← Back to article

Equation 9 · How Training Data and Synthetic Data Actually Work

What does this equation mean?

Pr⁡[M(D)∈S]≤eε⋅Pr⁡[M(D′)∈S]+δ\Pr[\mathcal{M}(D) \in S] \le e^{\varepsilon} \cdot \Pr[\mathcal{M}(D') \in S] + \delta

Read the formula alongside the article passage below. Each part has a deeper page with its role in the equation, the supporting passage and nearby citations.

This equation states a bound: one expression must stay on the indicated side of the other under the article’s assumptions. Read the equation part by part below; each part has a contextual explanation and a link to its mathematical background.

Read it piece by piece

M\mathcal{M}

Symbol M

the training mechanism, D and D' are two datasets differing by exactly one record.

Understand this part →

DD

Symbol D

D is a part of this expression. Its role is fixed by the surrounding article and by the operations shown in the formula.

Understand this part →

SS

Symbol S

any set of possible outcomes.

Understand this part →

eεe^{\varepsilon}

Symbol e^varepsilon

eve^varepsilon is a part of this expression. Its role is fixed by the surrounding article and by the operations shown in the formula.

Understand this part →

δ\delta

Symbol delta

delta is a part of this expression. Its role is fixed by the surrounding article and by the operations shown in the formula.

Understand this part →

multiplication

multiplication

Multiply the quantities on either side.

Understand this part →

addition

addition

Add the term after the plus sign to the term or group before it.

Understand this part →

superscript

superscript

A raised number can be a power. When it is a label or bound, it selects a case or the upper limit of a sum; the formula’s structure distinguishes these uses.

Understand this part →

See an illustrated explanation →
Pr⁡\Pr

Probability operator

The probability operator gives the chance of the event named inside its brackets or parentheses.

Understand this part →

How to interpret it

Read this expression with the definitions, units, and assumptions supplied by the article.

What the article says around this equation

The final mechanism worth separating out is synthetic data generation aimed specifically at privacy rather than capability — producing a dataset that preserves the statistical properties of a sensitive real dataset (medical records, private communications) without preserving any individual record well enough to be re-identified. The standard mechanical tool here is differential privacy, formalized by Abadi and colleagues’ DP-SGD algorithm, which modifies ordinary stochastic gradient descent by clipping each individual training example’s gradient contribution to a bounded norm and then adding calibrated random noise before the aggregated update is applied [ 9 ] . The guarantee this produces…
Read the full surrounding passage
The final mechanism worth separating out is synthetic data generation aimed specifically at privacy rather than capability — producing a dataset that preserves the statistical properties of a sensitive real dataset (medical records, private communications) without preserving any individual record well enough to be re-identified. The standard mechanical tool here is differential privacy, formalized by Abadi and colleagues’ DP-SGD algorithm, which modifies ordinary stochastic gradient descent by clipping each individual training example’s gradient contribution to a bounded norm and then adding calibrated random noise before the aggregated update is applied [ 9 ] . The guarantee this produces is a specific, quantifiable one, expressed as a privacy budget: Pr⁡[M(D)∈S]≤eε⋅Pr⁡[M(D′)∈S]+δ\Pr[\mathcal{M}(D) \in S] \le e^{\varepsilon} \cdot \Pr[\mathcal{M}(D') \in S] + \delta. where M\mathcal{M} is the training mechanism, D and D' are two datasets differing by exactly one record, and S is any set of possible outcomes. In plain terms: the probability of any particular trained model (or any synthetic dataset it produces) coming out of the process is bounded so that it cannot depend too strongly, by a factor set by ε\varepsilon , on whether any one individual’s record was included or excluded. This is the load-bearing distinction between “privacy-preserving” as a marketing description and as an engineering guarantee: ε\varepsilon is a number a data controller chooses and can disclose, and a smaller ε\varepsilon buys a stronger guarantee at the cost of more injected noise and correspondingly lower utility in the resulting synthetic data or model [ 9 ] .

Read the equation in its article →

Sources cited in the surrounding passage

These citations give research context. Read each source to check which claims it supports.

Return to How Training Data and Synthetic Data Actually Work

See this formula across 1 published context →

Browse the mathematical compendium →