Amirarsalan Moatazedian, Yauhen Yakimenka, Rémi A. Chou, Jörg Kliewer · Entropy 2026 · 2026
DOI: 10.3390/e28101054
Counts differ because each database indexes a different set of publications. We treat OpenAlex as the canonical count; Google Scholar is not shown (no API, and crawling it violates its ToS).
We study a privacy-preserving data-sharing setting where a privatizer transforms private data into a sanitized release observed by an authorized reconstructor and two unauthorized adversaries, each with access to side information correlated with the private data. An adversary is considered stronger when it estimates the private data more accurately, thereby achieving a lower estimation loss. The privatizer maximizes the estimation loss of the stronger adversary while keeping the reconstruction distortion within a distortion budget. The difficulty is that the identity of the stronger adversary can vary with the distortion budget. Thus, optimizing the privatizer against a single adversary selected in advance can overlook the other adversary when that adversary estimates the private data more accurately. This motivates a constrained minimax formulation that accounts for both adversaries at every distortion budget. Penalized alternating updates train the privatizer and estimators. To evaluate the algorithm, we study finite-alphabet, scalar-Gaussian, ten-component Gaussian-mixture, and MNIST settings. For these settings, we compute theoretical reference curves under their respective assumptions to assess the learned sanitization mechanisms. We prove local conditional convergence bounds for a single-adversary recursion with fixed stochastic-gradient steps.
No comments yet — start the discussion below.