Simulatable auditing

Simulatable auditing
复制标题

DOI:
10.1145/1065167.1065183
复制
发表时间:
2005-06
期刊:
Proceedings of the twenty-fourth ACM SIGMOD-SIGACT-SIGART symposium on Principles of database systems
影响因子:
--
通讯作者:
K. Kenthapadi;Nina Mishra;Kobbi Nissim
K. Kenthapadi;Nina Mishra;Kobbi Nissim
中科院分区:
其他
文献类型:
--
作者:
K. Kenthapadi;Nina Mishra;Kobbi Nissim

文献摘要

被引文献

相似文献

给定一个包含个人隐私信息的数据集,我们考虑在线查询审计问题:给定一系列已经提出的关于数据的查询,它们对应的答案--其中每个答案要么是真答案,要么是“拒绝”。(如果透露答案会损害隐私)--并且给出新的查询,如果可能侵犯隐私,则拒绝回答,否则给出真实答案。一个相关的问题是离线审计问题,其中一个给定的查询序列和所有的真实答案,其目标是确定是否已经发生了隐私泄露。我们发现的根本问题是,离线审计问题的解决方案不能直接用于解决在线审计问题,因为查询拒绝可能会泄露信息。因此,我们引入了一个新的模型,称为模拟审计查询拒绝可证明不泄漏信息。我们证明,最大查询可以在这个模拟的范式下,隐私的经典定义,如果一个敏感的值被完全妥协,发生违反审计。我们还介绍了(部分)妥协的概率概念。我们的隐私定义要求敏感值位于某个小区间内的先验概率与后验概率(给定查询答案)没有太大差异。我们证明,总和查询可以在这个隐私定义下,以模拟的方式进行审计。
Given a data set consisting of private information about individuals, we consider the online query auditing problem: given a sequence of queries that have already been posed about the data, their corresponding answers -- where each answer is either the true answer or "denied" (in the event that revealing the answer compromises privacy) -- and given a new query, deny the answer if privacy may be breached or give the true answer otherwise. A related problem is the offline auditing problem where one is given a sequence of queries and all of their true answers and the goal is to determine if a privacy breach has already occurred.We uncover the fundamental issue that solutions to the offline auditing problem cannot be directly used to solve the online auditing problem since query denials may leak information. Consequently, we introduce a new model called simulatable auditing where query denials provably do not leak information. We demonstrate that max queries may be audited in this simulatable paradigm under the classical definition of privacy where a breach occurs if a sensitive value is fully compromised. We also introduce a probabilistic notion of (partial) compromise. Our privacy definition requires that the a-priori probability that a sensitive value lies within some small interval is not that different from the posterior probability (given the query answers). We demonstrate that sum queries can be audited in a simulatable fashion under this privacy definition.