arXiv · 2606.17995
Differential Privacy of Gaussian Process Posterior Sampling
Abstract
We study the privacy of releasing posterior sample paths from a Gaussian process (GP) when the entire training set including covariates and responses is private. Unlike standard differential-privacy (DP) mechanisms that add external noise, posterior sampling is random by construction. We show that this intrinsic randomness yields DP guarantees by deriving explicit R\'enyi-DP bounds for GP posterior sample-path release. The bounds separate posterior-mean leakage from data-dependent posterior-covariance leakage showing that meaningful privacy depends sharply on effective ridge regularisation. We apply membership-inference attacks to show that empirical leakage follows the predicted dependence on regularisation, posterior variance and the number of released posterior sample-paths. Utility experiments on downstream posterior-sampling tasks identify noisy-observation regimes where privacy-compatible regularisation preserves useful decisions with modest utility loss. When stronger privacy is needed, the intrinsic guarantee can be sharpened by adding calibrated GP noise, providing an explicit additional privacy knob.
Explore related subjects
Keep this discovery
Explore connections, maps & timelines
Tomasz Maciazek. 2026-06-16. Differential Privacy of Gaussian Process Posterior Sampling. https://arxiv.org/abs/2606.17995
Cite the original work for its findings. Save a collection to share your selection of sources.