Skip to content

Privacy Amplification Without Independence: How Far Negative Dependence Carries the Guarantees of Poisson Subsampling

Xujun Che, Depeng Xu

cs.CRarXiv:2609.01944

Abstract

Poisson subsampling is the default sampler in differentially private optimization because its independence makes privacy amplification tractable. Practical systems, however, are moving toward structured participation: random allocation (balls-in-bins), per-epoch allocation, random check-ins, schemes widely believed to be at least as private as Poisson subsampling at the matched rate. We isolate the probabilistic mechanism behind this belief and delimit it exactly, for Gaussian mechanisms up to correlated-noise matrix mechanisms. (1) If the participation indicator vector is negatively associated (NA), then at every integer Rényi order α2, exactly at all finite parameters, its remove-direction Rényi divergence is dominated by that of the marginal-matched independent scheme. For fixed gradient sequences, this extends to the mechanism level whenever the noise strategy's Gram matrix is sign-balanced, an O(t2)-checkable condition. (2) The integer-order restriction is essential. For random allocation with k=1, we prove a linear law for the Rényi-difference criterion: at large t, dominance reverses for every α<3/2, including KL divergence, while the crossing order tends to 3/2 independently of σ. (3) We also localize the known failure of rate-matched Poisson domination exactly: below (1-q)t, the hockey-stick ordering reverses, so substituting the Poisson pair into composition machinery is unsound. An upper-tail argument yields a finite crossover γ, connecting this threshold picture to the Rényi boundary at 3/2. Together, these results give a substitution map for privacy accounting: when Poisson-based computations remain sound for structured participation, where they fail, and what sound alternatives cost in deployment.

Create a lesson