Differential Privacy: An Economic Method for Choosing Epsilon
arXiv:1402.3329 · doi:10.1109/CSF.2014.35
Abstract
Differential privacy is becoming a gold standard for privacy research; it offers a guaranteed bound on loss of privacy due to release of query results, even under worst-case assumptions. The theory of differential privacy is an active research area, and there are now differentially private algorithms for a wide range of interesting problems. However, the question of when differential privacy works in practice has received relatively little attention. In particular, there is still no rigorous method for choosing the key parameter , which controls the crucial tradeoff between the strength of the privacy guarantee and the accuracy of the published results. In this paper, we examine the role that these parameters play in concrete applications, identifying the key questions that must be addressed when choosing specific values. This choice requires balancing the interests of two different parties: the data analyst and the prospective participant, who must decide whether to allow their data to be included in the analysis. We propose a simple model that expresses this balance as formulas over a handful of parameters, and we use our model to choose on a series of simple statistical studies. We also explore a surprising insight: in some circumstances, a differentially private study can be more accurate than a non-private study for the same cost, under our model. Finally, we discuss the simplifying assumptions in our model and outline a research agenda for possible refinements.
References in corpus (6)
- Differential Privacy: An Economic Method for Choosing Epsilon
- A Theory of Pricing Private Data
- DPCube: Differentially Private Histogram Release through Multidimensional Partitioning
- Personalized Social Recommendations - Accurate or Private?
- PrivBasis: Frequent Itemset Mining with Differential Privacy
- Privacy Preserving Record Linkage via grams Projections
Cited by in corpus (41)
- RAPPOR: Randomized Aggregatable Privacy-Preserving Ordinal Response
- Technical Privacy Metrics: a Systematic Survey
- Differential Privacy: An Economic Method for Choosing Epsilon
- Privacy Loss in Apple's Implementation of Differential Privacy on MacOS 10.12
- The Long Road to Computational Location Privacy: A Survey
- Mutual Information Optimally Local Private Discrete Distribution Estimation
- Privacy and Confidentiality in Process Mining -- Threats and Research Challenges
- Guidelines for Implementing and Auditing Differentially Private Systems
- How to Balance Privacy and Money through Pricing Mechanism in Personal Data Market
- DP-BART for Privatized Text Rewriting under Local Differential Privacy
- Hypothesis Testing Interpretations and Renyi Differential Privacy
- Decision Tree Classification with Differential Privacy: A Survey
- Differential Privacy Techniques for Cyber Physical Systems: A Survey
- Local Obfuscation Mechanisms for Hiding Probability Distributions
- : Efficiently Querying Databases While Providing Differential Privacy
- Applications of Differential Privacy in Social Network Analysis: A Survey
- The Privacy-Utility Trade-off in the Topics API
- A novel analysis of utility in privacy pipelines, using Kronecker products and quantitative information flow
- On the Anonymization of Differentially Private Location Obfuscation
- An Incentive Mechanism for Trading Personal Data in Data Markets
- Effects of Differential Privacy and Data Skewness on Membership Inference Vulnerability
- Differentially-Private Counting of Users' Spatial Regions
- Rademacher Observations, Private Data, and Boosting
- On the Differential Private Data Market: Endogenous Evolution, Dynamic Pricing, and Incentive Compatibility
- Disclosure Risk from Homogeneity Attack in Differentially Private Frequency Distribution
- Mitigating Query-Flooding Parameter Duplication Attack on Regression Models with High-Dimensional Gaussian Mechanism
- Turbo: Effective Caching in Differentially-Private Databases
- General Inferential Limits Under Differential and Pufferfish Privacy
- Privacy-Preserving Directly-Follows Graphs: Balancing Risk and Utility in Process Mining
- Scalable Distributed Reproduction Numbers of Network Epidemics with Differential Privacy
- Lightweight Transformer in Federated Setting for Human Activity Recognition
- Privacy-Enhanced Database Synthesis for Benchmark Publishing (Technical Report)
- Establishing the Price of Privacy in Federated Data Trading
- Big data, differential privacy, and national statistical organisations
- Why Data Anonymization Has Not Taken Off
- Privacy Parameter Variation Using RAPPOR on a Malware Dataset
- The Influence of Differential Privacy on Short Term Electric Load Forecasting
- Testing Differential Privacy with Dual Interpreters
- Participation Cost Estimation: Private Versus Non-Private Study
- On Heuristic Models, Assumptions, and Parameters
- Learning Games and Rademacher Observations Losses