Information Design for Differential Privacy
arXiv:2202.05452
Abstract
Firms and statistical agencies must protect the privacy of the individuals whose data they collect, analyze, and publish. These organizations often do so by using publication mechanisms that satisfy differential privacy. We consider the problem of choosing such a mechanism to maximize the value of its output to end users. We show that mechanisms which add conditionally independent noise to the statistic of interest -- like most of those used in practice -- are never without loss of generality when the statistic is a sum or average of magnitude data (e.g., income). But conversely, adding conditionally independent noise is always optimal when the statistic is a count of data entries with a certain characteristic, and the underlying database is drawn from a symmetric distribution (e.g., if individuals' data are i.i.d.). When, in addition, data users view higher actions and higher values of the statistic as complementary (e.g., their payoffs are supermodular), we show that the simple geometric mechanism is always optimal by using a novel comparative static that ranks information structures according to their usefulness in monotone decision problems.