[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-detail-84093-en":3,"doc-seo-84093-105":30,"detail-sidebar-cat-0-en-105":91},{"code":4,"msg":5,"data":6},0,"success",{"doc_id":7,"user_id":8,"nickname":9,"user_avatar":10,"doc_module":4,"category_id":11,"category_name":12,"doc_title":13,"doc_description":14,"doc_content":15,"file_id":16,"file_url":17,"file_type":18,"file_size":19,"view_count":20,"is_deleted":4,"is_public":21,"is_downloadable":21,"audit_status":21,"page_count":22,"language":23,"language_code":24,"site_id":25,"html_lang":24,"table_of_contents":26,"faqs":27,"seo_title":13,"seo_description":14,"update_tm":28,"read_time":29},84093,1099514067438,"River Wang","https://ap-avatar.wpscdn.com/avatar/100002539ee87300030?x-image-process=image/resize,m_fixed,w_180,h_180&k=1780474512215547542",8,"Research & Report","Dithered Gaussian Mechanism for Randomness Efficient Differential Privacy","The work introduces the dithered Gaussian mechanism, a randomness-efficient alternative to the discrete Gaussian mechanism for differential privacy. It discretizes the private output rather than discretizing the noise distribution, treating this discretization as post-processing of the standard Gaussian mechanism to directly inherit its privacy guarantees. The construction reduces privacy-critical randomness by sampling discretized output values directly and separating randomness sources for critical sampling and public randomized discretization. Applied to DP-SGD, it enables cryptographically secure noise generation with reduced floating-point vulnerabilities and modest overhead.","arXiv :2607 .06320v 1 [ cs .CR] 7 Jul 2026  \nDithered Gaussian Mechanism for Randomness-Efficient Differential Privacy  \nNikita P. Kalinin  \nInstitute of Science and Technology Austria [nikita.kalinin@ist.ac.at](nikita.kalinin@ist.ac.at)  \nRasmus Pagh  \nBARC University of Copenhagen  \n[pagh@di.ku.dk](pagh@di.ku.dk)  \nAbstract  \nWe present the dithered Gaussian mechanism, a novel alternative to the discrete Gaussian mechanism for differential privacy that discretizes the private output rather than the noise distribution itself. By interpreting this discretization as post-processing of the Gaussian mechanism, our construction directly inherits the privacy guarantees of the standard Gaussian mechanism while avoiding vulnerabilities caused by finite-precision floating-point outputs. We show that the mechanism is provably randomness-efficient: by sampling the discretized output values directly, the number of high-quality random bits required for privacy can be reduced significantly and made independent of the noise level. This is achieved by separating the randomness into two sources: a high-quality source used for the privacy-critical sampling step, and a high-performance public source, possibly known to the adversary, that supplies the additional randomness needed for randomized discretization. This separation enables the use of cryptographically secure randomness without substantial performance loss. As an application, we study model training with DP-SGD and show that cryptographically secure noise generation with reduced exposure to floating-point vulnerabilities can be achieved with modest practical overhead.  \n1 Introduction  \nModern machine learning increasingly relies on sensitive individual-level data, making formal privacy guarantees essential. Differential privacy provides one such guarantee by limiting how much any single data point can influence the output of an algorithm. The Gaussian mechanism [18] is one of the most widely used primitives for ensuring differential privacy. It is especially central in private machine learning, where it forms the noise-addition step of differentially private stochastic gradient descent (DP-SGD) [1] . Despite its ubiquity, the Gaussian mechanism has important practical limitations. First, it is an idealized continuous mechanism, whereas real implementations run on finite-precision computers. As a result, a faithful implementation of a continuous Gaussian distribution is impossible: naive samplers can leave detectable “holes” in the set of representable floating-point values, creating privacy vulnerabilities of the kind first observed for the Laplace mechanism [39] and later identified for the Gaussian mechanism itself [33] . A second limitation is the amount of randomness required to sample Gaussian noise. In the ideal continuous model, exact sampling requires infinitely many random bits, while high-precision implementations can still require many random bits in practice. This cost becomes substantial at scale: recent efforts to train language models entirely under differential privacy, such as the VaultGemma 1B model, required quadrillions of Gaussian random draws and petabytes of randomness to obtain a formal privacy guarantee [46] . At this scale, randomness generation itself can become a bottleneck [20] . Several discrete-valued mechanisms, most prominently the discrete Gaussian mechanism [9], address finite-precision concerns by adding discrete noise. However, these mechanisms can still require many privacy-critical random bits. Moreover, because their privacy  \nPreprint.  \nguarantees do not directly follow from those of the continuous Gaussian mechanism, they require separate privacy analyses for composition and amplification by subsampling, making them difficult to use as drop-in replacements for Gaussian noise in DP-SGD. Unlike existing discrete mechanisms, which approximate Gaussian noise and typically require separate privacy analyses, our construction inherits the privacy gu","cbCaitf12IG7DLVH","https://ap.wps.com/l/cbCaitf12IG7DLVH","pdf",504033,4,1,25,"English","en",105,"# Introduction\n## Differential privacy and the Gaussian mechanism\n## Practical limitations: finite precision and randomness cost\n## Discrete mechanisms and their challenges\n## Contributions and overview of the dithered Gaussian mechanism\n## Application to DP-SGD","[{\"question\":\"What is the dithered Gaussian mechanism and how does it differ from discrete Gaussian mechanisms?\",\"answer\":\"It replaces Gaussian noise by rounding a dithered Gaussian output onto a discrete grid. Unlike discrete Gaussian mechanisms that approximate Gaussian noise and require separate analyses, it derives privacy guarantees directly from the standard Gaussian mechanism via post-processing.\"},{\"question\":\"How does the method achieve randomness efficiency?\",\"answer\":\"It samples directly from the discretized output distribution after conditioning on the public dither. Privacy-critical sampling uses high-quality private randomness, while a high-performance public source provides additional randomness for randomized discretization.\"},{\"question\":\"How is the mechanism applied in practice and what benefits are reported for DP-SGD?\",\"answer\":\"The mechanism is used as a drop-in replacement for the Gaussian noise step in DP-SGD. Experiments indicate cryptographically secure noise generation with reduced exposure to floating-point vulnerabilities, with roughly 30% overhead versus a non-cryptographic approach and about 20% versus cryptographically secure noise generation on CIFAR-10.\"}]",1784192719,63,{"code":4,"msg":31,"data":32},"ok",{"site_id":25,"language":24,"slug":33,"title":13,"keywords":34,"description":14,"schema_data":35,"social_meta":86,"head_meta":88,"extra_data":90,"updated_unix":28},"dithered-gaussian-mechanism-for-randomness-efficient-differential-privacy","",{"@graph":36,"@context":85},[37,53,68],{"@type":38,"itemListElement":39},"BreadcrumbList",[40,44,48,51],{"item":41,"name":42,"@type":43,"position":21},"https://docshare.wps.com","Home","ListItem",{"item":45,"name":46,"@type":43,"position":47},"https://docshare.wps.com/document/","Document",2,{"item":49,"name":12,"@type":43,"position":50},"https://docshare.wps.com/document/research-report/",3,{"item":52,"name":13,"@type":43,"position":20},"https://docshare.wps.com/document/dithered-gaussian-mechanism-for-randomness-efficient-differential-privacy/84093/",{"url":52,"name":13,"@type":54,"author":55,"headline":13,"publisher":57,"fileFormat":60,"inLanguage":24,"description":14,"dateModified":61,"datePublished":62,"encodingFormat":60,"isAccessibleForFree":63,"interactionStatistic":64},"DigitalDocument",{"name":9,"@type":56},"Person",{"url":41,"name":58,"@type":59},"DocShare","Organization","application/pdf","2026-07-27","2026-07-16",true,{"@type":65,"interactionType":66,"userInteractionCount":20},"InteractionCounter",{"@type":67},"ViewAction",{"@type":69,"mainEntity":70},"FAQPage",[71,77,81],{"name":72,"@type":73,"acceptedAnswer":74},"What is the dithered Gaussian mechanism and how does it differ from discrete Gaussian mechanisms?","Question",{"text":75,"@type":76},"It replaces Gaussian noise by rounding a dithered Gaussian output onto a discrete grid. Unlike discrete Gaussian mechanisms that approximate Gaussian noise and require separate analyses, it derives privacy guarantees directly from the standard Gaussian mechanism via post-processing.","Answer",{"name":78,"@type":73,"acceptedAnswer":79},"How does the method achieve randomness efficiency?",{"text":80,"@type":76},"It samples directly from the discretized output distribution after conditioning on the public dither. Privacy-critical sampling uses high-quality private randomness, while a high-performance public source provides additional randomness for randomized discretization.",{"name":82,"@type":73,"acceptedAnswer":83},"How is the mechanism applied in practice and what benefits are reported for DP-SGD?",{"text":84,"@type":76},"The mechanism is used as a drop-in replacement for the Gaussian noise step in DP-SGD. Experiments indicate cryptographically secure noise generation with reduced exposure to floating-point vulnerabilities, with roughly 30% overhead versus a non-cryptographic approach and about 20% versus cryptographically secure noise generation on CIFAR-10.","https://schema.org",{"og:url":52,"og:type":87,"og:title":13,"og:site_name":58,"og:description":14},"article",{"robots":89,"canonical":52},"index,follow",{"doc_id":7,"site_id":25},{"code":4,"msg":5,"data":92},[93,97,101,105,110,115,120,123,128,131,135],{"id":21,"doc_module":4,"doc_module_name":46,"category_name":94,"show_sort_weight":95,"slug":96},"Story & Novel",90,"story-novel",{"id":47,"doc_module":4,"doc_module_name":46,"category_name":98,"show_sort_weight":99,"slug":100},"Literature",80,"literature",{"id":20,"doc_module":4,"doc_module_name":46,"category_name":102,"show_sort_weight":103,"slug":104},"Exam",70,"exam",{"id":106,"doc_module":4,"doc_module_name":46,"category_name":107,"show_sort_weight":108,"slug":109},5,"Comic",60,"comic",{"id":111,"doc_module":4,"doc_module_name":46,"category_name":112,"show_sort_weight":113,"slug":114},6,"Technology",50,"technology",{"id":116,"doc_module":4,"doc_module_name":46,"category_name":117,"show_sort_weight":118,"slug":119},7,"Healthcare",40,"healthcare",{"id":11,"doc_module":4,"doc_module_name":46,"category_name":12,"show_sort_weight":121,"slug":122},30,"research-report",{"id":124,"doc_module":4,"doc_module_name":46,"category_name":125,"show_sort_weight":126,"slug":127},9,"Religion & Spirituality",20,"religion-spirituality",{"id":126,"doc_module":4,"doc_module_name":46,"category_name":129,"show_sort_weight":126,"slug":130},"World Cup","world-cup",{"id":132,"doc_module":4,"doc_module_name":46,"category_name":133,"show_sort_weight":132,"slug":134},10,"Lifestyle","lifestyle",{"id":136,"doc_module":4,"doc_module_name":46,"category_name":137,"show_sort_weight":106,"slug":138},19,"General","general"]