Privacy-Preserving Utility Verification of the Data Published by Non-Interactive Differentially Private Mechanisms

Privacy-Preserving Utility Verification of the Data Published by Non-Interactive Differentially Private Mechanisms
复制标题

非交互式差分隐私机制发布的数据的隐私保护实用程序验证

DOI:
10.1109/tifs.2016.2532839
复制
发表时间:
2016-10-01
影响因子:
6.8
通讯作者:
Zhong, Sheng
Zhong, Sheng
中科院分区:
计算机科学1区
文献类型:
--
作者:
Hua, Jingyu;Tang, An;Zhong, Sheng

文献摘要

被引文献

相似文献

在保护隐私的协作数据发布问题中,中央数据发布者负责聚合来自多方的敏感数据,然后在发布之前将其匿名以进行数据挖掘。在这种场景下,数据用户可能有强烈的需求来衡量已发布数据的效用,因为大多数匿名技术都会对数据效用产生副作用。然而,这项任务并不简单,因为效用测量通常需要汇总的原始数据,而出于隐私考虑,这些数据不会透露给数据用户。此外,数据发布者甚至可能在原始数据中作弊,因为包括个别提供者在内的任何人都不知道完整的数据集。在本文中,我们首先针对DiffPart提出了一种基于密码技术的隐私保护效用验证机制——一种针对集值数据设计的差分隐私方案。该提案可以根据聚合原始数据的加密频率而不是明文值来衡量数据效用,从而防止隐私泄露。此外,它还可以私下检查发布者提供的加密频率的正确性,这有助于检测不诚实的发布者。我们还将这种机制扩展到 DiffGen——另一种专为关系数据设计的差分隐私发布方案。我们的理论和实验评估证明了所提出机制的安全性和效率。
In the problem of privacy-preserving collaborative data publishing, a central data publisher is responsible for aggregating sensitive data from multiple parties and then anonymizing it before publishing for data mining. In such scenarios, the data users may have a strong demand to measure the utility of the published data, since most anonymization techniques have side effects on data utility. Nevertheless, this task is non-trivial, because the utility measuring usually requires the aggregated raw data, which is not revealed to the data users due to privacy concerns. Furthermore, the data publishers may even cheat in the raw data, since no one, including the individual providers, knows the full data set. In this paper, we first propose a privacy-preserving utility verification mechanism based upon cryptographic technique for DiffPart-a differentially private scheme designed for set-valued data. This proposal can measure the data utility based upon the encrypted frequencies of the aggregated raw data instead of the plain values, which thus prevents privacy breach. Moreover, it is enabled to privately check the correctness of the encrypted frequencies provided by the publisher, which helps detect dishonest publishers. We also extend this mechanism to DiffGen-another differentially private publishing scheme designed for relational data. Our theoretical and experimental evaluations demonstrate the security and efficiency of the proposed mechanism.