Utility-Optimized Local Differential Privacy Mechanisms for Distribution Estimation

Utility-Optimized Local Differential Privacy Mechanisms for Distribution Estimation
复制标题

DOI:
--
复制
发表时间:
2018-07
期刊:
--
影响因子:
--
通讯作者:
Takao Murakami;Yusuke Kawamoto
Takao Murakami;Yusuke Kawamoto
中科院分区:
其他
文献类型:
--
作者:
Takao Murakami;Yusuke Kawamoto

文献摘要

被引文献

相似文献

LDP (Local Differential Privacy)在保护用户隐私的同时,被广泛用于估计个人数据的统计数据(例如,数据背后的分布)。虽然自民党不需要可信的第三方,但它认为所有的个人数据都同样敏感,这导致了过度的混淆,从而失去了效用。在本文中,我们引入了ULDP (Utility-optimized LDP)的概念,它只对敏感数据提供等同于LDP的隐私保证。我们首先考虑所有用户使用相同混淆机制的设置,并提出两种提供ULDP的机制:实用程序优化的随机响应和实用程序优化的RAPPOR。然后,我们考虑敏感数据和非敏感数据之间的区别可能因用户而异的设置。对于这种设置,我们提出了一种带有语义标签的个性化ULDP机制,以高实用的方式估计个人数据的分布,同时对每个用户的敏感信息保密。我们的理论和实验表明,当存在大量非敏感数据时,我们的机制比现有的LDP机制提供更高的效用。我们还表明,当大多数数据是非敏感数据时,我们的机制甚至提供了与低隐私制度下的非私有机制几乎相同的效用。
LDP (Local Differential Privacy) has been widely studied to estimate statistics of personal data (e.g., distribution underlying the data) while protecting users' privacy. Although LDP does not require a trusted third party, it regards all personal data equally sensitive, which causes excessive obfuscation hence the loss of utility. In this paper, we introduce the notion of ULDP (Utility-optimized LDP), which provides a privacy guarantee equivalent to LDP only for sensitive data. We first consider the setting where all users use the same obfuscation mechanism, and propose two mechanisms providing ULDP: utility-optimized randomized response and utility-optimized RAPPOR. We then consider the setting where the distinction between sensitive and non-sensitive data can be different from user to user. For this setting, we propose a personalized ULDP mechanism with semantic tags to estimate the distribution of personal data with high utility while keeping secret what is sensitive for each user. We show theoretically and experimentally that our mechanisms provide much higher utility than the existing LDP mechanisms when there are a lot of non-sensitive data. We also show that when most of the data are non-sensitive, our mechanisms even provide almost the same utility as non-private mechanisms in the low privacy regime.