Conceptio › Archive › arXiv CS
arXiv CSopen access

$α$-Wasserstein Mechanism for Rényi Pufferfish Privacy

2026 · arxiv_cs
arXiv CS · Papers · License: Open Access · 2026
Open Source ↗Direct PDF ↓
cryptographycybersecurityprivacysecurity
cryptography, security, privacy, cybersecurity

α-Wasserstein Mechanism for Rényi Pufferfish Privacy

arXiv:2605.05723v1 [cs.CR] 7 May 2026

Ni Ding University of Auckland New Zealand [email protected]

Wenjin Yang Beijing Institute of Technology China [email protected]

Zijian Zhang Beijing Institute of Technology China [email protected]

Abstract This paper introduces the α-Wasserstein mechanism for achieving Rényi Pufferfish Privacy using Laplace and Gaussian noise. By leveraging Hölder’s inequality, we demonstrate that the scale parameter of the Laplace mechanism can be calibrated via an upper bound on the Wα metric to satisfy (α, ϵ)-Rényi Pufferfish Privacy for α ∈ (1, ∞]. We show that at the limit α = ∞, this framework recovers the established W∞ mechanism for ϵ-pufferfish privacy. This result is subsequently extended to the exponential mechanism. Furthermore, we propose a Wα mechanism for Gaussian noise for α ∈ (1, ∞), demonstrating that it generalizes existing results within the Rényi Differential Privacy framework. Experimental evaluations reveal that our α-Wasserstein mechanism significantly reduces noise power compared to the conventional W∞ -based approach, with the Gaussian mechanism providing superior utility over the Laplace mechanism. Notably, the mechanisms derived in this work achieve exact (α, ϵ)-Rényi Pufferfish Privacy without requiring additional relaxations, such as δ-approximations.

1

Introduction

Rooted in a rigorous mathematical framework of statistical indistinguishability, differential privacy provides a robust guarantee that the inclusion or exclusion of a single record remains probabilistically undetectable by bounding output variations within a privacy budget ϵ [1–3]. By ensuring that an adversary cannot reliably infer an individual’s presence or specific contribution from observable outputs, differential privacy has emerged as the gold standard for privacy-preserving data analysis. Due to its formal security properties, differential privacy is now widely deployed across various domains, including official statistics [4], machine learning [5] and healthcare [6]. The Pufferfish framework extends the principles of differential privacy to scenarios where the original data, such as a query response, exhibits probabilistic dependence on a secret [7, 8]. In this setting, the challenge lies in achieving statistical indistinguishability within the posterior data distribution following sanitization. To address this, the first noise calibration method was introduced by Song et al. (2017), who proposed setting the scale parameter b of zero-mean Laplace noise according to the ∞-order Wasserstein metric to satisfy ϵ-pufferfish privacy [9]. However, computing the ∞Wasserstein metric is complicated by its non-convex nature [10, 11]. To resolve these computational difficulties, Ding (2022) introduced a 1-order Wasserstein (Kantorovich) approach for both Laplace and Gaussian noise mechanisms [12]. While strict privacy constraints often degrade data utility—a primary concern in differential privacy literature [13, 14]—one may resort to relaxations such as Rényi measures. Similar to (ϵ, δ)-differential privacy, these relaxations bound the probability of a data breach within specified limits. Building on the principles of Rényi Differential Privacy [15], ϵ-pufferfish privacy has been extended to (α, ϵ)Rényi Pufferfish Privacy (RPP) [16], which originally utilized a W∞ mechanism scaled by the order α [16, Corollary 3.1]. However, because an order α < ∞ eases the stringent privacy requirements of ϵ-pufferfish privacy, and given that α plays a functionally identical role in the Wasserstein metric, Preprint.

it is logical to expect a Wasserstein mechanism of the same order. This intuition motivated the Wα mechanism proposed in [16, Section 4]. Nevertheless, this approach necessitates an additional relaxation via an approximate probability δ alongside the Rényi order α [16, Definition 4.1]. In this paper, we propose a Wα mechanism to achieve exact (α, ϵ)-Rényi Pufferfish Privacy (RPP) without requiring further relaxations. Our main contributions are summarized as follows: • Calibration of Laplace Mechanisms: By applying Hölder’s inequality, we derive a sufficient condition for calibrating Laplace noise via the α-Wasserstein metric. Specifically, we show that if the scale parameter b ensures the Wα metric is upper bounded by ϵ α−1 α , (α, ϵ)-Rényi pufferfish privacy is satisfied. In the limiting case where α = ∞, this recovers the existing ∞-Wasserstein mechanism for ϵ-pufferfish privacy [9]. We further extend this Wα metric approach to the exponential mechanism. • Gaussian Noise Refinement: For Gaussian mechanisms, we demonstrate that (α, ϵ)-Rényi pufferfish privacy is achieved by selecting a variance σ 2 such that the Wα(α−1) metric is upper bounded by αϵ . Under deterministic data settings (standard differential privacy), this condition aligns with the results in [15, Corollary 3] for (α, ϵ)-Rényi differential privacy. • Utility and Performance Analysis: Experimental results indicate that our proposed αWasserstein mechanism requires significantly smaller values for b and σ 2 compared to existing benchmarks in [16], leading to a substantial improvement in data utility. Furthermore, we demonstrate that for a fixed (α, ϵ)-Rényi pufferfish privacy level, the Gaussian mechanism requires considerably less noise power than the Laplace mechanism when the privacy budget ϵ is small. Finally, we outline several directions for future research, including the derivation of closed-form solutions for noise parameters, the exploration of operational interpretations for the range α ∈ (0, 1), and the development of W2 mechanisms utilizing Monge’s formulation for Gaussian priors. Organization The remainder of this paper is organized as follows. Section 2 defines the system model and provides the necessary mathematical foundations and privacy definitions. Section 3 introduces the proposed α-Wasserstein mechanism for Laplace, Gaussian, and exponential noise, followed by an evaluation of its performance through experimental results. Finally, Section 4 discusses potential directions for future research and concludes the paper. Notation We use capital letters to denote random variables (r.v.s) and lower case letters to denote the elementary event. Calligraphic letters refer to the alphabet of r.v.s. For example, x is an instance of r.v. X, that takes value in alphabet X . Denote PX (x) = Pr(X = x) the probability of outcome X = x when r.v. X takes the value x. We use PX = (PX (x) : x ∈ X ) to denote a probability distribution and X ∼ PX means that r.v. X follows distribution PX . The support of PX (·) is denoted by supp(PX ) = {x ∈ X : PX (x) > 0}. The expected value R of f (X) for some deterministic function f w.r.t. probability PX is denoted by EX∼PX [f (X)] = PX (x)f (x) dx. The conditional probability PY |X (y|x) = Pr(Y = y|X = x) denotes the chances of having Y = y given the outcome X = x. PY |x = (PY |X (y|x) : y ∈ Y) refers to the probability distribution of Y conditioned on X = x. For two probability distributions PX and QX , the Rényi divergence [17] is Z α PX 1 (x) Dα (PX ∥QX ) = log dx (1) α−1 α−1 QX (x) where α ∈ [0, ∞] is referred to as Rényi order. In this paper, we assume PX ≪ QX so that the Radon–Nikodym derivative is always well defined. For extended orders α = 1 and ∞, we  PX (x)  should apply the L’Hôpital’s rule to get D1 (PX ∥QX ) = EX∼PX log Q and D∞ (PX ∥QX ) = X (x) PX (x) log max Q , respectively. Here, D1 refers to the Kullback-Leibler divergence. X (x) x∈X

2

Preliminary

We review the Pufferfish privacy framework as originally proposed by Kifer and Machanavajjhala (2012, 2014) [7, 8], alongside its extension to the Rényi-divergence-based variant, Rényi Pufferfish Privacy (Pierquin et al., 2024 [16]). Furthermore, we examine established noise calibration methods based on the recent W1 and W∞ Wasserstein metric calibration techniques. 2

2.1

System Setting and Rényi Pufferfish privacy

Assume that the data to be published, X (e.g., a query response or a column in a table), is statistically correlated with a sensitive secret S. Let PX|s,ρ denote the conditional probability distribution of the data X given a secret instance S = s, where ρ represents the adversary’s prior knowledge—such as the mean and covariance in the case of Gaussian-distributed data. In a multi-adversary environment, different agents may possess distinct prior beliefs ρ. To preserve privacy, we transform X into a randomized output Y before publication. The adversary is assumed to have access only to this sanitized data Y , though they may attempt to infer individual secrets by analyzing aggregated statistics from repeated queries. Let S define a set of secret pairs (si , sj ) specified by the data curator. This set identifies the instances where statistical indistinguishability must be enforced to ensure robust data protection. Any significant discrepancy between the distributions of Y conditioned on S = si versus S = sj could be exploited by an adversary to distinguish between secret states, leading to a privacy breach. This risk motivates a formal privacy definition that imposes an upper bound on the statistical distinguishability between such posterior distributions. Pufferfish Privacy For a privacy budget ϵ > 0, the privatized data Y is said to be ϵ-pufferfish privacy if [8, 7] PY |S (y|si , ρ) ≤ eϵ PY |S (y|sj , ρ),

∀y, ρ, (si , sj ) ∈ S.

(2)

Equation (2) guarantees an ϵ-level of indistinguishability across all adversarial prior beliefs ρ. The formalization of Rényi Pufferfish Privacy mirrors the extension of differential privacy to its Rényi counterpart, as established in [15]. Rényi Pufferfish Privacy For a privacy budget ϵ > 0 and Rényi order α ∈ [1, ∞], the privatized data Y is said to be (α, ϵ)-Rényi pufferfish privacy in S if [16] Dα (PY |si ,ρ ∥PY |sj ,ρ ) ≤ ϵ,

∀ρ, (si , sj ) ∈ S.

(3)

For given input distributions, Dα is (strictly) increasing in α [18, Theorem 3]. It reaches maximum at α = ∞, where (∞, ϵ)-Rényi pufferfish privacy refers to D∞ (PY |si ,ρ ∥PY |sj ,ρ ) = P

(y|s ,ρ)

i |S log max PYY |S (y|sj ,ρ) ≤ ϵ, ∀ρ, (si , sj ) ∈ S, equivalent to ϵ-pufferfish privacy. This is clear if we

y

rewrite the definition as 1 i α−1  h P (·|s , ρ)  α−1 i Y |S Dα (PY |si ,ρ ∥PY |sj ,ρ ) = log EY ∼PY |si ,ρ PY |S (·|sj , ρ)

(4)

eDα (PY |si ,ρ ∥PY |sj ,ρ ) is an (α − 1)-exponent generalized (Hölder) mean that is monotonically nondecreasing in α. The expression in (4) elucidates how Rényi Pufferfish Privacy provides a relaxation of the standard Pufferfish framework. At α = ∞, the generalized mean locates at the maximum statistical P |S (y|si ,ρ) distinguishability, PYY |S (y|sj ,ρ) , aligning with the core objective of data privacy: protecting against the worst-case, or catastrophic, data breach, irrespective of its frequency. However, when preventing this worst-case scenario becomes practically infeasible—for instance, when the required noise power severely degrades the utility of the published data—one may trade a degree of privacy for enhanced data utility. By selecting a finite order α < ∞, the generalized mean incorporates the statistical distinguishability across the entire support, where the influence of the maximum distinguishability is effectively discounted by its associated probability mass. Consequently, an upper bound ϵ on the Rényi divergence Dα no longer constrains the instantaneous worst-case ratio, but rather bounds the overall statistical distinguishability in an average sense. Thus, we can satisfy Dα (PY |si ,ρ ∥PY |sj ,ρ ) ≤ ϵ even if specific events X = x violate the stringent ϵ-Pufferfish constraint, PY |S (y|si ,ρ) ϵ PY |S (y|sj ,ρ) ≤ e .

The conceptual motivation for relaxing α from ∞ parallels the δ-approximation used in (ϵ, δ)differential and pufferfish privacy. While (ϵ, δ)-privacy guarantees that the probability of violating P |S (y|si ,ρ) ϵ the requirement PYY |S (y|sj ,ρ) ≤ e is bounded by δ, Rényi privacy offers a different, though related, form of relaxation. Because of this shared goal, (α, ϵ)-pufferfish privacy can always be translated 3

into the (ϵ, δ) framework. For instance, according to [15, Proposition 3], a finite order α can be log δ viewed as an increase in the effective privacy budget from ϵ to ϵ + −α−1 within a δ-approximate setting. Alternatively, an α < ∞ can be expressed in terms of the approximation probability itself. By applying the Chernoff bound, for any α ∈ (1, ∞),   P (Y |s , ρ) i Y |S (5) Pr > eϵ ≤ e(α−1)(Dα (PY |si ,ρ ,PY |sj ,ρ )−ϵ) . PY |S (Y |sj , ρ) Here, Pr(·) denotes the probability with respect to the distribution PY |si ,ρ . Recall that (ϵ, δ)pufferfish privacy is satisfied if PY |si ,ρ (A) ≤ eϵ PY |sj ,ρ (A) + δ for all measurable sets A, all priors ρ, and all secret pairs (si , sj ) ∈ S [12, Section 5]. Therefore, any (α, ϵ)-Rényi pufferfish privacy guarantee such that Dα (PY |si ,ρ , PY |sj ,ρ ) ≤ ϵ inherently provides the approximation (ϵ, e(α−1)(Dα (PY |si ,ρ ,PY |sj ,ρ )−ϵ) )-pufferfish privacy. It is important to note that these two relaxation methods—selecting a finite α in the Rényi framework or allowing a δ-approximation with α = ∞—serve similar purposes. In this paper, we focus on the former, attaining exact (α, ϵ)-Rényi pufferfish privacy without introducing an additional δ parameter. 2.2

Additive Noise Mechanism

A straightforward approach to data sanitization is adding noise to the original data. Let N denote a zero-mean noise variable that is statistically independent of X. The randomized output is then generated as Y = X + N . When X is an r.v., the resulting probability distribution of Y is determined by the convolution Z PY |S (y|s, ρ) = PN (y − x)PX|S (x|s, ρ) dx. (6) |z|

1 − b , ∀z ∈ R. The scale Laplace noise N ∼ Lap(b) follows the probability distribution PN (z) = 2b e parameter b indicates the flatness of Laplace distribution and determines noise variance 2b2 . For exponential mechanisim N ∼ Exp(θ) [1, Section 3.3], c is a metric that is nonnegative, symmetric c(z) = c(−z), ∀z, and satisfies the triangular inequality c(z) ≤ c(a) + c(z − a), ∀z, a. The noise ditribution is PN (z) ∝ e−η(θ)c(z) , where η ∝ θ1 . By the triangular inequality, PN (y − x) ≤ ′ ′ eη(θ)c(x−x ) PN (y − x′ ), ∀x, x′ , y, where eη(θ)c(x−x ) refers to an upper bound on the probability mass transport cost from x to x′ . It is clear that Laplace noise is an example of the exponential mechanism when η(θ) = 1/θ and c(z) = |z|. For Gaussian noise N ∼ Gauss(σ 2 ), the probability z2

1 distribution is PN (z) = √2πσ e− 2σ2 , ∀z ∈ R, with the noise variance being σ 2 .

Noise calibration involves determining the optimal values for the parameters b, θ, and σ for the Laplace, exponential, and Gaussian mechanisms, respectively. To preserve the utility of the randomized data Y , it is essential to minimize the noise power (variance), thereby navigating the privacy-utility tradeoff. Specifically, the noise parameters must be tuned to the minimum threshold necessary to satisfy the privacy constraint. Excessively large parameters should be avoided, as they unnecessarily deteriorate data utility without providing additional requisite protection. Wasserstein Metric For each pair of prior distributions PX|si ,ρ and PX|sj ,ρ , denote π a couR ′ pling joint distribution such that P (x|s , ρ) = π(x, x ) dx′ for all x and PX|S (x′ |sj , ρ) = i X|S R π(x, x′ ) dx for all x′ . Note that π is not unique. For α ∈ [1, ∞] and a nonnegative cost (or distance) function d(·), the α-Wasserstein distance is Z   α1 Wα (PX|si ,ρ , PX|sj ,ρ ) := inf d(x − x′ )α dπ(x, x′ ) π

measuring the minimum cost for transforming the probability mass from PY |si ,ρ to PY |sj ,ρ . WassersteinRdistance Wα is monotonically increasing in α. For α = 1, W1 (PX|si ,ρ , PX|sj ,ρ ) = inf π |x − x′ | dπ(x, x′ ) is called the earth mover distance, and the minimization is a linear programming. The minimizer π ∗ is called Kantorovich optimal transport plan [19, 20]. Assuming convex d, the optimal joint probability π ∗ can be computed directly using the existing knowledge of PX|si ,ρ and PX|sj ,ρ : let FX|S (·|si , ρ) and FX|S (·|sj , ρ) be the corresponding cu 2 mulative density functions, π ∗ (x, x′ ) = dxddx′ min FX|S (x|si , ρ), FX|S (x′ |sj , ρ) . For α = ∞, W∞ (PX|si ,ρ , PX|sj ,ρ ) = inf π sup(x,x′ )∈supp(π) d(x − x′ ). 4

3

α-Wasserstein Mechanism

We maintain consistent notation by using α to denote the order for both the Rényi divergence (Dα ) and the Wasserstein metric (Wα ), as the parameter serves a functionally analogous role in both frameworks. This notation establishes a direct correspondence between the two measures for any given value of α. Given that the W∞ metric is utilized to calibrate noise for ϵ-pufferfish privacy [9], it is natural to anticipate a corresponding Wα mechanism for (α, ϵ)-Rényi pufferfish privacy. In this section, we formally validate this intuition by proposing α-Wasserstein mechanisms for Laplace and Gaussian noise, as well as an exponential mechanism, for the range α ∈ (1, ∞). 3.1

Laplace Noise

The Laplace mechanism was the inaugural method proposed for achieving differential privacy, introduced concurrently with the framework’s formal definition in [1]. Its prominence stems from the fact that the privacy requirement can be satisfied through straightforward arithmetic properties of the Laplace distribution. Consequently, it remains the most widely adopted additive noise mechanism across various extensions and variations of the differential privacy framework. In the context of pufferfish privacy, Song et al. [9] first demonstrated that calibrating the Laplace scale parameter to the ∞-Wasserstein distance between discriminative secrets ensures ϵ-pufferfish privacy—a result later extended to a Kantorovich (W1 ) mechanism in [12]. Intuitively, this suggests that an α-Wasserstein mechanism should exist for the Rényi Pufferfish Privacy framework. In this section, we derive a method for calibrating the scale parameter using the Wα metric to satisfy (α, ϵ)-Rényi pufferfish privacy, and we demonstrate that our approach generalizes the existing W∞ mechanism. Theorem 1. Let b > 0 be the maximum value that satisfies Z |x−x′ | eα b dπ ∗ (x, x′ ) = e(α−1)ϵ (7) over all (si , sj ) ∈ S and ρ. Adding Laplace noise N ∼ Lap(b) attains (ϵ,α)-Rényi pufferfish privacy in Y for α ∈ (1, ∞]. Proof. For each secret pair (si , sj ) ∈ S and prior belief ρ, there are the two corresponding prior distributions PX|si ,ρ and PX|sj ,ρ . By definition of Rényi divergence and the convolution (6), for Laplace noise, we have Dα (PY |si ,ρ ∥PY |sj ,ρ ) α R Z PN (y − x)PX|S (x|si ) dx 1 log = α−1 dy R α−1 PN (y − x′ )PX|S (x′ |sj ) dx′ α R − |y−x| Z e b dπ(x, x′ ) 1 1 = log (8) ′| α−1 dy α−1 2b R e− |y−x b dπ(x, x′ ) α R − |y−x′ | |x−x′ | Z b e e b dπ(x, x′ ) 1 1 ≤ log (9) α−1 dy R − |y−x′ | α−1 2b b e dπ(x, x′ ) α R − |y−x′ | 1 − |y−x′ | α−1 |x−x′ | Z b αe b α e b e dπ(x, x′ ) 1 1 = log dy α−1 R α−1 2b e−|y−x′ | dπ(x, x′ ) α−1 R − |y−x′ | α |x−x′ | R − |y−x′ | Z b b b e dπ(x, x′ ) e e dπ(x, x′ ) 1 1 ≤ log dy  R |y−x′ | α−1 α−1 2b e− b dπ(x, x′ ) (10) Z

Z

1 1 log e e dπ(x, x′ ) dy α−1 2b Z Z  |x−x′ | 1 = log PN (y − x′ ) dy eα b dπ(x, x′ ) α−1 Z |x−x′ | 1 = log eα b dπ(x, x′ ) α−1 =

|y−x′ | − b

|x−x′ | α b

5

(11) (12)

for all α ∈ (1, ∞). Note that equation (8) holds for all joint probability π. Inequality (9) is because of α triangular inequality, and inequality (10) is due to the Hölder’s inquatlity. Here, α > 1 and α−1 >1 1 α−1 are Hölder conjugates such that α + α = 1. It suffices to request (12) upper bounded by ϵ. In order to obtain the smallest scale parameter b that satisfies this condition, we apply a minimization of the integral in (12) over all joint probability π: Z |x−x′ | inf eα b dπ(x, x′ ) ≤ e(α−1)ϵ (13) π

|·|

For each α, the LHS of (13) is a W1 distance. As eα b is convex, the minimizer is the Kantorovich optimal mechanism π ∗ . In this case, the smallest b should achieve the upper bound in (13), and we have (7). This is a sufficient condition on b to achieve Dα (PY |si ,ρ ∥PY |sj ,ρ ) ≤ ϵ for a specific secret pair (si , sj ) ∈ S under a prior belief. Maximizing this scale parameter b over all secret pairs and ρ, we have the (α, ϵ)-Rényi pufferfish privacy. To determine the parameter b in Theorem 1, we can utilize the modified Brent’s method proposed in [21, 22].The approach involves employing the standard Brent’s method [23, 24] to iteratively refine the lower and upper bounds of the root in (7). Upon convergence, the algorithm outputs the lower bound to satisfy the inequality constraint in (13). For a detailed implementation of this searching algorithm, we refer the reader to [21]. It should be noted that other numerical root-finding techniques are equality applicable for determining b in Theorem 1. Although the optimal transport plan π ∗ in (7) is formulated similarly to the Kantorovich W1 metric, Theorem 1 actually establishes a sufficient condition based on the Wα metric. This relationship becomes evident by rewriting (13) as: Z   α1 |x−x′ | α−1 (14) Wα (PX|si ,ρ , PX|sj ,ρ ) = inf eα b dπ(x, x′ ) ≤e α ϵ π

|z|

where the distance function is defined as d(z) = e b for all z ∈ R. Under this formulation, the scale parameter b in Theorem 1 is effectively calibrated by the Wα distance; hence, we refer to this as the α-Wasserstein mechanism. This approach integrates seamlessly with the established W∞ mechanism for ϵ-pufferfish privacy, providing a unified framework for varying privacy requirements. Remark 1 (Generalization). Setting α = ∞ to consider the problem of attaining ϵ-pufferfish privacy in Y , we have (14) being W∞ (PX|si , PX|sj ) ≤ eϵ . This is equivalent to |x − x′ | . π ρ,(x,x′ )∈supp(π ∗ ) ϵ

b ≥ inf

sup

(15)

The RHS of (15) is a ∞-Wasserstein metic for d(z) = |z|, ∀z ∈ R, and (15) is exactly the ∞Wasserstein mechanism proposed in [9]. See Figure 3. It was previously established in [16, Corollary 3.1] that a scale parameter satisfying ϵ = α−1 α α α−1 b W∞ (PY |si ,ρ ,PY |sj ,ρ ) b W∞ (PY |si ,ρ ,PY |sj ,ρ ) + 2α−1 e ensures (α, ϵ)-Rényi Pufferfish Privacy. 2α−1 e This result was derived by applying the shift reduction lemma [25, Lemma 20] to obtain the shifted Rényi divergence [25, Definition 8]. Essentially, this constitutes an ∞-Wasserstein mechanism analogous to the Rényi differential privacy framework in [15, Proposition 6], with the ℓ1 -sensitivity replaced by the W∞ distance. This alignment is expected, as the maximum ℓ1 -norm in the pufferfish setting corresponds exactly to the ∞-Wasserstein distance. However, because the Wα metric is monotonically non-decreasing with respect to α, relying on the W∞ distance inevitably necessitates a larger noise scale to satisfy the privacy constraint. Experimental results in Figure 1 demonstrate that our proposed α-Wasserstein mechanism, as defined in Theorem 1, requires a significantly smaller scale parameter b compared to [16, Corollary 3.1]. One approach to improving data utility is to relax the Wasserstein mechanism from α = ∞ to a finite α < ∞. To this end, [16, Section 4] introduced a δ-approximation for Rényi Pufferfish Privacy, formally defined by the triplet (α, ϵ, δ)-Rényi Pufferfish Privacy [16, Definition 4.1]. Subsequently, a sufficient condition based on the α-Wasserstein metric was proposed in [16, Theorem 4.3] for 6

general cases. This was achieved by approximating the shift reduction in the post-processing of Rényi divergence [16, Lemma 4.1]. However, as discussed in Section 2.1, the Rényi measure is itself a relaxation of the stringent ϵ-pufferfish privacy constraint. Specifically, it allows for a breach probability bounded by e(α−1)(Dα (PY |si ,ρ ,PY |sj ,ρ )−ϵ) , as shown in (5). Consequently, there is no inherent need to further approximate Rényi pufferfish Privacy, as the framework is already an approximation by design. Introducing an additional parameter δ further eases the privacy constraint, which may lead to unintended consequences. For instance, an (α, ϵ, δ)-Rényi Pufferfish Privacy guarantee may be equivalent to an (ϵ, δ ′ )-pufferfish privacy bound where δ ′ = e(α−1)(Dα (PY |si ,ρ ,PY |sj ,ρ )−ϵ) + δ.1 In such cases, δ must be selected with extreme care; if the combined δ ′ approaches or exceeds 1, the privacy guarantee becomes vacuous. It is evident that applying relaxations via both α and δ complicates the calculation of the cumulative privacy loss. Therefore, Theorem 1 and the subsequent results in this work focus exclusively on relaxation through the Rényi order α. Exponential Mechanism The α-Wasserstein mechanism for Laplace noise can be easily extended to the exponential mechanism as follows. The proof is in Appendix A. Corollary 1. Let θ be the maximum value satisfying Z ′ eαη(θ)c(x−x ) dπ ∗ (x, x′ ) = e(α−1)ϵ

(16)

over all (si , sj ) ∈ S and ρ. Adding exponential mechanism N ∼ Exp(θ) attains (ϵ,α)-Rényi pufferfish privacy in Y for α ∈ (1, ∞]. This can be reformulated as an α-Wasserstein mechanism: Z   α1 α−1 ′ Wα (PX|si ,ρ , PX|sj ,ρ ) = inf eαη(θ)c(x−x ) dπ(x, x′ ) ≤e α ϵ π

(17)

where the distance function is defined as d(z) = eαη(θ)c(z) , ∀z ∈ R. In the limiting case where α = ∞, we obtain the closed-form expression θ = η −1 ϵ/ sup(x,x′ )∈supp(π∗ ) c(x − x′ ) . This result recovers the Kantorovich-exponential mechanism originally proposed in [12, Theorem 1]. 3.2

Gaussian Noise

Another widely adopted approach is the Gaussian mechanism. Owing to its sub-Gaussian concentration properties and rapidly decaying tail probabilities, it is often preferred over the Laplace mechanism in applications requiring high data utility and accuracy [26, 27]. In the context of Rényi differential Privacy, the Gaussian mechanism yields a closed-form expression for privacy loss [15, Proposition 7], making noise calibration significantly more straightforward than for the Laplace mechanism [15, 28, Corollary 3]. Below, we propose an α-Wasserstein mechanism for calibrating Gaussian noise to satisfy Rényi pufferfish Privacy. We further demonstrate that this formulation generalizes the established Rényi differential Privacy results found in [15, Corollary 3] to correlated data settings. Theorem 2. Let σ 2 be the maximum value satisfying Z (x−x′ )2 eα(α−1) 2σ2 dπ ∗ (x, x′ ) = e(α−1)ϵ

(18)

over all (si , sj ) ∈ S and ρ. Adding Gaussian noise N ∼ Gauss(σ) attains (ϵ,α)-Rényi pufferfish privacy in Y for α ∈ (1, ∞). The proof is in Appendix B. Theorem (2) is in fact a Wα(α−1) mechanism. This is clear if we rewrite (18) to Z 1   α(α−1) (x−x′ )2 ϵ Wα(α−1) (PX|si , PX|sj ) = inf eα(α−1) 2σ2 dπ(x, x′ ) ≤ eα (19) π

where the distance function is d(z) = e

z2 2σ 2

, ∀z ∈ R.

1We conjecture that the resulting approximation probability is additive in the (α, ϵ, δ)-Rényi pufferfish Privacy framework.

7

Remark 2 (Generalizing from Rényi Differential Privacy). When the adversary’s prior knowledge indicates that the data is deterministic—meaning PX|si ,ρ and PX|sj ,ρ are point masses centered at distinct values µi and µj , respectively—Rényi Pufferfish Privacy reduces to standard Rényi Differential Privacy. In this scenario, the condition in (18) simplifies to: α

(µi − µj )2 = ϵ. 2σ 2

The LHS of this equation represents the Rényi divergence between two Gaussian distributions sharing a common variance σ 2 [15, Proposition 7]. By defining the ℓ1 -sensitivity as △ = maxρ,(si ,sj )∈S |µi − 2

µj |, we obtain the closed-form solution σ 2 = α △ 2ϵ . This result is identical to the Gaussian noise calibration method proposed in [15, Corollary 3] for achieving (α, ϵ)-Rényi differential privacy. Consistent with the framework in [15, Corollary 3], our approach does not require additional relaxations—such as the δ-approximation introduced in [16, Definition 4.1]—to calibrate Gaussian noise for Rényi pufferfish privacy. Experimental results presented in Figure 1 demonstrate that our proposed α-Wasserstein mechanism, as defined in Theorem 2, requires a significantly smaller variance σ 2 compared to the bounds established in [16, Corollary 3.1]. 3.3

Experiment

The experimental results in Figure 1 are obtained in three real-world datasets in the UCI machine learning repository [29]: adult, heart disease and student performance. For adult, X refers to attribute education, si =‘relationship=Husband’, and sj =‘relationship=Not-in-family’; for heart disease, X refers to oldpeak, si =‘fbs=0’ and sj =‘fbs=1’; for student performance, X refers to G3 (the final grade), si =‘guardian=mother’ and sj =‘guardian=father’. Figure 1 further evaluates the noise power requirements by comparing the variance of the Laplace mechanism in Theorem 1 with that of the Gaussian mechanism in Theorem 2 for ϵ = 0.1 (row 4) and α = 1.5 (row 5). The results indicate that the Gaussian mechanism requires considerably less noise power than the Laplace mechanism; this advantage is particularly pronounced in the high-privacy regime where the budget ϵ is small. The minor irregularities observed in Figure 1 for the Laplace mechanism (Theorem 1) near α = 1 arise because the Rényi divergence in (1) is undefined at this limit. Consequently, our α-Wasserstein mechanisms in Theorems 1 and 2 do not apply when α = 1. Furthermore, the case of α = 1 represents an excessive relaxation where D1 (Kullback–Leibler divergence) measures only the average statistical distinguishability. This should generally be avoided in privacy contexts, which focus on preventing worst-case or catastrophic data breaches. Figure 2 also shows for smaller value of α, a larger scale parameter b for Laplace noise should be chosen to satisfy the sufficient condition in Theorem 1.

4

Conclusion

We investigated the calibration of Wasserstein mechanisms to achieve (α, ϵ)-Rényi pufferfish privacy. We proposed an α-Wasserstein mechanism where the parameters for Laplace and Gaussian noise are calibrated using an upper-bounded Wα metric of the same order α. Experimental results demonstrate that our α-Wasserstein mechanism significantly reduces noise compared to existing W∞ -based approaches. The results further verify that the Gaussian mechanism offers superior data utility over the Laplace mechanism when utilizing the Rényi divergence as a privacy relaxation. Discussion The primary results of this paper leverage Hölder’s inequality for the conjugate expoα nents α and α−1 . This established technique is a staple of information theory, used in generalized error bounds [30, 31] , entropy power inequalities [32, 33], and foundational bounds on guessing α entropy [34, 35].. Furthermore, Rényi measures of order α−1 have recently gained prominence in information-theoretic privacy [36, 37]. Beyond its core application to differential and pufferfish privacy, we highlight several promising extensions for future work. R |x−x′ | Closed-form Solution: For (7), find an invertible function f such that eα b dπ ∗ (x, x′ ) ≤ fα (b), and compute scale parameter b = fα−1 (e(α−1)ϵ ), we obtain a closed-form sufficient condition. 8

4

5

2

Theorem 1 [16, Corollary 3.1]

3 2 1 2

3 α

4

4

6

1

5

2

4 2

2

3 α

4

6 4

1 2

2

3 α

4

3 α

4

5

heart disease: Gaussian, ϵ = 1

1

5

Theorem 2 [16, Corollary 3.1]

4 3 2 1

5

2

3 α

4

5

student performance: Laplace, ϵ = 1 student performance: Gaussian, ϵ = 1

Theorem 2 [16, Corollary 3.1]

10

2

5

1.5

scale parameter b

standard deviation σ

scale parameter b

Theorem 1 [16, Corollary 3.1]

4

Theorem 1 [16, Corollary 3.1]

2

student performance: Laplace, ϵ = 0.5 student performance: Gaussian, ϵ = 0.5

8

3 α

Theorem 2 [16, Corollary 3.1]

3

heart disease: Laplace, ϵ = 1

Theorem 2 [16, Corollary 3.1]

5

standard deviation σ

1.5

heart disease: Gaussian, ϵ = 0.5 standard deviation σ

scale parameter b

heart disease: Laplace, ϵ = 0.5

4

3 α

adult: Gaussian, ϵ = 1

Theorem 1 [16, Corollary 3.1]

standard deviation σ

3 α

2

scale parameter b

2

4

2

5

5

standard deviation σ

2

Theorem 2 [16, Corollary 3.1]

scale parameter b

Theorem 1 [16, Corollary 3.1]

3

adult: Laplace, ϵ = 1

adult: Gaussian, ϵ = 0.5 standard deviation σ

scale parameter b

adult: Laplace, ϵ = 0.5

Theorem 1

W∞ -Laplace 4 3 2

Theorem 2 [16, Corollary 3.1]

8 6 4 2

2 3 α

4

2

5

3 α

4

Laplace: Theorem 1 Gaussian: Theorem 2

101

noise variance

noise variance

2

3 α

4

5

0

10

2

2

3 α

4

5

student performance, ϵ = 0.1

heart disease, ϵ = 0.1

adult, ϵ = 0.1

102

5

Laplace: Theorem 1 Gaussian: Theorem 2

101 100

103 noise variance

2

Laplace: Theorem 1 Gaussian: Theorem 2

102 101

10

3 α

4

5

2

4

5

2

Laplace: Theorem 1 Gaussian: Theorem 2

101 100

Laplace: Theorem 1 Gaussian: Theorem 2

101

100

3 α

4

5

student performance, α = 1.5

heart disease, α = 1.5

noise variance

noise variance

adult, α = 1.5

3 α

noise variance

2

Laplace: Theorem 1 Gaussian: Theorem 2

102 101 100

0

2

4

0

2

ϵ

4 ϵ

0

2

4 ϵ

Figure 1: Experimental results using adult, heart disease and student performance datasets from UCI machine learning repository [29]: rows 1-3 compare Theorems 1 and 2 to W∞ based mechanism in [16, Corollary 3.1] for ϵ = 0.5, 1; rows 4-5 show noise reduction by Gaussian mechanism in Theorem 2 as compared to Laplace mechanism in Theorems 1.

R |x−x′ | Range α ∈ (0, 1): It is not difficult to derive the sufficient condition e−α b dπ(x, x′ ) ≥ e(α−1)ϵ , ∀ρ, (si , sj ) ∈ S for attaining (α, ϵ)-Rényi pufferfish privacy for α ∈ (0, 1) by Laplace mechanism. See Proposition 1 in Appendix C. However, the operational interpretation for Rényi pufferfish (and differential) privacy in range α ∈ (0, 1) should be studied first. W2 Mechanism for Gaussian Noise and Gaussian Priors: For (24), we have the sufficient ′) 2 R α(x−x √ 1 2σ condition Dα (PY |si ,ρ ∥PY |sj ,ρ ) ≤ α−1 log inf π e dπ(x, x′ ) ≤ ϵ, equivalent to 2 αz α−1 √ W2 (PY |si ,ρ , PY |sj ,ρ ) ≤ e 2 ϵ for d(z) = e 2σ , ∀z ∈ R. For PX|si and PX|sj being Gaussian distributions, the value of W2 is determined by Monge’s formulation [38–40]. It is worth discussing if meaningful results can be derived. 9

References [1] Dwork, C., F. McSherry, K. Nissim, et al. Calibrating noise to sensitivity in private data analysis. In S. Halevi, T. Rabin, eds., Theory of Cryptography, pages 265–284. Springer Berlin Heidelberg, Berlin, Heidelberg, 2006. [2] Dwork, C. Differential privacy. In M. Bugliesi, B. Preneel, V. Sassone, I. Wegener, eds., Automata, Languages and Programming, pages 1–12. Springer Berlin Heidelberg, Berlin, Heidelberg, 2006. [3] Wasserman, L., S. Zhou. A statistical framework for differential privacy. Journal of the American Statistical Association, 105(489):375–389, 2010. [4] Abowd, J. M. The u.s. census bureau adopts differential privacy. In Proceedings of the 24th ACM SIGKDD International Conference on Knowledge Discovery and Data Mining, KDD ’18, pages 2867–2867. ACM, 2018. [5] Abadi, M., A. Chu, I. Goodfellow, et al. Deep learning with differential privacy. In Proceedings of the 2016 ACM SIGSAC Conference on Computer and Communications Security, pages 308–318. ACM, 2016. [6] Mohammadi, M., M. Vejdanihemmat, M. Lotfinia, et al. Differential privacy for deep learning in medicine. arXiv e-prints, pages arXiv–2506, 2025. [7] Kifer, D., A. Machanavajjhala. A rigorous and customizable framework for privacy. In Proceedings of the 31st ACM SIGMOD-SIGACT-SIGAI Symposium on Principles of Database Systems, PODS ’12, page 77–88. Association for Computing Machinery, New York, NY, USA, 2012. [8] —. Pufferfish: A framework for mathematical privacy definitions. ACM Transactions on Database Systems, 39(1), 2014. [9] Song, S., Y. Wang, K. Chaudhuri. Pufferfish privacy mechanisms for correlated data. In Proceedings of the 2017 ACM International Conference on Management of Data, page 1291–1306. New York, NY, USA, 2017. [10] Champion, T., L. De Pascale, P. Juutinen. The ∞-Wasserstein distance: Local solutions and existence of optimal transport maps. SIAM Journal on Mathematical Analysis, 40(1):1–20, 2008. [11] De Pascale, L., J. Louet. A study of the dual problem of the one-dimensional l∞ -optimal transport problem with applications. Journal of Functional Analysis, 276(11):3304–3324, 2019. [12] Ding, N. Kantorovich mechanism for pufferfish privacy. In G. Camps-Valls, F. J. R. Ruiz, I. Valera, eds., Proceedings of The 25th International Conference on Artificial Intelligence and Statistics, vol. 151 of Proceedings of Machine Learning Research, pages 5084–5103. PMLR, 2022. [13] Soria-Comas, J., J. Domingo-Ferrer, D. Sanchez, et al. Individual differential privacy: A utility-preserving formulation of differential privacy guarantees. IEEE Transactions on Information Forensics and Security, 12(6):1418–1429, 2017. [14] Li, B., W. Wang, P. Ye. The limits of differential privacy in online learning. In Advances in Neural Information Processing Systems 37, NeurIPS 2024, pages 65328–65360. Neural Information Processing Systems Foundation, Inc. (NeurIPS), 2024. [15] Mironov, I. Rényi differential privacy. In 2017 IEEE 30th Computer Security Foundations Symposium (CSF), pages 263–275. 2017. [16] Pierquin, C., A. Bellet, M. Tommasi, et al. Rényi Pufferfish Privacy: General Additive Noise Mechanisms and Privacy Amplification by Iteration via Shift Reduction Lemmas. In International Conference on Machine Learning (ICML 2024). Vienna (Austria), Austria, 2024. [17] Rényi, A. On measures of entropy and information. In Proceedings of the Fourth Berkeley Symposium on Mathematical Statistics and Probability, Volume 1: Contributions to the Theory of Statistics, vol. 4, pages 547–562. University of California Press, 1961. [18] van Erven, T., P. Harremoes. Rényi divergence and Kullback-Leibler divergence. IEEE Transactions on Information Theory, 60(7):3797–3820, 2014. [19] Villani, C. Optimal transport: old and new, vol. 338. Springer, 2009. [20] Santambrogio, F. Optimal transport for applied mathematicians. Birkäuser, NY, 55(58-63):94, 2015.

10

[21] Yang, W., N. Ding, Z. Zhang, et al. Noise reduction for pufferfish privacy: A practical noise calibration method. arXiv preprint arXiv:2601.06385, 2026. [22] Ding, N., S. Lu, W. Yang, et al. Multi-user pufferfish privacy. arXiv preprint arXiv:2512.18632, 2025. [23] Brent, R. P. An algorithm with guaranteed convergence for finding a zero of a function. The Computer Journal, 14(4):422–425, 1971. [24] Süli, E., D. F. Mayers. An introduction to numerical analysis. Cambridge university press, 2003. [25] Feldman, V., I. Mironov, K. Talwar, et al. Privacy amplification by iteration. In 2018 IEEE 59th Annual Symposium on Foundations of Computer Science (FOCS), pages 521–532. IEEE, 2018. [26] Dwork, C., A. Roth, et al. The algorithmic foundations of differential privacy. Found. Trends Theor. Comput. Sci., 9(3-4):211–407, 2014. [27] Balle, B., Y.-X. Wang. Improving the Gaussian mechanism for differential privacy: Analytical calibration and optimal denoising. In J. Dy, A. Krause, eds., Proceedings of the 35th International Conference on Machine Learning, vol. 80 of Proceedings of Machine Learning Research, pages 394–403. PMLR, 2018. [28] Mironov, I., K. Talwar, L. Zhang. Rényi differential privacy of the sampled gaussian mechanism. arXiv preprint arXiv:1908.10530, 2019. [29] Asuncion, A., D. Newman. UCI machine learning repository https://archive.ics.uci.edu/ml/index.php, 2007. [30] Esposito, A. R., M. Gastpar, I. Issa. Robust generalization via f -mutual information. pages 2723–2728, 2020. [31] —. Generalization error bounds via Rényi-, f -divergences and maximal leakage. IEEE Transactions on Information Theory, 67(8):4986–5004, 2021. [32] Rioul, O. Information theoretic proofs of entropy power inequalities. IEEE Transactions on Information Theory, 57(1):33–55, 2011. [33] —. Rényi entropy power and normal transport. In 2020 International Symposium on Information Theory and Its Applications (ISITA), pages 1–5. 2020. [34] Massey, J. Guessing and entropy. In Proceedings of 1994 IEEE International Symposium on Information Theory, ISIT-94, page 204. IEEE. [35] Arikan, E. An inequality on guessing and its application to sequential decoding. IEEE Transactions on Information Theory, 42(1):99–105, 1996. [36] Liao, J., O. Kosut, L. Sankar, et al. Tunable measures for information leakage and applications to privacy-utility tradeoffs. IEEE Transactions on Information Theory, 65(12):8043–8066, 2019. [37] Ding, N., F. Farokhi, T. Guo, et al. α-leakage interpretation of sibson mutual information and rényi capacity. In 2025 IEEE Information Theory Workshop (ITW), pages 752–757. IEEE, 2025. [38] Dowson, D., B. Landau. The fréchet distance between multivariate normal distributions. Journal of multivariate analysis, 12(3):450–455, 1982. [39] Givens, C. R., R. M. Shortt. A class of Wasserstein metrics for probability distributions. Michigan Mathematical Journal, 31(2):231–240, 1984. [40] Takatsu, A. Wasserstein geometry of Gaussian measures. Osaka Journal of Mathematics, 48(4):1005–1026, 2011. [41] Daoxiang, Z., P. Yan. On the hardy–carleman inequality for a negative exponent. Journal of mathematical inequalities, 11(3):885–890, 2017.

11

A

Proof of Corollary 1

Proof. The proof is similar to Theorem 1. We still apply the Hölder’s inequality, but use the triangular ′ inequality, PNθ (y − x) ≤ eη(θ)c(x−x ) PNθ (y − x′ ), ∀x, x′ , y. Dα (PY |si ,ρ ∥PY |sj ,ρ ) α R Z PN (y − x) dπ(x, x′ ) 1 = log α−1 dy R α−1 PN (y − x′ ) dπ(x, x′ ) α ′ Z R PN (y − x′ )eη(θ)c(x−x ) dπ(x, x′ ) 1 dy ≤ log α−1 R α−1 PN (y − x′ ) dπ(x, x′ ) α α−1 ′ 1 Z R PN (y − x′ ) α PN (y − x′ ) α eη(θ)c(x−x ) dπ(x, x′ ) 1 = dy log α−1 R α−1 PN (y − x′ ) dπ(x, x′ ) α−1 R ′ Z R PN (y − x′ ) dπ(x, x′ ) PN (y − x′ )eαη(θ)c(x−x ) dπ(x, x′ ) 1 ≤ dy log α−1 R α−1 PN (y − x′ ) dπ(x, x′ ) ZZ ′ 1 = log PN (y − x′ )eαη(θ)c(x−x ) dπ(x, x′ ) dy α−1 Z Z  ′ 1 log PN (y − x′ ) dy eαη(θ)c(x−x ) dπ(x, x′ ) = α−1 Z ′ 1 = log eαη(θ)c(x−x ) dπ(x, x′ ) (20) α−1 for all α ∈ (1, ∞]. Substitute the Kantorovich optimal transport plan π ∗ . Requesting (20) to be upper bounded by ϵ and search the smallest θ that holds this condition for all ρ and (si , sj ) ∈ S, we have Corollary (1).

B

Proof of Theorem 2

Proof. For Gaussian noise, we have for all α ∈ (1, ∞), Dα (PY |si ,ρ ∥PY |sj ,ρ ) α R − (y−x)2 Z e 2σ2 dπ(x, x′ ) 1 1 = log √ ′ )2 α−1 dy α−1 2πσ R e− (y−x 2σ 2 dπ(x, x′ ) 1 = log α−1

Z

1 = log α−1

Z

1 √ 2πσ

R

1 √ 2πσ

R

e−

(y−x′ )2 +2(y−x′ )(x′ −x)+(x−x′ )2 2σ 2

R e−

e−

(y−x′ )2 2σ 2

(y−x′ )2 1 ( α + α−1 α ) 2σ 2

dπ(x, x′ ) e−

α dπ(x, x′ )

α−1

2(y−x′ )(x′ −x)+(x−x′ )2 2σ 2

dy

dπ(x, x′ )

(21) α

dy (22) α−1 dπ(x, x′ ) α−1 R − (y−x′ )2 +2α(y−x′ )(x′ −x)+α(x−x′ )2 R − (y−x′ )2 Z 2σ 2 dπ(x, x′ ) e 2σ2 dπ(x, x′ ) e 1 1 ≤ log √ dy ′ 2  R − (y−x ) α−1 α−1 2πσ e 2σ2 dπ(x, x′ ) (23) ZZ (y−x′ )2 +2α(y−x′ )(x′ −x)+α2 (x−x′ )2 α2 (x−x′ )2 −α(x−x′ )2 1 1 2σ 2 2σ 2 √ = log e− e dπ(x, x′ ) dy α−1 2πσ Z Z  α2 (x−x′ )2 −α(x−x′ )2 1 2σ 2 = dπ(x, x′ ) log PN (y + (α − 1)x′ − αx)) dy e α−1 Z (x−x′ )2 1 = log eα(α−1) 2σ2 dπ(x, x′ ), (24) α−1 where inequality (23) is by applying Holder’s inequality. We still adopt Kantorovich mechanism π ∗ to tune to the lowest level of noise, and get (18). R

e−

(y−x′ )2 2σ 2

12

A Sufficient Condition for α ∈ (0, 1)

C

Proposition 1. For α ∈ (0, 1), Dα (PY |si ,ρ , PY |sj ,ρ ) ≤ ϵ, if Z |x−x′ | e−α b dπ(x, x′ ) ≥ e(α−1)ϵ . Proof. For each PX|si ,ρ and PX|sj ,ρ , we have Dα (PY |si ,ρ ∥PY |sj ,ρ ) |y−x′ |

|x−x′ |

1 ≤ log α−1

Z

1 2b

R

e− b e− b dπ(x, x′ ) α−1 R − |y−x′ | b e dπ(x, x′ )

1 = log α−1

Z

1 2b

R

e−

|y−x′ | 1 b α

e−

|y−x′ | α−1 b α

e−

α

|x−x′ | b

α dπ(x, x′ )

dy α−1 e−|y−x′ | dπ(x, x′ ) α−1 R − |y−x′ | α |x−x′ | R − |y−x′ | Z b b b e dπ(x, x′ ) e e dπ(x, x′ ) 1 1 ≤ log dy  R |y−x′ | α−1 α−1 2b e− b dπ(x, x′ ) Z Z |y−x′ | −|x−x′ | 1 1 = log e− b eα b dπ(x, x′ ) dy α−1 2b Z |x−x′ | 1 = log eα b dπ(x, x′ ) α−1 R

α for α ∈ (0, 1). Here, we still adopt Hölder conjugates α and α−1 . But, the inequality is reversed as α is negative [41]. α−1

D

More Experimental Results heart disease,ϵ = 0.5

α−1

α−1

Wα vs. e α ϵ in (14)

Wα vs. e α ϵ in (14)

adult,ϵ = 0.5

100 1

2

3 α

4

5

1

2

3 α

4

5

student performance,ϵ = 0.5

α−1

Wα vs. e α ϵ in (14)

Wα , b = 2 Wα , b = 2.5 Wα , b = 3 Wα , b = 3.5 Wα , b = 4 Wα , b = 5 Wα , b = 6 exp((α − 1)ϵ/α) 100 1

2

3 α

4

5 α−1

Figure 2: The comparison of Wα (PX|si ,ρ , PX|sj ,ρ ) with it’s upper bound e α ϵ in (14) for fixed ϵ.

13

adult, ϵ = 0.5

10

4

3 2.5

Theorem 1 [16, Corollary 3.1] limit W∞ /ϵ [9]

2 10

1

10

2

10

3

10

9

3.5 3 Theorem 1 [16, Corollary 3.1] limit W∞ /ϵ [9]

2.5

4

scale parameter b

3.5

scale parameter b

scale parameter b

student performance, ϵ = 0.5

heart disease, ϵ = 0.5 4.5

4

1

10

10

2

α

10

3

10

8 7 Theorem 1 [16, Corollary 3.1] limit W∞ /ϵ [9]

6 5

4

α

101

102

103

104

α

Figure 3: The variation of scale parameter b determined by Theorem 1 and [16, Corollary 3.1]. They both approach W∞ /ϵ mechanism proposed in [9] as α → ∞ for attaining ϵ-pufferfish privacy. α−1

Figure 2 shows how the LHS Wα (PX|si ,ρ , PX|sj ,ρ )and RHS e α ϵ of the inequality (14) varies with α, for different values of scale parameter b of Laplace noise. Figure 3 is an example of Remark 1. It shows the scale parameter b determined by Theorem 1 and [16, Corollary 3.1] both converges to W∞ /ϵ, the ∞-Wasserstein mechanism in [9], when α grows large.

14

Record · ID 160741 · SHA-256 c857b54b5dd6c070
Retrieved via Conceptio — every document is proof-bundled with source, license, and retrieval metadata.