On the `Semantics' of Differential Privacy: A Bayesian Formulation
arXiv:0803.3946 · doi:10.29012/jpc.v6i1.634
Abstract
Differential privacy is a definition of "privacy'" for algorithms that analyze and publish information about statistical databases. It is often claimed that differential privacy provides guarantees against adversaries with arbitrary side information. In this paper, we provide a precise formulation of these guarantees in terms of the inferences drawn by a Bayesian adversary. We show that this formulation is satisfied by both "vanilla" differential privacy as well as a relaxation known as (epsilon,delta)-differential privacy. Our formulation follows the ideas originally due to Dwork and McSherry [Dwork 2006]. This paper is, to our knowledge, the first place such a formulation appears explicitly. The analysis of the relaxed definition is new to this paper, and provides some concrete guidance for setting parameters when using (epsilon,delta)-differential privacy.
Older version of this paper was titled: "A Note on Differential Privacy: Defining Resistance to Arbitrary Side Information"
Cited by in corpus (17)
- An Economic Analysis of Privacy Protection and Statistical Accuracy as Social Choices
- Privacy Odometers and Filters: Pay-as-you-Go Composition
- Privacy Accounting and Quality Control in the Sage Differentially Private ML Platform
- Guidelines for Implementing and Auditing Differentially Private Systems
- Hypothesis Testing Interpretations and Renyi Differential Privacy
- Secure and Utility-Aware Data Collection with Condensed Local Differential Privacy
- Covariance-Aware Private Mean Estimation Without Private Covariance Estimation
- Hiding in the Crowd: A Massively Distributed Algorithm for Private Averaging with Malicious Adversaries
- Tight Lower Bounds for Differentially Private Selection
- A necessary and sufficient stability notion for adaptive generalization
- Local Information Privacy and Its Application to Privacy-Preserving Data Aggregation
- Correspondences between Privacy and Nondiscrimination: Why They Should Be Studied Together
- Private Graph Data Release: A Survey
- DiPPS: Differentially Private Propensity Scores for Bias Correction
- Bayesian Analysis of Privacy Attacks on GPS Trajectories
- Testing Differential Privacy with Dual Interpreters
- Generalization in the Face of Adaptivity: A Bayesian Perspective