{ "schema_version": 1, "title": "Reproduction: Privacy Amplification in DP Zeroth-Order Optimization", "emoji": "🔐", "space_id": "snaykey/repro-dp-zeroth-order", "paper": { "openreview_id": "YBIGgUet07" }, "tags": [ "icml2026-repro", "paper-YBIGgUet07" ], "updated_at": "2026-08-02T00:00:00+00:00", "root": { "slug": "index", "title": "Reproduction: Privacy Amplification in DP Zeroth-Order Optimization", "file": "pages/index.md", "children": [ { "slug": "claim-1-thm32-hidden-state", "title": "For the hidden-state threat model, Theorem 3.2 establishes a Rényi differential privacy bound for zeroth-order optimization that improves with the number of coordinate-update directions K, in contrast to standard composition-based bounds (Theorem 3.2, Section 3).", "file": "pages/claim-1-thm32-hidden-state/page.md", "children": [] }, { "slug": "claim-2-cor33-closed-form", "title": "Corollary 3.3 gives a closed-form DP guarantee for strongly convex losses, epsilon = O(sqrt(Delta^2 log(1/delta)/(n^2 sigma^2) * min(T, M*R*n*sqrt(d)/(K*Delta)))), showing privacy loss saturates rather than growing with the number of iterations T (Corollary 3.3, Section 3.2).", "file": "pages/claim-2-cor33-closed-form/page.md", "children": [] }, { "slug": "claim-3-lem37-lem38-lipschitz-beta", "title": "Lemma 3.7 shows the zeroth-order update map has a (c1, c2)-generalized Lipschitz property, and Lemma 3.8 derives high-probability concentration bounds using a Beta(K/2, (d-K)/2) distribution to control the anisotropic noise introduced by directional perturbations (Lemma 3.7, Lemma 3.8, Section 3).", "file": "pages/claim-3-lem37-lem38-lipschitz-beta/page.md", "children": [] }, { "slug": "claim-4-lem39-wasserstein", "title": "Lemma 3.9 bounds the forward Wasserstein-infinity distance between adjacent privacy processes as W_infinity(w_t, w_t') <= min(2R, 2*eta*Delta*t/sqrt(K)), which underlies the shifted-divergence argument used to prove convergent (non-diverging) privacy loss over iterations (Lemma 3.9, Section 3).", "file": "pages/claim-4-lem39-wasserstein/page.md", "children": [] }, { "slug": "claim-5-thm31-baseline", "title": "Theorem 3.1 establishes a public-state baseline privacy bound via standard composition, epsilon = O(sqrt(Delta^2 log(1/delta) T/(n^2 sigma^2))) when the noise-blending parameter beta_t = 0, against which the hidden-state analysis (Theorem 3.2) is compared (Theorem 3.1, Section 3).", "file": "pages/claim-5-thm31-baseline/page.md", "children": [] }, { "slug": "executive-summary", "title": "executive-summary", "file": "pages/executive-summary/page.md", "children": [] }, { "slug": "conclusion", "title": "conclusion", "file": "pages/conclusion/page.md", "children": [] } ] } }