[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-detail-83203-en":3,"doc-seo-83203-105":30,"detail-sidebar-cat-0-en-105":95},{"code":4,"msg":5,"data":6},0,"success",{"doc_id":7,"user_id":8,"nickname":9,"user_avatar":10,"doc_module":4,"category_id":11,"category_name":12,"doc_title":13,"doc_description":14,"doc_content":15,"file_id":16,"file_url":17,"file_type":18,"file_size":19,"view_count":20,"is_deleted":4,"is_public":21,"is_downloadable":21,"audit_status":21,"page_count":22,"language":23,"language_code":24,"site_id":25,"html_lang":24,"table_of_contents":26,"faqs":27,"seo_title":13,"seo_description":14,"update_tm":28,"read_time":29},83203,1374391974468,"Eden","https://ap-avatar.wpscdn.com/davatar_29158cc5080c5b710cf443261637dec0",8,"Research & Report","Continual Learning With Participation Privacy: An Auditable Buffering-Aggregation Recipe","Modern federated and streaming learning systems release intermediate model snapshots, so privacy must protect the entire learning trajectory under adaptive interaction. Motivated by participation privacy, the work studies single-edit neighboring user streams, where one insertion or deletion shifts all subsequent updates and invalidates standard Hamming-neighbor continual-release analysis. It provides an auditable modular recipe using randomized buffering to reduce edit-neighbor streams to per-bin Hamming-style updates with explicit backlog and delay. A certification theorem specifies when non-adaptive Hamming-neighbor DP proofs lift to adaptive inputs, yielding trajectory-level (ε,δ)-DP for single-edit streams and an explicit privacy–latency tradeoff via the buffering parameter U.","arXiv :2607 .07209v 1 [ cs .CR] 8 Jul 2026  \nContinual Learning With Participation Privacy: An Auditable  \nBuffering-Aggregation Recipe  \nT-H. Hubert Chan 1 Elaine Shi2 Mengshi Zhao 1 Mingxun Zhou3  \n1 The University of Hong Kong, Hong Kong, China  \n2 Carnegie Mellon University, Pittsburgh, USA  \n3 The Hong Kong University of Science and Technology, Hong Kong, China  \nAbstract  \nModern federated and streaming learning systems often release intermediate models, so privacy must hold for the full trajectory under adaptive interaction. Motivated by participation privacy, we study single-edit neighboring user streams, where one insertion/deletion shifts all subsequent updates and defeats standard Hamming-neighbor continual-release analyses. We give an auditable modular recipe. A randomized buffering wrapper emits bins of size [U,2U], reducing single-edit streams to a Hamming-style per-bin update stream with explicit backlog/delay guarantees, where U is calibrated by the privacy parameters (ε,δ) . We then prove a certification theorem identifying when a non-adaptive Hamming-neighbor DP proof for a continual primitive lifts to adaptive inputs: the primitive must use fresh per-round randomness and have a stable one-round privacy profile under common adaptive context. Together, these ingredients yield trajectory-level (ε,δ)-DP for single-edit streams using standard primitives (e.g., tree prefix sums), with an explicit privacy–latency link via U.  \n1 Introduction  \nModern federated and streaming learning systems release intermediate model snapshots throughout training, so an adversary may observe the entire trajectory (w(t))t≥0 rather than only a final model. A canonical instance is streaming stochastic gradient descent (SGD): at step t, a user contributesa private loss function ft and the learner updates using a gradient step based on the current model [TS13,KMS+21] . Beyond protecting the data within each ft, some deployments also require participation privacy: a user may wish to ensure plausible deniability of whether they participated at all. This motivates single-edit (edit-distance) neighboring streams, where two user-update streams are neighbors if one can be obtained from the other by inserting or deleting a single user event.  \nContinual release also makes the learning process intrinsically interactive: the released model w (t) influences what happens next, so the update stream can be adaptively generated in response to prior outputs. While classical continual-release primitives such as tree-based private prefix sums [DNPR10,CSS11] were originally analyzed under statically chosen (Hamming-neighbor) streams, recent work formalizes differential privacy against such adaptive interaction [JRSS23] . Our goal is to make this adaptive viewpoint compatible with the single-edit participation model above.  \nThe difficulty is that Hamming-style neighboring streams are not the right abstraction for participation privacy on a stream. Most continual DP analyses change the value at a single time index t0 while keeping all other positions aligned [Dwo06] . In contrast, a single insertion/deletion shifts the alignment of all subsequent positions, so an edit-neighbor pair can be far from Hammingneighboring. This also undermines deterministic batching: partitioning the stream into fixed contiguous blocks can cause one edit to shift many later batch boundaries, so standard Hammingneighbor continual DP guarantees do not directly transfer.  \nTo address this mismatch, we use a simple modular recipe: randomized buffering and an adaptive-safety certification for downstream continual primitives. We apply a randomized buffering wrapper [CCMS22, ZSCM23] that introduces random delay and releases user updates in bins of controlled size (e.g., in [U,2U]); here U is a privacy-implied systems cost, calibrated by the target (ε,δ) and inducing delay. We then invoke standard continual DP primitives (e.g., tree/prefix-sum) to privately aggregate the resulting vect","cbCaifSDPvZKPqjS","https://ap.wps.com/l/cbCaifSDPvZKPqjS","pdf",628792,2,1,44,"English","en",105,"# Abstract\n# Introduction\n## Participation privacy in continual and streaming learning\n## Single-edit neighboring streams vs Hamming neighbors\n## Modular solution: randomized buffering and adaptive-safety certification\n# Contributions\n## Edit-neighbor continual learning under feedback\n## Modular pipeline with privacy-to-latency link\n## Certification theorem for adaptive safety of continual DP primitives\n# Results and organization","[{\"question\":\"What does “participation privacy” mean in this continual learning setting?\",\"answer\":\"It requires that a user cannot be distinguished as having participated based on the released sequence of intermediate models, modeled via single-edit (insertion/deletion) neighboring streams.\"},{\"question\":\"Why do standard Hamming-neighbor continual DP analyses not work for participation privacy?\",\"answer\":\"A single insertion or deletion shifts the alignment of all later updates, so an edit-neighbor pair can be far from Hamming-neighboring, breaking assumptions used in typical analyses.\"},{\"question\":\"How does randomized buffering enable auditable privacy for edit-neighbor streams?\",\"answer\":\"Random delay groups updates into bins of size [U, 2U], transforming the single-edit stream into a Hamming-style per-bin update stream with explicit backlog/delay guarantees calibrated by (ε,δ).\"},{\"question\":\"When can a non-adaptive Hamming-neighbor DP proof be reused under adaptive feedback?\",\"answer\":\"When the continual primitive uses fresh per-round randomness and satisfies a stable-context condition ensuring that adaptive interaction does not change the privacy cost of the unique Hamming discrepancy.\"}]",1784185932,111,{"code":4,"msg":31,"data":32},"ok",{"site_id":25,"language":24,"slug":33,"title":13,"keywords":34,"description":14,"schema_data":35,"social_meta":90,"head_meta":92,"extra_data":94,"updated_unix":28},"continual-learning-with-participation-privacy-an-auditable-buffering-aggregation-recipe","",{"@graph":36,"@context":89},[37,53,68],{"@type":38,"itemListElement":39},"BreadcrumbList",[40,44,47,50],{"item":41,"name":42,"@type":43,"position":21},"https://docshare.wps.com","Home","ListItem",{"item":45,"name":46,"@type":43,"position":20},"https://docshare.wps.com/document/","Document",{"item":48,"name":12,"@type":43,"position":49},"https://docshare.wps.com/document/research-report/",3,{"item":51,"name":13,"@type":43,"position":52},"https://docshare.wps.com/document/continual-learning-with-participation-privacy-an-auditable-buffering-aggregation-recipe/83203/",4,{"url":51,"name":13,"@type":54,"author":55,"headline":13,"publisher":57,"fileFormat":60,"inLanguage":24,"description":14,"dateModified":61,"datePublished":62,"encodingFormat":60,"isAccessibleForFree":63,"interactionStatistic":64},"DigitalDocument",{"name":9,"@type":56},"Person",{"url":41,"name":58,"@type":59},"DocShare","Organization","application/pdf","2026-07-24","2026-07-16",true,{"@type":65,"interactionType":66,"userInteractionCount":20},"InteractionCounter",{"@type":67},"ViewAction",{"@type":69,"mainEntity":70},"FAQPage",[71,77,81,85],{"name":72,"@type":73,"acceptedAnswer":74},"What does “participation privacy” mean in this continual learning setting?","Question",{"text":75,"@type":76},"It requires that a user cannot be distinguished as having participated based on the released sequence of intermediate models, modeled via single-edit (insertion/deletion) neighboring streams.","Answer",{"name":78,"@type":73,"acceptedAnswer":79},"Why do standard Hamming-neighbor continual DP analyses not work for participation privacy?",{"text":80,"@type":76},"A single insertion or deletion shifts the alignment of all later updates, so an edit-neighbor pair can be far from Hamming-neighboring, breaking assumptions used in typical analyses.",{"name":82,"@type":73,"acceptedAnswer":83},"How does randomized buffering enable auditable privacy for edit-neighbor streams?",{"text":84,"@type":76},"Random delay groups updates into bins of size [U, 2U], transforming the single-edit stream into a Hamming-style per-bin update stream with explicit backlog/delay guarantees calibrated by (ε,δ).",{"name":86,"@type":73,"acceptedAnswer":87},"When can a non-adaptive Hamming-neighbor DP proof be reused under adaptive feedback?",{"text":88,"@type":76},"When the continual primitive uses fresh per-round randomness and satisfies a stable-context condition ensuring that adaptive interaction does not change the privacy cost of the unique Hamming discrepancy.","https://schema.org",{"og:url":51,"og:type":91,"og:title":13,"og:site_name":58,"og:description":14},"article",{"robots":93,"canonical":51},"index,follow",{"doc_id":7,"site_id":25},{"code":4,"msg":5,"data":96},[97,101,105,109,114,119,124,127,132,135,139],{"id":21,"doc_module":4,"doc_module_name":46,"category_name":98,"show_sort_weight":99,"slug":100},"Story & Novel",90,"story-novel",{"id":20,"doc_module":4,"doc_module_name":46,"category_name":102,"show_sort_weight":103,"slug":104},"Literature",80,"literature",{"id":52,"doc_module":4,"doc_module_name":46,"category_name":106,"show_sort_weight":107,"slug":108},"Exam",70,"exam",{"id":110,"doc_module":4,"doc_module_name":46,"category_name":111,"show_sort_weight":112,"slug":113},5,"Comic",60,"comic",{"id":115,"doc_module":4,"doc_module_name":46,"category_name":116,"show_sort_weight":117,"slug":118},6,"Technology",50,"technology",{"id":120,"doc_module":4,"doc_module_name":46,"category_name":121,"show_sort_weight":122,"slug":123},7,"Healthcare",40,"healthcare",{"id":11,"doc_module":4,"doc_module_name":46,"category_name":12,"show_sort_weight":125,"slug":126},30,"research-report",{"id":128,"doc_module":4,"doc_module_name":46,"category_name":129,"show_sort_weight":130,"slug":131},9,"Religion & Spirituality",20,"religion-spirituality",{"id":130,"doc_module":4,"doc_module_name":46,"category_name":133,"show_sort_weight":130,"slug":134},"World Cup","world-cup",{"id":136,"doc_module":4,"doc_module_name":46,"category_name":137,"show_sort_weight":136,"slug":138},10,"Lifestyle","lifestyle",{"id":140,"doc_module":4,"doc_module_name":46,"category_name":141,"show_sort_weight":110,"slug":142},19,"General","general"]