-Information-theoretic Privacy Watchdog and Optimal Privatization Scheme
arXiv:2101.10551
Abstract
This paper proposes an -lift measure for data privacy and determines the optimal privatization scheme that minimizes the -lift in the watchdog method. To release data that is correlated with sensitive information , the ratio denotes the `lift' of the posterior belief on and quantifies data privacy. The -lift is proposed as the -norm of the lift: . This is a tunable measure: When , each lift is weighted by its likelihood of appearing in the dataset (w.r.t. the marginal probability ); For , -lift reduces to the existing maximum lift. To generate the sanitized data , we adopt the privacy watchdog method using -lift: Obtain containing all 's such that ; Apply the randomization to all , while all other are published directly. For the resulting -lift , it is shown that the Sibson mutual information is proportional to . We further define a stronger measure using the worst-case -lift: . We prove that the optimal randomization that minimizes both and is -invariant, i.e., for any probability distribution over . Numerical experiments show that -lift can provide flexibility in the privacy-utility tradeoff.