scieee AI-readable full text Open interactive document viewer

Differentially private hypothesis testing with the subsampled and aggregated randomized response mechanism

Peña Pizarro, Víctor,Barrientos, Andrés F.

Abstract

Randomized response is one of the oldest and most well-known methods used to analyze confidential data. However, its utility for differentially private hypothesis testing is limited because it cannot simulaneously achieve high privacy levels and low type-I error rates. We overcome this problem using the subsample and aggregate technique. The result is a general-purpose method that can be used for both frequentist and Bayesian testing. We demonstrate the performance of the proposed method in three scenarios: goodness-of-fit testing for linear regression models, nonparametric testing of a location parameter using the Wilcoxon test, and the nonparametric Kruskal–Wallis test.

Full text

Statistica Sinica 35 (2025), 1-21 doi:https://doi.org/10.5705/ss.202022.0279 DIFFERENTIALLY PRIVATE HYPOTHESIS TESTING WITH THE SUBSAMPLED AND AGGREGATED RANDOMIZED RESPONSE MECHANISM V´ıctor Pe˜na∗and Andr´es F. Barrientos Universitat Polit`ecnica de Catalunya and Florida State University Abstract: Randomized response is one of the oldest and most well-known methods used to analyze confidential data. However, its utility for differentially private hypothesis testing is limited because it cannot simulaneously achieve high privacy levels and low type-I error rates. We overcome this problem using the subsample and aggregate technique. The result is a general-purpose method that can be used for both frequentist and Bayesian testing. We demonstrate the performance of the proposed method in three scenarios: goodness-of-fit testing for linear regression models, nonparametric testing of a location parameter using the Wilcoxon test, and the nonparametric Kruskal–Wallis test. Key words and phrases: Bayesian hypothesis testing, differential privacy, hypothesis testing, randomized response. 1. Introduction In this paper, we propose a method for testing hypotheses based on confidential data. It is conceptually simple, widely applicable, and can simultaneously attain high privacy levels and low type-I error rates. We work within the differential privacy framework (Dwork et al., 2006). From a data privacy perspective, differentially private algorithms are appealing because they are robust to deanonymization attacks (Dwork and Roth, 2014). From a statistical perspective, differentially private algorithms are useful because they facilitate inferences from private data. There is a growing body of literature on differentially private hypothesis testing. For example, Gaboardi et al. (2016) and Rogers and Kifer (2017) provide differentially private chi-squared tests, Couch et al. (2019) develop differentially private versions of nonparametric tests such as the Mann–Whitney and Kruskal– Wallis tests, and Barrientos et al. (2019), Pe˜na and Barrientos (2021), and Alabi and Vadhan (2022) propose methods for testing in linear regression models. Our proposed method applies the subsample and aggregate technique (Nissim, Raskhodnikova and Smith, 2007) to randomized response (Warner, 1965). The result is a general-purpose algorithm that can create differentially private *Corresponding author. E-mail: [email protected]