Outis: Crypto-Assisted Differential Privacy on Untrusted Servers

Outis: Crypto-Assisted Differential Privacy on Untrusted Servers
复制标题

Outis:不受信任服务器上的加密辅助差异隐私

DOI:
--
复制
发表时间:
2019
期刊:
arXiv.org
影响因子:
--
通讯作者:
S. Jha
S. Jha
中科院分区:
--
文献类型:
--
作者:
A. Chowdhury;Chenghong Wang;Xi He;Ashwin Machanavajjhala;S. Jha

文献摘要

被引文献

相似文献

差异隐私已成为实现数据分析中强大的隐私权的事实上的标准。数据所有者和输出的私人统计数据在后者中分别对其输入进行了随机,以确保当地模型具有差异性。但是,在本地模型中,对可信赖的数据收集器的需求是,与中央模型相比,差异性私有程序的准确性和算法表达式严格降低了。差异隐私系统((1)消除了像本地模型中对可信数据收集器的需求中央模型。一组数据转换和不同的私人测量隐私。差异化。我们证明了对不受信任的服务器进行实际差异分析的可行性,并在真实数据集上进行了广泛的经验评估。 chenghong.wang552@duke.edu‡xihe@uwaterloo.ca§ashwin@cs.duke.edu¶jha@cs.wisc.edu1 ar x IV:1 90 2。07 75 6V 1 [CS.C R] 2 0 Fe B 20 19
Differential privacy has steadily become the de-facto standard for achieving strong privacy guarantees in data analysis. It is typically implemented either in the “central" or “local" model. In the former, a trusted centralized server collects the records in the clear from the data owners and outputs differentially private statistics; while in the latter, the data owners individually randomize their inputs to ensure differential privacy. The local model has been popular as it dispenses with the need for a trusted data collector. This increased security in the local model, however, comes at the cost of strictly lower accuracy and restricted algorithmic expressibility for differentially private programs compared to the central model. In this work, we propose, Outis, a system for differential privacy that (1) eliminates the need for a trusted data collector like in the local model, but still (2) achieves the accuracy guarantees and algorithmic expressibility of DP programs of the central model. Outis achieves the “best of both worlds" by employing two non-colluding untrusted servers that run differentially private programs on encrypted data from data owners. Outis supports a rich class of differentially private programs that can be written in terms of a small set of data transformation and differentially private measurement primitives. Further, we propose optimizations that speed up computation on encrypted data by leveraging the fact that the final output is differentially private. We demonstrate the feasibility of Outis for practical differentially private analysis on untrusted servers with an extensive empirical evaluation on real datasets. Keywords-Differential Privacy, Crypto Service Provider, Linear Homomorphic Encryption, Secure Computation ∗amrita@cs.wisc.edu †chenghong.wang552@duke.edu ‡xihe@uwaterloo.ca §ashwin@cs.duke.edu ¶jha@cs.wisc.edu 1 ar X iv :1 90 2. 07 75 6v 1 [ cs .C R ] 2 0 Fe b 20 19