The power of synergy in differential privacy: Combining a small curator with local randomizers

The power of synergy in differential privacy: Combining a small curator with local randomizers
复制标题

DOI:
10.4230/lipics.itc.2020.14
复制
发表时间:
2019-12
期刊:
ArXiv
影响因子:
--
通讯作者:
A. Beimel;A. Korolova;Kobbi Nissim;Or Sheffet;Uri Stemmer
A. Beimel;A. Korolova;Kobbi Nissim;Or Sheffet;Uri Stemmer
中科院分区:
其他
文献类型:
--
作者:
A. Beimel;A. Korolova;Kobbi Nissim;Or Sheffet;Uri Stemmer

文献摘要

相似文献

出于弥合用于实际应用的差分隐私的本地和可信管理者模型之间的效用差距的愿望,我们发起了对由“Blender”引入的混合模型的理论研究[Avent等人,\ USENIX Security '17],其中在本地模型中工作的n个代理的差分私有协议由可以访问m个附加用户的数据的差分私有管理者辅助。我们专注于政权,其中m << n,并研究这种(m,n)-混合模型的新功能。我们发现,尽管事实上,混合模型增加了简单的假设测试的基本任务没有显着的新功能,有许多其他的任务(在广泛的参数范围内),可以在混合模型中解决,但不能解决无论是策展人或本地用户分开。此外,我们还展示了额外的任务,其中馆长和本地用户之间至少有一轮的互动是必要的-也就是说,没有这种互动的混合模型协议可以解决这些任务。两者合计,我们的研究结果表明,本地模型与一个小馆长的组合可以成为一个有前途的工具包的一部分,用于设计和实施差异隐私。
Motivated by the desire to bridge the utility gap between local and trusted curator models of differential privacy for practical applications, we initiate the theoretical study of a hybrid model introduced by "Blender" [Avent et al.,\ USENIX Security '17], in which differentially private protocols of n agents that work in the local-model are assisted by a differentially private curator that has access to the data of m additional users. We focus on the regime where m << n and study the new capabilities of this (m,n)-hybrid model. We show that, despite the fact that the hybrid model adds no significant new capabilities for the basic task of simple hypothesis-testing, there are many other tasks (under a wide range of parameters) that can be solved in the hybrid model yet cannot be solved either by the curator or by the local-users separately. Moreover, we exhibit additional tasks where at least one round of interaction between the curator and the local-users is necessary -- namely, no hybrid model protocol without such interaction can solve these tasks. Taken together, our results show that the combination of the local model with a small curator can become part of a promising toolkit for designing and implementing differential privacy.