The Privacy Price of Tail-Risk Learning: Effective Tail Sample Size in Differentially Private CVaR Optimization
Organizations: School of Engineering, Institute of Science Tokyo, Yokohama, Kanagawa 226-8501, Japan
Abstract
Differential privacy changes the effective sample size governing CVaR learning. For tail mass , the privacy-relevant sample size is not , but ; equivalently, the effective private tail sample size is . Private CVaR excess risk decomposes into ordinary tail-risk statistical error and a privacy price. This decomposition is complete for scalar estimation and finite classes: scalar estimation has rate , and finite classes of size have rate . These complete rates hold under pure DP, and their lower bounds extend to approximate DP in the stated small- regimes. For convex Lipschitz learning, modular upper and lower reductions show that the CVaR-specific privacy term necessarily scales as , with dimension dependence inherited from private stochastic convex optimization. Together, these results identify ordinary private learning on informative tail records as the canonical hard subproblem inside private CVaR learning.