Higher-Order Approximate Relational Refinement Types for Mechanism Design and Differential Privacy
arXiv:1407.6845 · doi:10.1145/2676726.2677000
Abstract
Mechanism design is the study of algorithm design in which the inputs to the algorithm are controlled by strategic agents, who must be incentivized to faithfully report them. Unlike typical programmatic properties, it is not sufficient for algorithms to merely satisfy the property---incentive properties are only useful if the strategic agents also believe this fact. Verification is an attractive way to convince agents that the incentive properties actually hold, but mechanism design poses several unique challenges: interesting properties can be sophisticated relational properties of probabilistic computations involving expected values, and mechanisms may rely on other probabilistic properties, like differential privacy, to achieve their goals. We introduce a relational refinement type system, called , for verifying mechanism design and differential privacy. We show that is sound w.r.t. a denotational semantics, and correctly models -differential privacy; moreover, we show that it subsumes DFuzz, an existing linear dependent type system for differential privacy. Finally, we develop an SMT-based implementation of and use it to verify challenging examples of mechanism design, including auctions and aggregative games, and new proposed examples from differential privacy.
References in corpus (1)
Cited by in corpus (18)
- Proving Differential Privacy via Probabilistic Couplings
- LightDP: Towards Automating Differential Privacy Proofs
- Advanced Probabilistic Couplings for Differential Privacy
- Proving Differential Privacy with Shadow Execution
- Synthesizing Coupling Proofs of Differential Privacy
- A Semantic Account of Metric Preservation
- Proving Expected Sensitivity of Probabilistic Programs
- Coupling proofs are probabilistic product programs
- Approximate Span Liftings
- Differentially Private Bayesian Programming
- A Monadic Framework for Relational Verification: Applied to Information Security, Program Equivalence, and Optimizations
- Computer-aided verification in mechanism design
- Relational Cost Analysis for Functional-Imperative Programs
- Bidirectional Type Checking for Relational Properties
- The Complexity of Verifying Boolean Programs as Differentially Private
- Divergences on Monads for Relational Program Logics
- Cutting the Cake: A Language for Fair Division
- Approximate Algorithms for Verifying Differential Privacy with Gaussian Distributions