential privacy mechanisms using exact real arithmetic, specifically through the generation of statistical noise with Cauchy sequences, to ensure robustness against precision-based attacks and maintain privacy guarantees.
The method generates statistical noise that is resilient to floating-point and precision-based attacks, ensuring differential privacy guarantees by using exact real arithmetic and customizing the granularity of results.
Smart Images

Figure EP2024050656_17072025_PF_FP_ABST
Abstract
Description
[0001]DIFFERENTIAL PRIVACY MECHANISMS USING EXACT REAL ARITHMETIC TECHNICAL FIELD The present disclosure relates to generating a sample of statistical noise to be aggregated with a result of a query in a differential privacy mechanism, a method for obtaining a randomized result of a query, an electronic device configured to perform any of said methods, a computer program product, and a computer program carrier. BACKGROUND Large amounts of data are being collected about subjects (individuals) by a variety of organizations like research institutions or companies. However, much of the collected data is private: it comprises details about subjects and their behavior. Privacy concerns about subjects restrict the way this information can be used and released, where utilizing subjects' data is therefore curbed for ethical, legal, or business reasons. It is often believed that data can be anonymized somehow in order to preserve the privacy of individuals. While a step forward, simply anonymizing data loses their effectiveness when additional knowledge can be exploited. Differential privacy (DP) mechanisms enable data analyses to release statistical information about the population without compromising data subjects' privacy. A standard way to comply with a DP guarantee is adding statistical noise into the results of data analyses. Such statistical noise is typically sampled from Laplace or Gaussian distributions. A problem with differential privacy mechanisms is that there are known attacks that exploit vulnerabilities of the implementation of the DP mechanism. Such attacks may compromise the privacy of the released randomized data, which is undesired. Therefore, there is a need for improved implementations of DP mechanisms. SUMMARY It is an object of the present disclosure to enable improved differential privacy mechanisms, and in particular differential privacy mechanisms less vulnerable to attacks. This object is obtained at least in part by a computer-implemented method for generating a sample of statistical noise to be aggregated, by an aggregation operation, with a result of a query in a differential privacy mechanism. The method comprises obtaining data indicative of a statistical noise distribution; obtaining one or more parameters indicative of desired differential privacy guarantee; obtaining a parameter indicative of a sensitivity of the query in the differential privacy mechanism; obtaining a parameter indicative of a first natural number of significant digits for computing the aggregation operation in the differential privacy mechanism and / or indicative of second natural number of observable digits after the radix point for a result of the aggregation operation in the differential privacy mechanism; and generating the sample of statistical noise from the statistical distribution based on the one or more parameters indicative of desired differential privacy guarantee, the parameter indicative of a sensitivity of the query in the differential privacy mechanism, and the parameter indicative of the first natural number and / or the second natural number. The sample of statistical noise is generated using exact real arithmetic based on a Cauchy sequence. The Cauchy sequence may be a fast binary Cauchy sequence, which is a type of a Cauchy sequence and is computationally efficient in terms of speed and memory efficiency. The fast binary Cauchy sequence is particularly suitable for exact real arithmetic operations. The disclosed method generates statistical noise suitable for ensuring differential privacy guarantees according to given parameters. The generated sample is suitable for randomizing a query, i.e., to be aggregated with a query, which will be insensitive to precision attacks, also called floating-point attacks. The first natural number may also be called a significant number. The second natural number may be called an observable number. According to some aspects, a minimum length, represented by a third natural number, of a Cauchy sequence representing the statistical noise to be generated provides the first natural number of significant digits for computing the aggregation operation in the differential privacy mechanism. According to some aspects, the statistical distribution is a Laplace distribution or a Gaussian distribution. Any of these distributions may provide suitable random numbers for differential privacy mechanisms. According to some aspects, the statistical distribution is a Laplace distribution and the sample of statistical noise is generated using inverse transform sampling. The inverse transform sampling provides a computationally efficient way of generating a sample with a predetermined precision, in particular for Laplace distributions. According to some aspects, the statistical distribution is a Gaussian distribution and the sample of statistical noise is generated using the Box–Muller transform, the Marsaglia polar method, or the Ziggurat algorithm. Any of these sampling methods provide computationally efficient ways of generating a sample with a predetermined precision, in particular for Gaussian distributions.According to some aspects, is the sample of statistical noise, and is generated as =(2^^ − 1)∆^^log(^^) / ^^, where ∆^^ is the parameter indicative of a sensitivity of the query, ^^ is oneof the one or more parameters indicative of desired differential privacy guarantee, ^^ is a random number generated from a uniform distribution between zero and one, and ^^ is a random number generated from a uniform distribution consisting of one and zero. In that case, the random number ^^ may be generated as a Cauchy sequence. This Cauchy sequence may be a fast binary Cauchy sequence. One advantage of this way of generating the sample of statistical noise is that it only requires two random numbers to be generated, i.e., ^^ and ^^.According to some aspects, is the sample of statistical noise, and is generated as =sgn(^^)∆^^log(1 − 2|^^|) / ^^, where ^^ = ^^ − 1 / 2, ∆^^ is the parameter indicative of a sensitivity ofthe query, ^^ is one of the one or more parameters indicative of desired differential privacy guarantee, and ^^ is a random number generated from a uniform distribution between zero and one. In that case, the random number ^^ may be generated as a fast binary Cauchy sequence. This Cauchy sequence may be a fast binary Cauchy sequence. One advantage of this way of generating the sample of statistical noise is that it only requires one random number to be generated, i.e., the random number ^^. Furthermore, only one Cauchy sequence is randomly generated (the random number ^^). In particular, the random number ^^, according to the previous two paragraphs, may be generated by: obtaining a uniformly sampled bit sequence comprising the third natural number of bits; obtaining a fourth natural number based on the uniformly sampled bit sequence; and providing ^^ by dividing the fourth natural number by 2 to the power of the third natural number. According to some aspects, the third natural number is larger the first natural number , and preferably larger than the first natural number by at least a factor of the first natural number times 2log(10). Here, “2log” is the log of base 2. There is also disclosed herein, a computer-implemented method for obtaining a randomized result of a query. Said method is associated with the above-discussed advantages. The method comprises obtaining a result of the query, and aggregating a sample of statistical noise generated according to the discussions above to the obtained result of the query to obtain the randomized result of the query. Any of the result of the query, the generated sample of statistical noise, and the randomized result of the query may be represented by a respective Cauchy sequence. According to some aspects, in the method for obtaining a randomized result of a query, the aggregating the sample of statistical noise to the obtained result of the query is computed with the first natural number of significant digits. The method for obtaining a randomized result of a query may further comprise truncating the randomized result of the query to the second natural number of observable digits after the radix point. The truncation may comprise reducing the number of observable digits or rounding the sample of the sample of statistical noise. For example, if the first number is five, the second number is two, and the generated sample of statistical noise is 0.98654, and the answer to the query is 1, then the randomized result by the mechanism becomes 1 + 0.98654 which may be reduced to 1.98 (if cut after the second observable digit) or 1.99 (if rounded). The advantage of this feature is to make differential privacy mechanisms robust to floating point attacks while allowing customization of the granularity of the results, i.e., the number of digits after the radix point. According to some aspects, the first natural number is larger than the second natural number, preferably five times larger, and more preferably ten times larger. It has been found that these ratios enable enough to make differential privacy mechanism robust to floating point attacks while allowing customization of the granularity of the results, i.e., the number of digits after the radix point. However, it should be noted that the larger the first natural number is than the second natural number, the larger the computational cost. There is also disclosed herein an electronic device associated with the above-discussed advantages. The electronic device comprises at least one processing circuitry and a memory, the at least one processing circuitry being configured to perform any of the methods discussed above. There is also disclosed herein a computer program product associated with the above- discussed advantages. The computer program product comprising instructions which, when executed on at least one processing circuitry, cause the at least one processing circuitry to carry out any of the methods discussed above. There is also disclosed herein a computer program carrier associated with the above- discussed advantages. The computer program carrier carries a computer program product according to the discussion above. The computer program carrier is one of an electronic signal, optical signal, radio signal, or computer-readable storage medium. Generally, all terms used in the claims are to be interpreted according to their ordinary meaning in the technical field, unless explicitly defined otherwise herein. All references to "a / an / the element, apparatus, component, means, step, etc." are to be interpreted openly as referring to at least one instance of the element, apparatus, component, means, step, etc., unless explicitly stated otherwise. The steps of any method disclosed herein do not have to be performed in the exact order disclosed, unless explicitly stated. Further features of, and advantages with, the present disclosure will become apparent when studying the appended claims and the following description. The skilled person realizes that different features of the present disclosure may be combined to create embodiments other than those described in the following, without departing from the scope of the present disclosure. BRIEF DESCRIPTION OF THE DRAWINGS With reference to the appended drawings, below follows a more detailed description of embodiments of the present disclosure cited as examples. In the drawings: Figure 1 is a schematic block diagram illustrating an example system; Figure 2 is a schematic block diagram illustrating an exemplary device; and Figures 3-4 are a schematic block diagrams illustrating respective exemplary methods; Figures 5-6 are a schematic block diagrams illustrating respective differential privacy mechanisms. DETAILED DESCRIPTION The present disclosure will now be described more fully hereinafter with reference to the accompanying drawings, in which certain aspects of the present disclosure are shown. The present disclosure may, however, be embodied in many different forms and should not be construed as limited to the embodiments and aspects set forth herein; rather, these embodiments are provided by way of example so that this disclosure will be thorough and complete, and will fully convey the scope of the present disclosure to those skilled in the art. Like numbers refer to like elements throughout the description. It is to be understood that the present disclosure is not limited to the embodiments described herein and illustrated in the drawings; rather, the skilled person will recognize that many changes and modifications may be made within the scope of the appended claims. As mentioned, there are known attacks that exploits vulnerabilities of the implementation of differential privacy mechanisms. Implementations of DP algorithms can suffer from serious vulnerabilities based on how computers represent numbers when sampling statistical noise. This is discuss in, e.g., Mironov, Ilya, "On significance of the least significant bits for differential privacy", In Proceedings of the 2012 ACM conference on Computer and communications security, pp. 650-661, 2012, and in Gazeau, Ivan, Dale Miller, and Catuscia Palamidessi, "Preserving differential privacy under finite-precision semantics", Theoretical Computer Science 655 (2016): 92-108. Mironov shows that using floating-point numbers, as indicated by the IEEE Standard for Floating-Point Arithmetic (IEEE 754), when sampling from a Laplace distribution creates “holes” in the distribution, i.e., certain floating-point values are never generated as noise. In other words, certain floating-point numbers have probability zero of being generated as noise. These values may then be used to attack, and nullify, the privacy guarantees provided by DP algorithms. Such attack is called a floating point attack or Mironov’s attack. An adaptation to Mironov’s attack has been encountered when statistical noise comes from Gaussian distributions which use floating point arithmetic, see, e.g., . Jin, Jiankai, Eleanor McMurtry, Benjamin IP Rubinstein, and Olga Ohrimenko, "Are we there yet? timing and floating-point attacks on differential privacy systems", In 2022 IEEE Symposium on Security and Privacy (SP), pp.473-488, IEEE, 2022. New differential privacy mechanisms have been proposed to address these attacks, such as the ones discussed by Mironov (cited above). However, such new mechanisms cannot be easily generalized to sample statistical noise from more than one kind of distribution and requires a re-analyzation of privacy and accuracy guarantees. Furthermore, such new solutions still rely on using floating-point representation, and may therefor still be sensitive to other vulnerabilities related to floating-point representation like precision-based attacks as presented by Samuel Haney, Damien Desfontaines, Luke Hartman, Ruchit Shrestha, and Michael Hay, “Precision-based attacks and interval refining: how to break, then fix, differential privacy on finite computers”, in Theory and Practice of Differential Privacy Workshop, 2022. The present disclosure therefore presents a method for generating a sample of statistical noise to be used in a differential privacy mechanism and to a method for obtaining a randomized result of a query using said sample of statistical noise. The disclosed methods are resilient to floating-point and precision-based attacks, and can be used by differential privacy mechanisms. The disclosed method of generating a sample of statistical noise introduces a new parameter for the generation of noise for differential privacy mechanisms. This parameter, which may be called a precision parameter, is indicative of a precision of a sample of the statistical noise. For example, the parameter may correspond a first natural number of significant digits for computing an aggregation operation in the differential privacy mechanism. Figure 1 shows a schematic block diagram illustrating an example system. In Figure 1, reference numeral 100 may be a system for generating a sample of statistical noise to be aggregated with a result of a query in a differential privacy mechanism, of for randomization of a query using said sample of statistical noise. The system comprise an electronic device 101 arranged to perform calculations and operate data analyses on data sets and / or accuracy estimations of data analyses and on data sets and data structures. Data analyses may for instance be statistical analyses and machine learning analyses but other types of analyses incorporating differential privacy mechanisms and noise generation may be performed as well. The electronic device is optionally connected to a display 102 for interacting with a user and displaying settings and results from provided functionality. The electronic device 101 may be arranged to receive information about data analyses to be performed, information about data sets, data sets, data structure information, or parameters relating to data analyses from a remote query device 110 communicating with the electronic device via a digital communications network 120 and network communication lines 115. Furthermore, the electronic device may be arranged to transmit results to the remote device in the same manner. It should be noted that the electronic device may receive data sets, data analyses, and / or data structure information using other means, such as using portable memory modules such as universal storage bus modules or similar. The network communication may be based on Ethernet or other communication protocols using wired or wireless technologies as physical transmission media. Using a communications interface the electronic device may receive relevant information for performing generation of a sample of statistical according to the present solution from remote devices and can optionally provide the sample of statistical noise as a service to different entities and the remote entities may perform further processing, such as randomizing a query using the sample of statistical noise. However, the electronic device may also be arranged to perform the randomization of a query. As can be seen in Figure 2, the electronic device 101 comprises at least one processing circuitry 210, which may be one or more processors or processing units, one or more memory 211 for storing data and / or instruction sets for operating functionality, at least one communication interface 215, and optionally a user interface (UI) 216 interface. The least one processing circuitry comprises one or several modules for operating different types of functionality, such as an instruction set operation module 220 arranged to operate calculations and other functionality of the processing unit and a communication module 230 for handling receiving and transmitting data via the digital communications network 120. Furthermore, the processing circuitry 210 may comprise a user interface module 240 for handling user interface functionality such as displaying data and functionality on a display 102 and / or receiving user instructions from a keyboard, mouse or other user interface devices (not shown). The at least one processing circuitry 210 may comprise any suitable processor or combination of processors arranged to operate instruction sets for operating software functions. For example, the processing unit may be a central processing unit (CPU), microprocessor, digital signal processor (DSP), a graphical processing unit (GPU), a field programmable gate array (FPGA), application specific integrated circuit (ASIC), or any other similar device arranged to operate processing functionality and calculations. Memory 211 of the electronic device 101 can include one or more non-transitory computer- readable storage mediums, for storing computer-executable instructions, which, when executed by processing circuitry 210, for example, can cause the computer processors to perform the techniques described below. A computer-readable storage medium can be any medium that can tangibly contain or store computer-executable instructions for use by or in connection with the instruction execution system, apparatus, or device. In some examples, the storage medium is a transitory computer-readable storage medium. In some examples, the storage medium is a non-transitory computer-readable storage medium. The non- transitory computer-readable storage medium can include, but is not limited to, magnetic, optical, and / or semiconductor storages. Examples of such storage include magnetic disks, optical discs based on CD, DVD, or Blu-ray technologies, as well as persistent solid-state memory such as flash, solid-state drives, and the like. The computer-readable storage medium stores one or more programs configured to be executed by the one or more processors of an electronic device, the one or more programs including instructions or instruction sets for performing functions and methods as described in this document. The electronic device 101 is arranged to operate instruction sets and functionality for operating the method of generation of the sample of statistical noise and / or for obtaining a randomized result of a query using said sample of statistical noise. Differential privacy is a quantitative notion of privacy that bounds how much a single individual's private data can affect the result of a data analysis. Formally, differential privacy is a property of a randomized query ^̃^(∙). A query ^^ is a deterministic function representing adata analysis, where ^^ takes a dataset ^^ in ^^^^ and returns a vector in ℝ^^, i.e., ^^: ^^^^ → ℝ^^.Here, ℝ^^is the space of all n-dimensional vectors of real numbers. The randomized query canbe defined as ^̃^(^^) = ^^(^^) + ^^, where ^^ is a sample of statistical noise, and ^^ is a dataset in^^^^. Thus, ^̃^(∙) ∶ ^^^^ → ℝ^^.Definition (Differential Privacy)A randomized query ^̃^(∙) satisfies (^^, ^^)-differential privacy if and only if for any two datasets^^1and ^^2 in ^^^^, which differ in one row, and for every output set ^^ ℝ^^, it holds thatPr[^̃^(^^1) ∈ ^^] ≤ ^^ ^^ ∙ Pr[^̃^(^^2) ∈ ^^] + ^^.In the definition above, the parameters ^^, ^^ determine a bound on the distance between thedistributions induced by ^̃^(∙) when adding or removing an individual from the dataset. Whenthe equation above is fulfilled for predetermined ^^ ≥ 0 and 1 ≥ ^^ ≥ 0, it can be said that therandomized query meets predetermined differential privacy guarantees.When the parameter ^^ = 0, the definition above is referred as pure differential privacy, whilewhen ^^ > 0 is called approximated differential privacy.To protect all the different ways in which an individual's data can affect the result of a query, the noise should to be calibrated to the maximal change that the result of the query can have when changing an individual's data. This is formalized through the notion of sensitivity. Definition (Sensitivity)The (global) sensitivity of a query ^^ is the quantity Δ^^ = max{|^^(^^1) − ^^(^^2)|} for two datasets^^1and ^^2in ^^^^, which differ in one row. A standard way to achieve differential privacy is adding some calibrated noise to the result of a query, where it is also important the choice of the kind of noise that one adds. A standard approach to achieve pure differential privacy is based on the addition of noise sampled from the Laplace distribution. A standard approach to achieve approximated-DP is based on the addition of noise sampled from the Gaussian distribution. Theorem (Laplace mechanism)Let ^^ ∶ ^^^^ → ℝ^^ be a deterministic query with sensitivity Δ^^. Let ^̃^(∙) ∶ ^^^^ → ℝ^^be arandomized query defined as ^̃^(^^) = ^^(^^) + ^^, where is sample from the Laplacedistribution with mean ^^ = 0 and scale ^^ = Δ^^ / ^^. Then, ^̃^(∙) is (^^, 0)-differentially private, orsimply ^^-differentialy private. The function generating such sample from the Laplacedistribution may be written as Lap(Δ^^ / ^^), Lap(Δ^^ , ^^), or Lap(^^) where ^^ may, e.g., be ^^ = Δ^^ / ^^.The Laplace mechanism may be written as LapMech = ^^(^^) + Lap(Δ^^ / ^^).Theorem (Gaussian mechanism)Let ^^ ∶ ^^^^ → ℝ^^ be a deterministic query with sensitivity Δ^^. Let ^^ ≥ 0 and 1 ≥ ^^ ≥ 0 berespective parameters. Let ^̃^(∙) ∶ ^^^^ → ℝ^^ be a randomized query defined as ^̃^(^^) = ^^(^^) +^^, where ^^ is sample from the Gaussian distribution with mean ^^ = 0 and standard deviation ∙ log (1.25 / ^^) / ^^. Then, ^̃^(∙) is (^^, ^^)-differentialy private. The function generatingsuch sample from the Gaussian distribution may be written as Gauss . The Gaussianmechanism may be written as GaussMech = ^^(^^) + Gauss ^^, ^^).Floating-point attack example Below is an example of a floating point attack. We assume a counting query ^^ over a dataset ^^ that returns 0 and 1. In this scenario, the Mironov’s attack looks at the floating point number returned by the differential privacy LaplaceMechanism ^̃^(^^) and figures out if it came from 1 + noise(^^) or 0 + noise(^^), for some ^^uniformly sampled number ^^ between 0 and 1. Function noise(^^) is a function that implements an inverse sampling method – a method that samples from a uniform distribution, and transforms those numbers in a way that the results have the desired distribution, like Laplace. Mironov’s attack follows the following steps. 1. Observe the noisy result ^^ = ^̃^(^^) 2. Is ^^ = 0 + noise(^^), for some uniform random floating-point number ^^ between 0and 1? 3. If no, we can guess that ^^(^^) = 14. If yes, is ^^ = 1 + noise(^^), for some uniform random floating-point number ^^between 0 and 1? 5. If no, we can guess that ^^(^^) = 06. If yes, we cannot guess if ^^(^^) = 0 or ^^(^^) = 1.Following the attack above, we have that if we see the number 4.699548742745464 generatedby the Laplace Mechanism with ^^ = 1 / 10 and Δ^^ = 1, this number could only have beenobtained by 1 + noise(^^) and not as 0 + noise(^^) for some random number ^^ and ^^ between0 and 1.So, in other words, given a counting query ^^, and a privacy parameter ^^ = 1 / 10, the LaplaceMechanism thenPr[^̃^(^^1) = 4.699548742745464] = 0, butPr[^̃^(^^2) = 4.699548742745464] > 0.It is the fact that some numbers cannot be generated by the mechanism that gives room to perform the attack. Exact arithmetic The present disclosure uses exact arithmetic to represent real numbers. By doing so, the Mironov’s attack above is no longer possible. Exact arithmetic is a method to compute numbers within some specified error. We note that exact arithmetic for real numbers is not the same as fixed arbitrary precision reals. There are many methods to achieve exact arithmetic for real numbers. For instance, Continued Fractions as described by Jean E. Vuillemin. “Exact real computer arithmetic with continued fractions”, IEEE Transactions on Computers, 39(8):1087- 1105, 1990, B-adic number stream as described by Valérie Ménissier-Morain, “Arbitrary precision real arithmetic: design and algorithms”, Journal of Symbolic Computation, 1996, Linear Franctional Transformations as described by Abbas Edalat and Peter John Potts, “A new representation for exact real numbers”, Electronic Notes in Theoretical Computer Science, 6, 1997, and Fast Binary Cauchy Sequences as described by Paul Gowland and David Lester, “The Correctness of an Implementation of Exact Arithmetic”, In Proceedings of the Fourth Real Numbers and Computers Conference, 2000. Such methods entail to run a series of computations by prescribing only the precision of the end-result, where the precision of intermediate results is automatically determined. Definition (Fast Binary Cauchy Sequence) One way of representing a number using real arithmetic is by a Fast Binary Cauchy Sequence. A computable real number x is represented by a Fast Binary Cauchy Sequence if there is aninfinite computable sequence of integers ^^0, ^^1, … , ^^^^, …. such|^^ − 2−^^^^^^| < 2−^^Here, ^^ is an integer corresponding to the ^^-element of the sequence of integers. The further the ^^-element in the sequence of integers, the more precision, or closer, the approximation is from the computable real number ^^. We follow the notation, vocabulary, and approach to exact arithmetic by Paul Gowland and David Lester, “The Correctness of an Implementation of Exact Arithmetic”, In Proceedings of the Fourth Real Numbers and Computers Conference, 2000. We should think of real numbers as a infinite sequence of integers; so we represent number xas a function ^^^^ such that ^^^^(^^) = ^^^^2−^^. Intuitively, such approach about composing infinite sequences denoting real numbers. Aninteresting part is to compute an aggregation ^^ + ^^ as approximated by the ^^-element fromother computable reals, namely ^^ and ^^, requires the operands to be approximated further than ^^ in their correspondent fast binary Cauchy sequences. For instance, if we consider twonumbers ^^ and ^^ represented by functions ^^^^ and ^^^^, then their addition ^^ + ^^ is representedby the following function: Here, we can see that to approximate the sum by the ^^-element, we need the approximationof the operands by the (^^ + 2)-elements. We see that the definition of ^^^^+^^ contains a rationalnumber between the rounding brackets ⌊∙⌉. The operator ⌊∙⌉ takes the rational back into an integer by rounding the integer, i.e., 1.2 goes to 1, 1.8 goes to 2. However, when we have a number like 1.5, where there is a tie, the operator rounds-up only when the result will be an even number; otherwise it rounds down. For instance, 2.5 goes to 2, but 3.5 goes to 4. Paul Gowland and David Lester, in their work “The Correctness of an Implementation of Exact Arithmetic” , define operations like multiplication, negation, square root, and, more importantly, transcendental functions like ln(^^), ^^^^, sin(^^), by approximating power series. The algorithm for power series is involved but the important aspect to notice is that if we want ln(^^) at as approximated by the ^^-element, we need to consider ^^ as approximated by the ^^′-element,where ^^′ > ^^.Generation of noise for the Laplace mechanism using exact arithmetic Below follows an example of the present disclosure where generation of noise for the Laplace mechanism uses exact arithmetic. This particular way of sampling from a Laplace distribution is an example of inverse transform sampling. For simplicity, we are going to consider counting queries, i.e., queries with sensitivity one. The sample of noise ^^ for aggregating to a query is denoted Lap(^^). In that case, consider the following algorithm using exact real arithmetic operations to sample from a Laplace distribution. Lap(^^) = (2^^ − 1) ^^ln(1 − ^^)where ^^ ← ^^[0,1), and ^^ ← ^^{0,1}. This is the algorithm to sample from the Laplace distribution by sampling from the uniformdistribution between 0 and 1, i.e., ^^[0,1). Sampling ^^ ← ^^{0,1} uniformly from two values (i.e.,0 and 1) is trivial. Finally, computing (2^^ − 1)^^ln(1 − ^^) is supported by the real arithmeticoperators proposed as fast Binary Cauchy Sequences as described by Paul Gowland and David Lester in their work “The Correctness of an Implementation of Exact Arithmetic.” The function Lap(^^) returns a real number that can be approximated at any precision. In this light, we can represent Lap(^^) with a corresponding function that returns an approximation at precision ^^, that is, ^^^^^^^^(^^)(^^). We observe that if we want to observe a sampling from the Laplace distribution as approximated by the ^^-element, then we need to generate a uniformnumber that gets approximated by a ^^′-element, where ^^′ > ^^. The number ^^′ is determinedby how power series are used to approximate ln(1 − ^^) and the rest of the arithmeticoperations involved in the expression Lap(^^). We do not need to sample an infinite number of random bits to generate a uniform number between 0 and 1 since whatever we would generate to be used as an element of the sequence higher than the ^^′-element is never going to be used to compute the sampling from the Laplace distribution as approximated by the ^^-element. Precision and digits The text below provides some considerations for precision of approximations and digits. Below, leading zeros in bounds is discussed.Given a computable real number ^^ = {^^0, ^^1, … , ^^^^, … }, then ^^^^(^^) has ^^ = ⌊^^ / log2(10)⌋ leadingzeros in its approximation bound to ^^.Proof. We know, by definition of fast binary Cauchy sequence, that − 2−^^^^^^| < 2−^^, so we need to know how many zeroes after the radix point 2−^^has. We establish the equation: 2−^^ = 10−^^ ⇔ So, we take ^^ = ⌊^^ / log2(10)⌋.We take the floor to not assume half- or a third-leading zeros. For instance, if p = 4, then (1) 1.2log2(10)= 1.20, which implies that 1 / 10 > (1 / 10 ). In this case, we have only one exactdigit after the radix point, e.g., 1 / 24 = 0.0625, which indeed has one leading zero. Similarly, ifp = 8, then 8 log2(10)= 2.4, which implies that (1 / 102) > (1 / 102.4). In this case, we have twoleading zeros and in fact, 1 / 28 = 0.0039.Below, significant digits is discussed. We call significant digits of a computable real ^^ represented by a fast binacy Cauchy sequence ^^^^to the number of digits in ^^^^(^^) which coincide with the leading zeros in the bound 1 / 2^^. For instance, if ^^ is 8, then we say that ^^^^(^^) has two significant digits, since 1 / 28 = 0.0039.Below, significant digits and p-elements are discussed.Given a computable real number ^^ = {^^0, ^^1, … , ^^^^, … }, and we want an approximation of ^^ with^^ significant digits, then we should look, at least, to the approximation ^^^^(^^) where ^^ ≥⌈^^log2(10)⌉. For instance, if ^^ = 5, then ^^ = 16.6, so we rounded to ^^ = 17 and we observethat 1 / 217 = 0.000007629.Below, required bits for an approximation between 0 and 1 at precision p is discussed.Given the computable real number ^^, where ^^ (^ ) −^^^^ ^ = ^^^^ 2 and 0 ≤ ^^^^(^^) < 1, then integer ^^^^needs to have, at least, ^^ bits. To show that, we know that 0 ≤ ^^^^2−^^ < 1 by definition,therefore 0 ≤ ^^ < 2 ^^, so the biggest integer that sati ^^^^ sfies such inequality is ^^^^ = 2 − 1 andto represent it, it ^^ bits are needed. Avoiding floating-point attacks when using exact arithmetic We are going to show that there are no more attacks like those occurring with floating-point representation by (i) adopting a Laplace mechanism that uses exact arithmetic, and (ii) reduces the number of digits after the radix point. The radix point is the point that separates integers from fractions. In base 10, the radix point is commonly called the decimal point. The some reason why the Mironov’s attack is no longer possible are: a) exact arithmetic allows us to build arithmetic expressions that we can approximate as much as we want by simply determining the ^^-element to observe in a sequence, b) limiting the digits observed after a radix point of noisy results produced by the Laplace mechanism, written ^^^^, and c) the result of the mechanism gets computed with more significant digits than the observed digits, written ^^^^ where ^^^^ ≫ ^^^^. We write ^^ ≫ ^^ to indicate that number^^ is much bigger than ^^. Below follows a theorem.Consider a counting query ^^, datasets ^^0 and ^^1, a privacy parameter ^^, where ^^(^^0) = 0 and^^(^^1) =1, a number of observable digits ^^^^ for the Laplace Mechanism using exact arithmeticwhich results are computed with significant digits ^^^^, where ^^^^ ≫ ^^^^, and a maximum precision^^ for sampling random bits to create uniform numbers ^^ to be used in the inverse transformsampling such that ^^ ≫ ⌈^^^^ log2(10)⌉. Given a result of the mechanism applied to some of thedatasets ^^^^ = ^^(^^^^) + Lap(^^ ), where ^^ = ∆^^ / ^^, and the reduced version of such result being^^∗ = ^^^^^^^^^^^^(^^^^, ^^^^), then there exists an uniform number ^^1−^^, and a ^^ ∈ {0,1} such that^^∗ = ^^^^^^^^^^^^(^^(^^1−^^) + (2^^ − 1)^^ln(^^1−^^), ^^^^)The theorem says that if we get a result of the mechanism using real arithmetic with a certain dataset ^^^^with certain digits ^^^^after the radix point, the same result could have been obtained by applying the same mechanism to the other dataset up to ^^^^observable digits, where the injection of statistical noise has been calculate with more significant digits than the digits being observed, and the random noise is generated at a higher precision that those required to provide such significant digits. To prove this, we rely on exact arithmetic. First, we consider the fast binary Cauchy sequence produced by the mechanism, that is ^^^^, and establish the following equation ^^^^ = ^^(^^1−^^) + (2^^ − 1)^^ln(^^1−^^)and proceed to manipulate the expression to build the following fast binary Cauchy sequence ^^^^ − ^^(^^1−^^) = (2^^ − 1)^^ln(^^1−^^) At this point, we known that there exists ^^ = 0 or ^^ = 1 such that 0 ≤ ^^1−^^ < 1. That choicedepends on the magnitude of noise that has been used to generate ^^^^and the sign of that noise, that is, if the noise has been positive of negative. Since these parameters are unknowninformation, we simply try with both ^^ = 0 or ^^ = 1. For simplicity, we assume that with ^^ = 1and 0 ≤ ^^1−^^ < 1. We note that an analogous reasoning occurs when ^^ = 0. Simplifying thelast equation we have that As with ^^^^, we need to approximate ^^1−^^at precision ^^, that is, we need to obtain andwe can define(^^^^−^^(^^1−^^)) / ^^ To compute ^^ at precision ^^ might entail, due to how fast binary Cauchy sequences are built, to compute ^^^^with more significant digits than ^^^^, which in turn might entail to compute at a higher precision than ^^, which is not possible since the mechanism works on sampling ^^ random bits. However, this situation is avoided by reducing the number of digits produced by the Laplace mechanism to ^^^^, that is,^^∗ = ^^^^^^^^^^^^(^^^^, ^^^^). So, the equation above can be rewritten as follows. Since ^^^^ ≫ ^^^^, and ^^ ≫ ⌈^^^^ log2(10)⌉, we can be certain that ^^(^^) is defined so ^^ )(^^)does ^^1−^^at precision ^^. From this equation follows that, ^^∗ = ^^(^^1−^^) + ^^ln(^^1−^^)and thus ^^^^^^^^^^^^(^^(^^1−^^) + (2^^ − 1)^^ln(^^1−^^), ^^^^) = ^^^^^^^^^^^^(^^∗, ^^^^) = ^^∗. The proof shows that we always have a positive probability that a given result comes from either applying the query to ^^0or ^^1. This fact removes the floating-point attacks reported in literature when using the disclosed method of implementing the Laplace mechanism using exact arithmetic for generating and aggregating noise as well as reducing the number of digits of the produced noisy results. The proof above shows the following concept: the observable digits returned by the mechanism should be much less than the significant digits from which the Laplace mechanism computes randomized responses, which in turn is much less than the precision used to sample random uniform numbers. Examples of ^^^^, ^^^^, and ^^. Below we present some concrete parameters for the disclosed method. ^^^^^^^^^^ 2 10 70 2 10 127 4 20 127 10 40 300 The table above has been validated experimentally and coincides with the disclosedassumptions, namely that ^^^^ ≫ ^^^^ and ^^ ≫ log2(10)⌉.Generation of noise for the Gaussian mechanism using exact arithmetic There are known sampling methods to generate normally distributed random numbers, given a source of uniformly distributed random numbers. These are the Box–Muller transform, Marsaglia polar method, or Ziggurat algorithm. All of them consider two independent samples from a uniform distribution between 0 and 1. To describe how to adapt these methods to use exact arithmetic and being used by the Gaussian mechanism, it is enough to show how to apply it to the basic form of the Box-Muller transform. Below, the Box-Muller transform is discussed. Assuming two random numbers sampled from two independently distributed uniformdistribution, that is, ^^1 ← ^^(0,1), and ^^2 ← ^^(0,1), defining Then, numbers ^^0and ^^1are samples of an independent random variables with a standard normaldistribution, that is, with mean being zero, written ^^ = 0, and standard deviation being one, written^^ = 1. We write that ^^(^^, ^^2) to represent a random variable with mean ^^ and standard deviation^^. In other words, in the Box-Muller transform, number ^^0is a sample from a random variable ^^0~ ^^(0,1), where symbol ~ is used to specify the distribution of random variables. Similarly, number ^^1is a sample from a random variable ^^1~ ^^(0,1). To generate noise to be used in the Gaussian Mechanism with parameters ^^ and ^^, it is necessary to provide numbers that are being sampled from a normal distribution with mean^^ = 0 and ^^ = Δ^^√2 ∙ log (1.25 / ^^) / ^^, where Δ^^ is the sensitivity of the query Q considered bythe mechanism. It is worth noting that the Box-Muller transform generates two samples in one go, but the Gaussian Mechanism will use one at a time. More specifically, the Gaussian Mechanism uses the Box-Muller transform to generate two samples ^^0and ^^1, and proceed to use the firstsample to generate the statistical noise ^^0 Δ^^√2 ∙ log (1.25 / ^^) / ^^, a number which is sampledfrom the required normal distribution for the Gaussian Mechanism, and aggregates it to the result of the query Q. Next time that the Guassian Mechanism is used, it proceeds to use thesecond sample ^^1 to randomize its response with the statistical noise ^^1 Δ^^√2 ∙ log (1.25 / ^^) / ^^.Next time that the Guassian Mechanism is used, it will use the Box-Muller transform to generate two fresh samples ^^0and ^^1, and proceed to use the first sample to randomize the response of query Q as described before. All the arithmetic shown form the Box-Muller transform and Gaussian Mechanism can be formulated using fast binary Cauchy sequences. Putting all together, and assuming a dataset ^^, the result generated by the Gaussian Mechanism either uses the sample number ^^0or ^^1from the Box-Muller transform. We call to such cases ^^0and ^^1, respectively, ^^0 = ^^(^^) + ^^0 Δ^^√2 ∙ log (1.25 / ^^) / ^^^^1 = ^^(^^) + ^^1 Δ^^√2 ∙ log (1.25 / ^^) / ^^Unfolding the definition of ^^0or ^^1, we have that ∙log (1.25 / ^^) / ^^ ∙ log (1.25 / ^^) / ^^Avoiding floating-point attacks when using exact arithmetic in the Gaussian Mechanism Similar as we did for the Laplace mechanism to avoid floating-point attacks, we need to consider the number of observable digits ^^0after the radix point, the number of significant digits of the mechanism ^^^^for computing the results as indicated by ^^0and ^^1, and the maximum precision ^^ for sampling random bits to create uniform numbers ^^1and ^^2. As withthe Laplace Mechanism, we require that ^^^^ ≫ ^^0.The parameter ^^, which determines the number of random bits to sample, needs to consider the fact that the Box-Muller transform generates two samples in tandem, and aspect that is shared with other methods to generate normally distributed noise. More specifically, to obtain ^^^^significant digits when computing ^^0imposes some minimum precision for both ^^1and ^^2. Similarly, when computing ^^1with ^^^^significant digits entail a minimum precision for ^^1and ^^2.As in the Laplace Mechanism, it is still enough to pick a parameter ^^ where ^^ ≫ log2(10)⌉,but ensuring that ^^ is also big enough to ensure ^^^^significant digits for both ^^0and ^^1. Figures 3-6 To summarize, the disclosed method for generating a sample of statistical noise generates a sample of noise from a desired distribution, such as Laplace or Gaussian. The generation is further based on privacy parameters (e.g., ^^, ^^) and the sensitivity (e.g. ∆^^) of the query. The disclosed noise sampler generates statistical noise suitable for ensuring DP-guarantees according to the given privacy parameters with the addition of a quantity to account for the chosen precision. Figure 3 illustrates an overall view of a computer-implemented method 300 for generating a sample of statistical noise ^^ to be aggregated, by an aggregation operation, with a result of a query ^^ in a differential privacy mechanism. This query ^^ may be a query according to thediscussions above. In particular, this query ^^ is a deterministic query where ^^ ∶ ^^^^ → ℝ^^.The method may be performed in an electronic device as discussed previously in this document. The method comprises a number of actions for operating different functions, which are described below. Action 310 obtaining data indicative of a statistical noise distribution. The statistical distribution may, e.g., be a Laplace distribution or a Gaussian distribution. The data indicative of a statistical noise distribution may comprise a flag indicating a distribution. For example, the data may be a 0 for indicating a Laplace distribution and may be a 1 for indicating a Gaussian distribution. The statistical noise distribution indicated by the data is the distribution from which the sample of statistical noise is generated from. Action 320 comprises obtaining one or more parameters indicative of desired differential privacy guarantee. These parameters may, e.g., be any of ^^ and ^^ according to the discussions above. For example, wherein the one or more parameters indicative of desired differential privacy guarantee may comprises parameters ^^ and ^^, where a randomized query, ^̃^, is guaranteed^^, ^^-differential private if and only if for any two datasets ^^1 and ^^2 in a set ^^^^, which differ inone row, and for every output set ^^ ⊆ ℝ^^, it holds that Pr[^̃^(^^1) ∈ ^^] ≤ ^^ ^^ ∙ Pr[^̃^(^^2) ∈ ^^] +^^, where ℝ^^is the space of all n-dimensional vectors of real numbers, and where the randomized query ^̃^ takes a dataset in ^^^^ and returns a vector in ℝ^^. Note that ^^ may be zero. Also note that ^^ may be equal to one. In that case, the vector is a single number.The parameters ^^ and ^^ may be respective values where ^^ ≥ 0 and 1 ≥ ^^ ≥ 0. Preferably,these parameters are represented by respective Cauchy sequences or are in any form (natural number, rational number etc.) that can be converted into a fast binary Cauchy sequence. Action 330 comprises obtaining a parameter indicative of a sensitivity of the query ^^ in the differential privacy mechanism. This parameter may, e.g., be ∆^^according to the discussions above. For example, if ∆^^is the parameter indicative of a sensitivity of the query executed in thedifferential privacy mechanism, it may be is selected as ∆^^= max{|^^(^^1) − ^^(^^2)|}, where ^^1and ^^2are two datasets in a set ^^^^, which differ in one row, where the ^^ is the query and is adeterministic function which ^^^^ → ℝ^^, where ℝ^^ is the space of all n-dimensional vectors ofreal numbers.The parameter ∆^^ may be a value positive, that is, ∆^^> 0. Preferably, this parameter isrepresented by a Cauchy sequence or is in any form (natural number, rational number etc.) that can be converted into a fast binary Cauchy sequence. Action 340 comprises obtaining a parameter indicative of a first natural number ^^^^of significant digits for computing the aggregation operation in the differential privacy mechanism. Alternatively, or in addition, the parameter is indicative of second natural number ^^^^of observable digits after the radix point for a result of the aggregation operation in the differential privacy mechanism. This first natural number may, e.g., be ^^^^according to the discussions above. This second natural number may, e.g., be ^^^^according to the discussions above. Action 350 comprises generating the sample of the statistical noise from the statistical distribution based on the one or more parameters ^^, ^^ indicative of desired differential privacy guarantee, the parameter ∆^^indicative of a sensitivity of the query ^^, and the parameter indicative of the first natural number ^^^^and / or the second natural number ^^^^. The sample of statistical noise η is generated using exact real arithmetic based on a Cauchy sequence. The generated sample may be in the form of a fast binary Cauchy sequence. Also, any potential intermediate step may also use numbers in the form of respective fast binary Cauchy sequences when generating the sample. For example, in the inverse sampling method from a Laplace distribution according to the discussions above, the random number ^^ (discussed above) may be represented as a fast binary Cauchy sequence. Thus, the method generates statistical noise suitable for ensuring DP-guarantees according to the given privacy parameters with the addition of a quantity to account for the chosen precision. The generated sample is thus suitable for randomizing a query, i.e., to be aggregated with a result of a query, which thereafter will be insensitive to precision attacks. According to some aspects, a minimum length, represented by a third natural number p, of a Cauchy sequence representing the statistical noise to be generated ^^ provides the first natural number ^^^^of significant digits for computing the aggregation operation in the differential privacy mechanism. Action 351. The statistical distribution may be a Laplace distribution and the sample of statistical noise may be generated using inverse transform sampling. Inverse transform sampling (also called inverse sampling, the inverse transformation method, inverse probability integral transform) and is a method for generating random numbers from any probability distribution by using the inverse cumulative distribution of that probability distribution. Inverse transform sampling provides a computationally efficient way of generating a sample with a predetermined precision, in particular for Laplace distributions. Action 352. The statistical distribution may be a Gaussian distribution and the sample of statistical noise may be generated using the Box–Muller transform, as described in Box, G. E. P.; Muller, Mervin E., "A Note on the Generation of Random Normal Deviates", The Annals of Mathematical Statistics.29 (2): 610–611, 1958, the Marsaglia polar method, as described by Marsaglia, G.; Bray, T. A., "A Convenient Method for Generating Normal Variables", SIAM Review.6 (3): 260–264, 1964, or the Ziggurat algorithm, as described by George Marsaglia, Wai Wan Tsang (2000), "The Ziggurat Method for Generating Random Variables", Journal of Statistical Software. 5 (8), 2000. The Box-Muller transform sampling generates pairs of independent and normally distributed random numbers from uniformly distributed random numbers. The Marsaglia polar sampling (also called the Marsaglia polar method) generates a pair of independent normally distributed random numbers, and is more efficient than the Box- Muller transform sampling. The Ziggurat algorithm generates noise samples from uniformly distributed random numbers.Action 353. The sample of statistical noise may be generated as = (2^^ − 1)∆^^log(^^) / ^^,where ∆^^is the parameter indicative of a sensitivity of the query, ^^ is one of the one or more parameters indicative of desired differential privacy guarantee, ^^ is a random number generated from a uniform distribution between zero and one, i.e., ^^(0,1), and ^^ is a random number generated from a uniform distribution consisting of one and zero (^^).Action 354. The sample of statistical noise ^^ may be generated as = sgn(^^)∆^^log(1 − 2|^^|) / ^^, where ^^ = ^^ − 1 / 2, ∆^^ is the parameter indicative of a sensitivity of the query, ^^ is one ofthe one or more parameters indicative of desired differential privacy guarantee, and ^^ is a random number generated from a uniform distribution between zero and one, i.e., ^^(0,1). Action 355. In any of actions 353 and 354, the random number ^^ may be generated as Cauchy sequence, in particular as a fast binary Cauchy sequence. Actions 356, 357, and 358. In any of actions 353 and 354, the random number ^^ may be generated by obtaining 356 a uniformly sampled bit sequence comprising the third natural number ^^ of bits, obtaining 357 a fourth natural number based on the uniformly sampled bit sequence, and providing 358 ^^ by dividing the fourth natural number by 2 to the power of the third natural number ^^. In other words, ^^ is obtained from ^^ / 2^^, where ^^ is the fourth natural number. According to some aspects, the third natural number ^^ is larger the first natural number ^^^^, and preferably larger than the first natural number by at least a factor of the first natural number ^^^^ 2log (10). Figure 4 illustrates an overall view of a computer-implemented method 400 for obtaining a randomized result of a query ^^. The method may be performed in an electronic device as discussed previously in this document. The method comprises a number of actions for operating different functions. Action 410 comprise obtaining a result of the query ^^. Action 420 comprises aggregating a sample of statistical noise ^^ generated according to the method 300 to the obtained result of the query to obtain the randomized result of the query ^^. Here, aggregating typically means to add the sample of noise to the query. Any of the result of the query ^^, the generated sample of statistical noise ^^, and the randomized result of the query ^^ may be represented by a respective Cauchy sequence. According to some aspects, the aggregating 420 the sample of statistical noise ^^ to the obtained result of the query ^^ is computed with the first natural number ^^^^of significant digits. Action 430. The method 400 may further comprise truncating the randomized result of the query ^^ to a fourth natural number ^^^^of observable digits after the radix point, wherein the first natural number ^^^^is larger than the fourth natural number ^^^^. According to some aspects, the first natural number ^^^^is larger than the second natural number ^^^^, preferably at least five times larger, and more preferably at least ten times larger. Figures 5 and 6 shows two examples of respective differential privacy mechanisms 500 and 600 using the method 300 for generating a sample of statistical noise to be aggregated, and the method 400 for obtaining a randomized result of a query. These respective differential privacy mechanisms may be performed in an electronic device as discussed previously in this document. In particular, in Figure 5, a parameter indicative of the second natural number ^^^^of observable digits after the radix point for a result of the aggregation operation in the differential privacy mechanism, data indicative of a statistical noise distribution, one or more parameters ^^, ^^ indicative of desired differential privacy guarantee, and a parameter ∆^^indicative of a sensitivity of the query ^^ in the differential privacy mechanism are fed into the DP mechanism 500 and into the noise sampler 510. The second natural number ^^^^is further provided to a truncation function 530. The noise sampler 510 generates the sample of statistical noise ^^ from the statistical distribution based on the one or more parameters ^^, ^^ indicative of desired differential privacy guarantee, the parameter ∆^^indicative of a sensitivity of the query ^^ in the differential privacy mechanism, and the parameter indicative of the second natural number ^^^^. Furthermore, the noise sampler 510 provides the sample of statistical noise ^^ and a first natural number ^^^^of significant digits for computing the aggregation operation in the differential privacy mechanism to an aggregation operation 520. The first natural number ^^^^is derived from the generation of the sample of statistical noise together with the second natural number ^^^^. The aggregation operation 520 aggregates the sample of statistical noise ^^ to an obtained result of a query ^^, and provides a randomized result ^^ of the query ^^. The aggregation operation 520 is computed with the first natural number ^^^^of significant digits. The randomized result ^^ of the query ^^ is provided to a truncation function 530 that reduces the number of observable digits to the second natural number ^^^^. The reduced result ^^∗is thereafter outputted by the differential privacy mechanisms 500. In Figure 6, a parameter indicative of the first natural number ^^^^of significant digits for computing the aggregation operation in the differential privacy mechanism, data indicative of a statistical noise distribution, one or more parameters ^^, ^^ indicative of desired differential privacy guarantee, and a parameter ∆^^indicative of a sensitivity of the query ^^ in the differential privacy mechanism are fed into the DP mechanism 600 and into the noise sampler 610. The first natural number ^^^^is further provided to an aggregation operation 630. The noise sampler 610 generates the sample of statistical noise ^^ from the statistical distribution based on the one or more parameters ^^, ^^ indicative of desired differential privacy guarantee, the parameter ∆^^indicative of a sensitivity of the query ^^ in the differential privacy mechanism, and the parameter indicative of the first natural number ^^^^. Furthermore, the noise sampler 610 provides the sample of statistical noise ^^ to an aggregation operation 630. The noise sampler 620 further provides the second natural number ^^^^of observable digits after the radix point for a result of the aggregation operation in the differential privacy mechanism to a truncation function 630. The second natural number ^^^^is derived from the generation of the sample of statistical noise together with the first natural number ^^^^. The aggregation operation 620 aggregates the sample of statistical noise ^^ to an obtained result of the query ^^, and provides a randomized result ^^ of the query ^^. The aggregation operation is computed with the first natural number (^^^^) of significant digits. The randomized result ^^ of the query ^^ is provided to the truncation function 630 that reduces the number of observable digits to the second natural number ^^^^. The reduced result ^^∗is thereafter outputted by the differential privacy mechanisms 600.
Claims
CLAIMS 1. A computer-implemented method (300) for generating a sample of statistical noise (^^) to be aggregated, by an aggregation operation, with a result of a query (^^) in a differential privacy mechanism, the method comprising: obtaining (310) data indicative of a statistical noise distribution; obtaining (320) one or more parameters (^^, ^^) indicative of desired differential privacy guarantee; obtaining (330) a parameter (∆^^) indicative of a sensitivity of the query (^^) in the differential privacy mechanism; obtaining (340) a parameter indicative of a first natural number (^^^^) of significant digits for computing the aggregation operation in the differential privacy mechanism and / or indicative of second natural number (^^^^) of observable digits after the radix point for a result of the aggregation operation in the differential privacy mechanism; and generating (350) the sample of statistical noise (^^) from the statistical distribution based on the one or more parameters (^^, ^^) indicative of desired differential privacy guarantee, the parameter (∆^^) indicative of a sensitivity of the query (^^) in the differential privacy mechanism, and the parameter indicative of the first natural number (^^^^) and / or the second natural number (^^^^), wherein the sample of statistical noise (η) is generated (351) using exact real arithmetic based on a Cauchy sequence.
2. The method (300) according to claim 1, wherein a minimum length, represented by a third natural number (p), of a Cauchy sequence representing the statistical noise to be generated (^^) provides the first natural number (^^^^) of significant digits for computing the aggregation operation in the differential privacy mechanism.
3. The method (300) according to any previous claim, wherein the statistical distribution is a Laplace distribution or a Gaussian distribution.
4. The method (300) according to any previous claim, wherein the statistical distribution is a Laplace distribution and the sample of statistical noise is generated (351) using inverse transform sampling.
5. The method (300) according to any previous claim, wherein the statistical distribution is a Gaussian distribution and the sample of statistical noise is generated (352) using the Box– Muller transform, the Marsaglia polar method, or the Ziggurat algorithm.
6. The method (300) according to any of claims 1-4, wherein ^^ is the sample of statisticalnoise, and is generated (353) as= (2^^ − 1)∆^^log(^^) / ^^, where ∆^^ is the parameter indicativeof a sensitivity of the query, ^^ is one of the one or more parameters indicative of desired differential privacy guarantee, ^^ is a random number generated from a uniform distribution between zero and one (^^), and ^^ is a random number generated from a uniform distribution consisting of one and zero (^^).
7. The method (300) according to any of claims 1-4, wherein ^^ is the sample of statisticalnoise, and is generated (354)= sgn(^^)∆^^log(1 − 2|^^|) / ^^, where ^^ = ^^ − 1 / 2, ∆^^ is theparameter indicative of a sensitivity of the query, ^^ is one of the one or more parameters indicative of desired differential privacy guarantee, and ^^ is a random number generated from a uniform distribution between zero and one (^^).
8. The method (300) according to claim 6 or 7, wherein the random number ^^ is generated (355) as a Cauchy sequence.
9. The method (300) according to claim 8 when dependent on claim 2, wherein the random number ^^ is generated by obtaining (356) a uniformly sampled bit sequence comprising the third natural number (^^) of bits, obtaining (357) a fourth natural number based on the uniformly sampled bit sequence, and providing (358) ^^ by dividing the fourth natural number by 2 to the power of the third natural number (^^).
10. The method (300) according to claim 9, wherein the third natural number (^^) is larger the first natural number (^^^^) , and preferably larger than the first natural number by at least a factor of the first natural number (^^^^) times 2log(10).
11. A computer-implemented method (400) for obtaining a randomized result of a query (^^), the method comprising obtaining (410) a result of the query (^^), and aggregating (420) a sample of statistical noise (^^) generated according to the method according to any of claims 1-13 to the obtained result of the query (^^) to obtain the randomized result of the query (^^).
12. The method (400) according to claim 11, wherein any of the result of the query (^^), the generated sample of statistical noise (^^), and the randomized result of the query (^^) is represented by a respective Cauchy sequence.
13. The method (400) according to claim 11 or 12, wherein the aggregating (420) the sample of statistical noise (^^) to the obtained result of the query (^^) is computed with the first natural number (^^^^) of significant digits.
14. The method (400) according to any of claims 11-13, further comprising truncating (430) the randomized result of the query (^^) to the second natural number (^^^^) of observable digits after the radix point.
15. The method (400) according to claim 14, wherein the first natural number (^^^^) is larger than the second natural number (^^0), preferably at least five times larger , and more preferably ten times larger.
16. An electronic device (101) comprises at least one processing circuitry (210) and a memory (211), the at least one processing circuitry being configured to perform the method (300) of any of claims 1-10 and / or the method (400) of any of claims 11-15.
17. A computer program product comprising instructions which, when executed on at least one processing circuitry (210), cause the at least one processing circuitry to carry out the the method (300) of any of claims 1-10 and / or the method (400) of any of claims 11-15.
18. A computer program carrier carrying a computer program product according to claim 17, wherein the computer program carrier is one of an electronic signal, optical signal, radio signal, or computer-readable storage medium.
Citation Information
Patent Citations
Utility optimized differential privacy system
US20220215116A1