BLENDER: Enabling Local Search with a Hybrid Differential Privacy Model
arXiv:1705.00831 · doi:10.29012/jpc.680
Abstract
We propose a hybrid model of differential privacy that considers a combination of regular and opt-in users who desire the differential privacy guarantees of the local privacy model and the trusted curator model, respectively. We demonstrate that within this model, it is possible to design a new type of blended algorithm for the task of privately computing the head of a search log. This blended approach provides significant improvements in the utility of obtained data compared to related work while providing users with their desired privacy guarantees. Specifically, on two large search click data sets, comprising 1.75 and 16 GB respectively, our approach attains NDCG values exceeding 95% across a range of privacy budget values.
Proceedings of the 26th USENIX Security Symposium (USENIX Security 17). August 16-18, 2017, Vancouver, BC. ISBN 978-1-931971-40-9
References in corpus (8)
- RAPPOR: Randomized Aggregatable Privacy-Preserving Ordinal Response
- Local, Private, Efficient Protocols for Succinct Histograms
- Extremal Mechanisms for Local Differential Privacy
- Discrete Distribution Estimation under Local Privacy
- Privacy Loss in Apple's Implementation of Differential Privacy on MacOS 10.12
- PrivBasis: Frequent Itemset Mining with Differential Privacy
- Differentially Private Testing of Identity and Closeness of Discrete Distributions
- Differentially Private Identity and Closeness Testing of Discrete Distributions