As I was reading it in preparation for my JSM²⁴ lecture, I found anew that, in this landmark paper of Dimitrikakis et al. (2017), some limitations of the concept of differential privacy were most apparent:
– a requirement to bend both the model and the prior to fit differential privacy, like switching to Lipschitz constraints or using new (e.g., truncated) priors, which runs contrary to Bayesian principles, although the former can be seen as a form of randomization akin to ABC when the randomization itself is accounted for in the derivation of the “exact” posterior distribution (as in the paper of Berah, Favaro, and Rao (2023) on running MCMC for Bayesian non-parametric estimation on privatized (noisy) data I discussed a few days ago);
– a subtle switch of the randomness from the (privatization) procedure itself (as in Dwork (2006)) to the uncertainty about the parameter, not that it clashes per se with Bayesian principles (even though there is an unclear randomness statement in Theorem 9, when the prior itself seems to become random (?)). Which actually means that producing one realisation from the posterior is the (privatization) procedure, as I realised when discussing with Shenggang Hu in Warwick;
– a linear degradation of the privacy parameter ε when moving from one realisation of the posterior to a simulated sample, assuming iid realisations (I wonder whether or not releasing a dependent sample could involve the ESS instead of the number of MCMC iterations). The upper bound means that no privacy whatsoever is guaranteed for an infinite posterior sample, hence for delivering de facto the posterior (despite the paper producing an (ε,0) bound on the Kullback-Leibler measure of the difference between posteriors);
– an absence of prior knowledge or modelling on the data itself, unless the distance from the actual data to an hypothetical alternative, ρ(x,y), can be interpreted as minus a score function conditional on the actual data, eg the opposite of the log predictive
-
the occurrence of an “exponential prior” that is exp p/m ell (theta) with ell a Lipschitz constant for the associated likelihood
-
the assumption that the data user is not an adversary of the data keeper, in that their utility function is about the parameter (and publicly available)




