[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-detail-86394-en":3,"doc-seo-86394-105":30,"detail-sidebar-cat-0-en-105":91},{"code":4,"msg":5,"data":6},0,"success",{"doc_id":7,"user_id":8,"nickname":9,"user_avatar":10,"doc_module":4,"category_id":11,"category_name":12,"doc_title":13,"doc_description":14,"doc_content":15,"file_id":16,"file_url":17,"file_type":18,"file_size":19,"view_count":20,"is_deleted":4,"is_public":21,"is_downloadable":21,"audit_status":21,"page_count":22,"language":23,"language_code":24,"site_id":25,"html_lang":24,"table_of_contents":26,"faqs":27,"seo_title":13,"seo_description":14,"update_tm":28,"read_time":29},86394,16904993612988,"Olivia Brown","https://ap-avatar.wpscdn.com/davatar_a8503ba1806abce46bf441b54a3ca4cd",8,"Research & Report","Realisation-Level Privacy Filtering","Realisation-Level Privacy Filtering studies differential privacy for repeated database access through successive, possibly adaptive queries and mechanisms. It addresses conservatism in existing composition and privacy filters that aggregate worst-case per-round privacy parameters by introducing realisation-level accounting based on realised privacy loss. The paper presents a realisation-level filtering method that determines stopping times for data releases, proving an (ε,δ)-differential privacy guarantee where ε and δ are selected by the data handler. Numerical results show improved utility over mechanism-level approaches and applicability to arbitrary mechanisms, including those poorly behaved under Rnyi DP.","Realisation-Level Privacy Filtering  \nSophie Taylor, Praneeth Kumar Vippathalla, and Justin P. Coon  \narXiv :2604 .08630v2 [ cs .CR] 12 Jul 2026  \nAbstract—We study differentially private data release, where a database is accessed through successive, possibly adaptive queries and mechanisms. Existing composition theorems and privacy filters almost always combine worst case per-round privacy parameters, leaving room for more refined accounting based on realised privacy loss, which we term realisation-level accounting. We present a realisation-level filtering approach to determine stopping times for data releases, and design one such filter. Despite technical challenges arising from conditioning on realisations and stopping time, we prove that the filter guarantees (ϵ,δ)-differential privacy, with ϵ and δ chosen by the data handler. Through numerical evidence, we demonstrate that realisation-level filtering provides a path to better utility beyond mechanism-level methods. Furthermore, our proposed filter applies to arbitrary mechanisms, including those that are badly behaved under Rnyi differential privacy.  \nNote: This manuscript supersedes the earlier ISIT conference version. It contains updates and revisions. Readers are encouraged to use and cite this version.  \nI. INTRODUCTION  \nIn most privacy preserving applications, a database is subject to successive queries, and is therefore accessed more than once. In modern settings, queries and mechanisms are often adaptive, meaning they depend on previously released outputs. A key example is federated learning, where model training involves repeated access to data. In such systems, the sequence of queries and mechanisms may be generated by an adaptive training procedure. Moreover, each data access incurs a privacy loss, making adaptive privacy accounting essential. Hence, it is crucial that a system designer can quantify how privacy guarantees compose under multiple adaptive mechanism uses. Throughout this work, we take differential privacy (DP) as the privacy notion.  \nExisting approaches to privacy composition provide powerful guarantees in many contexts, but can be overly conservative in certain settings. Classical composition theorems bound the cumulative privacy loss without knowledge of mechanism outputs, commonly by combining known per-mechanism parameters [1]–[3] . Notably, Rnyi differential privacy (RDP) provides strong composition guarantees by leveraging the distribution of the privacy loss [4] and more recent FFT [5],[6] and saddle-point based [7] approaches refine this by directly  \nThe authors are with the Department of Engineering Science, University of Oxford, Oxford, U.K (e-mail: [sophie.taylor2@balliol.ox.ac.uk](sophie.taylor2@balliol.ox.ac.uk); [praneeth.vippathalla@eng.ox.ac.uk](praneeth.vippathalla@eng.ox.ac.uk); [justin.coon@eng.ox.ac.uk](justin.coon@eng.ox.ac.uk)). This research was funded in whole or in part by the Engineering and Physical Sciences Research Council under grant number EP/W524311/1, and the U. S. Army Research Laboratory and the U. S. Army Research Office under grant number W911NF-22-1-0070 . For the purpose of Open Access, the authors have applied a CC BY public copyright license to any Author Accepted Manuscript (AAM) version arising from this submission.  \ntargeting the tail probability of the privacy loss, the quantity that governs DP.1 In practice, RDP is used as an accounting tool, with privacy guarantees converted back to DP for reporting. Classical guarantees must be computed in advance and are independent of the realised mechanism outputs. Given a privacy budget, the number of allowable releases must be determined uniformly over all possible mechanism choices, rather than tailored to the specific sequence used. This can lead to very conservative stopping rules in adaptive scenarios. To tackle the adaptive setting, researchers have proposed the use of privacy filters, which may be DP based [8], [9] or RDP based [9], [10], and keep a ru","cbCaikwvCDfd0SEd","https://ap.wps.com/l/cbCaikwvCDfd0SEd","pdf",429057,4,1,7,"English","en",105,"# Introduction\n## Adaptive queries and privacy accounting\n## Privacy filters and mechanism-level vs realisation-level\n# Privacy Filtering\n## Adaptive data privacy problem setup","[{\"question\":\"What problem does realisation-level privacy filtering address?\",\"answer\":\"It targets differential privacy for databases accessed through successive, possibly adaptive queries, where cumulative privacy loss must be accounted for while adaptively deciding when to stop releasing data.\"},{\"question\":\"How does this approach differ from existing privacy filters?\",\"answer\":\"Existing filters typically combine worst-case per-round parameters using mechanism-level accounting. The proposed method tracks privacy loss pointwise at the realisation level, avoiding unnecessary conservatism when realised loss is smaller.\"},{\"question\":\"How is the privacy guarantee established?\",\"answer\":\"The paper designs a realisation-level filter and proves it satisfies (ε,δ)-differential privacy, with ε and δ chosen by the data handler, despite challenges from conditioning on realised outputs and stopping times.\"}]",1784211478,18,{"code":4,"msg":31,"data":32},"ok",{"site_id":25,"language":24,"slug":33,"title":13,"keywords":34,"description":14,"schema_data":35,"social_meta":86,"head_meta":88,"extra_data":90,"updated_unix":28},"realisation-level-privacy-filtering","",{"@graph":36,"@context":85},[37,53,68],{"@type":38,"itemListElement":39},"BreadcrumbList",[40,44,48,51],{"item":41,"name":42,"@type":43,"position":21},"https://docshare.wps.com","Home","ListItem",{"item":45,"name":46,"@type":43,"position":47},"https://docshare.wps.com/document/","Document",2,{"item":49,"name":12,"@type":43,"position":50},"https://docshare.wps.com/document/research-report/",3,{"item":52,"name":13,"@type":43,"position":20},"https://docshare.wps.com/document/realisation-level-privacy-filtering/86394/",{"url":52,"name":13,"@type":54,"author":55,"headline":13,"publisher":57,"fileFormat":60,"inLanguage":24,"description":14,"dateModified":61,"datePublished":62,"encodingFormat":60,"isAccessibleForFree":63,"interactionStatistic":64},"DigitalDocument",{"name":9,"@type":56},"Person",{"url":41,"name":58,"@type":59},"DocShare","Organization","application/pdf","2026-07-28","2026-07-16",true,{"@type":65,"interactionType":66,"userInteractionCount":20},"InteractionCounter",{"@type":67},"ViewAction",{"@type":69,"mainEntity":70},"FAQPage",[71,77,81],{"name":72,"@type":73,"acceptedAnswer":74},"What problem does realisation-level privacy filtering address?","Question",{"text":75,"@type":76},"It targets differential privacy for databases accessed through successive, possibly adaptive queries, where cumulative privacy loss must be accounted for while adaptively deciding when to stop releasing data.","Answer",{"name":78,"@type":73,"acceptedAnswer":79},"How does this approach differ from existing privacy filters?",{"text":80,"@type":76},"Existing filters typically combine worst-case per-round parameters using mechanism-level accounting. The proposed method tracks privacy loss pointwise at the realisation level, avoiding unnecessary conservatism when realised loss is smaller.",{"name":82,"@type":73,"acceptedAnswer":83},"How is the privacy guarantee established?",{"text":84,"@type":76},"The paper designs a realisation-level filter and proves it satisfies (ε,δ)-differential privacy, with ε and δ chosen by the data handler, despite challenges from conditioning on realised outputs and stopping times.","https://schema.org",{"og:url":52,"og:type":87,"og:title":13,"og:site_name":58,"og:description":14},"article",{"robots":89,"canonical":52},"index,follow",{"doc_id":7,"site_id":25},{"code":4,"msg":5,"data":92},[93,97,101,105,110,115,119,122,127,130,134],{"id":21,"doc_module":4,"doc_module_name":46,"category_name":94,"show_sort_weight":95,"slug":96},"Story & Novel",90,"story-novel",{"id":47,"doc_module":4,"doc_module_name":46,"category_name":98,"show_sort_weight":99,"slug":100},"Literature",80,"literature",{"id":20,"doc_module":4,"doc_module_name":46,"category_name":102,"show_sort_weight":103,"slug":104},"Exam",70,"exam",{"id":106,"doc_module":4,"doc_module_name":46,"category_name":107,"show_sort_weight":108,"slug":109},5,"Comic",60,"comic",{"id":111,"doc_module":4,"doc_module_name":46,"category_name":112,"show_sort_weight":113,"slug":114},6,"Technology",50,"technology",{"id":22,"doc_module":4,"doc_module_name":46,"category_name":116,"show_sort_weight":117,"slug":118},"Healthcare",40,"healthcare",{"id":11,"doc_module":4,"doc_module_name":46,"category_name":12,"show_sort_weight":120,"slug":121},30,"research-report",{"id":123,"doc_module":4,"doc_module_name":46,"category_name":124,"show_sort_weight":125,"slug":126},9,"Religion & Spirituality",20,"religion-spirituality",{"id":125,"doc_module":4,"doc_module_name":46,"category_name":128,"show_sort_weight":125,"slug":129},"World Cup","world-cup",{"id":131,"doc_module":4,"doc_module_name":46,"category_name":132,"show_sort_weight":131,"slug":133},10,"Lifestyle","lifestyle",{"id":135,"doc_module":4,"doc_module_name":46,"category_name":136,"show_sort_weight":106,"slug":137},19,"General","general"]