The Value of Privacy: Strategic Data Subjects, Incentive Mechanisms, and Fundamental Limits

The Value of Privacy: Strategic Data Subjects, Incentive Mechanisms, and Fundamental Limits
复制标题

隐私的价值:战略数据主体、激励机制和基本限制

DOI:
10.1145/3232863
复制
发表时间:
2018
影响因子:
1.2
通讯作者:
Zhang, Junshan
Zhang, Junshan
中科院分区:
--
文献类型:
--
作者:
Wang, Weina;Ying, Lei;Zhang, Junshan

文献摘要

相似文献

我们在一个交易私人数据的博弈论模型中研究了数据隐私的价值,在该模型中,数据收集者通过激励机制从战略数据主体(个人)那里购买私人数据。数据收集器的一个主要目标是从获取的数据中了解一些所需的信息。具体地说,这个信息是由一个基本的州来建模的,每个人的私人数据代表了他对这个州的了解。与大多数现有的隐私意识调查工作不同,我们的模型没有假设数据收集者是值得信任的。此外,个人完全控制自己的数据隐私,只报告其数据的隐私保护版本。在本文中,ε隐私单位的价值是通过所有非负支付机制中的最低支付来衡量的,在这种情况下,个人在纳什均衡下的最佳反应是以ε-本地差异隐私的方式报告他或她的数据。ε越高,报告的数据就越不隐私。我们推导出隐私权价值的下界和上界,它们随着数据主体的数量变得越来越大而渐近紧凑。具体地说,下限确保了不可能使用较低的支付来购买ε隐私单位,而上限是由我们设计的可实现的支付机制给出的。在这些基本限制的基础上,我们进一步推导了数据收集者达到给定的学习潜在状态的精度目标的最低总支付的下界和上界,并证明了所设计的机制的总支付至多是一个人的最低支付。
We study the value of data privacy in a game-theoretic model of trading private data, where a data collector purchases private data from strategic data subjects (individuals) through an incentive mechanism. One primary goal of the data collector is to learn some desired information from the elicited data. Specifically, this information is modeled by an underlying state, and the private data of each individual represents his of her knowledge about the state. Departing from most of the existing work on privacy-aware surveys, our model does not assume the data collector to be trustworthy. Further, an individual takes full control of his or her own data privacy and reports only a privacy-preserving version of his or her data.In this article, the value of ε units of privacy is measured by the minimum payment among all nonnegative payment mechanisms, under which an individual’s best response at a Nash equilibrium is to report his or her data in an ε-locally differentially private manner. The higher ε is, the less private the reported data is. We derive lower and upper bounds on the value of privacy that are asymptotically tight as the number of data subjects becomes large. Specifically, the lower bound assures that it is impossible to use a lower payment to buy ε units of privacy, and the upper bound is given by an achievable payment mechanism that we design. Based on these fundamental limits, we further derive lower and upper bounds on the minimum total payment for the data collector to achieve a given accuracy target for learning the underlying state and show that the total payment of the designed mechanism is at most one individual’s payment away from the minimum.