Privacy-Utility Tradeoffs under Constrained Data Release Mechanisms

Privacy-Utility Tradeoffs under Constrained Data Release Mechanisms
复制标题

受限数据发布机制下的隐私与效用权衡

DOI:
--
复制
发表时间:
2017
期刊:
arXiv.org
影响因子:
--
通讯作者:
P. Ishwar
P. Ishwar
中科院分区:
--
文献类型:
--
作者:
Ye Wang;Y. O. Basciftci;P. Ishwar

文献摘要

被引文献

相似文献

隐私保护数据发布机制旨在同时最小化敏感数据的信息泄漏和有用数据的失真。敏感数据和有用数据之间的重复性导致了隐私-效用权衡,这与广义率失真问题有很强的联系。在这项工作中,我们研究了最佳的隐私效用权衡区域是如何影响的数据,直接作为输入的释放机制的约束。特别是,我们只考虑敏感数据的可用性,只考虑有用数据的可用性,以及两者(完整数据)。我们表明,一般的层次结构举行:权衡区域只敏感的数据是不大于该区域只提供有用的数据,这反过来又是显然不大于该区域的敏感和有用的数据。此外,我们确定的条件下,只给出有用的数据与给定的全部数据相吻合的权衡区域。这些都是基于敏感数据和有用数据之间的共同信息。我们建立这些结果一般家庭的隐私和实用措施,满足某些自然属性所需的任何合理的措施的隐私或实用。我们还发现了一个新的,微妙的方面的数据处理不平等的一般非对称隐私措施,并讨论其操作的相关性和影响。最后,我们推导出精确的封闭解析形式的表达式的隐私效用权衡对称依赖的敏感和有用的数据下的互信息和汉明失真作为各自的隐私和效用的措施。
Privacy-preserving data release mechanisms aim to simultaneously minimize information-leakage with respect to sensitive data and distortion with respect to useful data. Dependencies between sensitive and useful data results in a privacy-utility tradeoff that has strong connections to generalized rate-distortion problems. In this work, we study how the optimal privacy-utility tradeoff region is affected by constraints on the data that is directly available as input to the release mechanism. In particular, we consider the availability of only sensitive data, only useful data, and both (full data). We show that a general hierarchy holds: the tradeoff region given only the sensitive data is no larger than the region given only the useful data, which in turn is clearly no larger than the region given both sensitive and useful data. In addition, we determine conditions under which the tradeoff region given only the useful data coincides with that given full data. These are based on the common information between the sensitive and useful data. We establish these results for general families of privacy and utility measures that satisfy certain natural properties required of any reasonable measure of privacy or utility. We also uncover a new, subtler aspect of the data processing inequality for general non-symmetric privacy measures and discuss its operational relevance and implications. Finally, we derive exact closed-analytic-form expressions for the privacy-utility tradeoffs for symmetrically dependent sensitive and useful data under mutual information and Hamming distortion as the respective privacy and utility measures.