Equation 9 · How Training Data and Synthetic Data Actually Work
What does this equation mean?
Read the formula alongside the article passage below. Each part has a deeper page with its role in the equation, the supporting passage and nearby citations.
This equation states a bound: one expression must stay on the indicated side of the other under the article’s assumptions. Read the equation part by part below; each part has a contextual explanation and a link to its mathematical background.
Read it piece by piece
Symbol M
the training mechanism, D and D' are two datasets differing by exactly one record.
Symbol D
D is a part of this expression. Its role is fixed by the surrounding article and by the operations shown in the formula.
Symbol e^varepsilon
arepsilon is a part of this expression. Its role is fixed by the surrounding article and by the operations shown in the formula.
Symbol delta
delta is a part of this expression. Its role is fixed by the surrounding article and by the operations shown in the formula.
superscript
A raised number can be a power. When it is a label or bound, it selects a case or the upper limit of a sum; the formula’s structure distinguishes these uses.
See an illustrated explanation →Probability operator
The probability operator gives the chance of the event named inside its brackets or parentheses.
How to interpret it
Read this expression with the definitions, units, and assumptions supplied by the article.
What the article says around this equation
The final mechanism worth separating out is synthetic data generation aimed specifically at privacy rather than capability — producing a dataset that preserves the statistical properties of a sensitive real dataset (medical records, private communications) without preserving any individual record well enough to be re-identified. The standard mechanical tool here is differential privacy, formalized by Abadi and colleagues’ DP-SGD algorithm, which modifies ordinary stochastic gradient descent by clipping each individual training example’s gradient contribution to a bounded norm and then adding calibrated random noise before the aggregated update is applied [ 9 ] . The guarantee this produces…
Read the full surrounding passage
The final mechanism worth separating out is synthetic data generation aimed specifically at privacy rather than capability — producing a dataset that preserves the statistical properties of a sensitive real dataset (medical records, private communications) without preserving any individual record well enough to be re-identified. The standard mechanical tool here is differential privacy, formalized by Abadi and colleagues’ DP-SGD algorithm, which modifies ordinary stochastic gradient descent by clipping each individual training example’s gradient contribution to a bounded norm and then adding calibrated random noise before the aggregated update is applied [ 9 ] . The guarantee this produces is a specific, quantifiable one, expressed as a privacy budget: . where is the training mechanism, D and D' are two datasets differing by exactly one record, and S is any set of possible outcomes. In plain terms: the probability of any particular trained model (or any synthetic dataset it produces) coming out of the process is bounded so that it cannot depend too strongly, by a factor set by , on whether any one individual’s record was included or excluded. This is the load-bearing distinction between “privacy-preserving” as a marketing description and as an engineering guarantee: is a number a data controller chooses and can disclose, and a smaller buys a stronger guarantee at the cost of more injected noise and correspondingly lower utility in the resulting synthetic data or model [ 9 ] .
Sources cited in the surrounding passage
These citations give research context. Read each source to check which claims it supports.
Return to How Training Data and Synthetic Data Actually Work