Distortion-Constrained Minimax Data Sanitization with Multiple Adversaries
We study a privacy-preserving data-sharing setting where a privatizer transforms private data into a sanitized release observed by an authorized reconstructor and two unauthorized adversaries, each with access to side information correlated with the private data. An adversary is considered stronger when it estimates the private data more accurately, thereby achieving a lower estimation loss. The privatizer maximizes the estimation loss of the stronger adversary while keeping the reconstruction distortion within a distortion budget. The difficulty is that the identity of the stronger adversary can vary with the distortion budget. Thus, optimizing the privatizer against a single adversary selected in advance can overlook the other adversary when that adversary estimates the private data more accurately. This motivates a constrained minimax formulation that accounts for both adversaries at every distortion budget. Penalized alternating updates train the privatizer and estimators. To evaluate the algorithm, we study finite-alphabet, scalar-Gaussian, ten-component Gaussian-mixture, and MNIST settings. For these settings, we compute theoretical reference curves under their respective assumptions to assess the learned sanitization mechanisms. We prove local conditional convergence bounds for a single-adversary recursion with fixed stochastic-gradient steps.
Authors
- Jörg Kliewer (ORCID: https://orcid.org/0000-0003-0942-8006)
- Rémi A. Chou (ORCID: https://orcid.org/0000-0003-4431-3175)
- Yauhen Yakimenka (ORCID: https://orcid.org/0000-0003-3030-2336)
- Amirarsalan Moatazedian
Institutions
- New Jersey Institute of Technology (US)
- The University of Texas at Arlington (US)
Publication Details
- Journal
- Entropy
- Published
- 2026-09-25
- DOI
- https://doi.org/10.3390/e28101054
- Primary Topic
- Privacy-Preserving Technologies in Data
- Type
- article
- Field-Weighted Citation Impact
- 0.00