paper

Continual Learning With Participation Privacy: An Auditable Buffering-Aggregation Recipe

arXiv:2607.07209

Abstract

Modern federated and streaming learning systems often release intermediate models, so privacy must hold for the full trajectory under adaptive interaction. Motivated by participation privacy, we study single-edit neighboring user streams, where one insertion/deletion shifts all subsequent updates and defeats standard Hamming-neighbor continual-release analyses. We give an auditable modular recipe. A randomized buffering wrapper emits bins of size , reducing single-edit streams to a Hamming-style per-bin update stream with explicit backlog/delay guarantees, where is calibrated by the privacy parameters . We then prove a certification theorem identifying when a non-adaptive Hamming-neighbor DP proof for a continual primitive lifts to adaptive inputs: the primitive must use fresh per-round randomness and have a stable one-round privacy profile under common adaptive context. Together, these ingredients yield trajectory-level -DP for single-edit streams using standard primitives (e.g., tree prefix sums), with an explicit privacy--latency link via .

This version corrects and clarifies the independent-decomposability condition underlying the adaptive-safety result in the ICML 2026 paper, with corresponding revisions to the affected statements and proofs

Continual Learning With Participation Privacy: An Auditable Buffering-Aggregation Recipe · wovepaper