← All parts of this equation

Equation 9 · Part 1 · How Training Data and Synthetic Data Actually Work

Symbol M

Pr⁡[M(D)∈S]≤eε⋅Pr⁡[M(D′)∈S]+δ\Pr[\mathcal{M}(D) \in S] \le e^{\varepsilon} \cdot \Pr[\mathcal{M}(D') \in S] + \delta
M\mathcal{M}

What this part means

the training mechanism, D and D' are two datasets differing by exactly one record.

Its job in the formula

M is a part of this expression. Its role is fixed by the surrounding article and by the operations shown in the formula.

Where the article explains it

where M\mathcal{M} is the training mechanism, D and D' are two datasets differing by exactly one record, and S is any set of possible outcomes.

The passage around this formula

…bounded norm and then adding calibrated random noise before the aggregated update is applied [ 9 ] . The guarantee this produces is a specific, quantifiable one, expressed as a privacy budget: Pr⁡[M(D)∈S]≤eε⋅Pr⁡[M(D′)∈S]+δ\Pr[\mathcal{M}(D) \in S] \le e^{\varepsilon} \cdot \Pr[\mathcal{M}(D') \in S] + \delta. where M\mathcal{M} is the training mechanism, D and D' are two datasets differing by exactly one record, and S is any set of possible outcomes. In plain terms: the probability of any particular trained model (or any synthetic dataset it produces) coming out of the process is bounded so that it cannot…

Read this part in the article →

Learn the underlying idea

A function assigns an output to each allowed input. The expression f(x) means “apply f to x”.

Open the illustrated functions: inputs become outputs guide →

See this notation across published equations →

Sources cited in the surrounding passage

These citations provide research context; check each source for the exact claim it supports.