A Framework for Adaptive Di erential Privacy

A Framework for Adaptive Di erential Privacy
复制标题

自适应差分隐私框架

DOI:
--
复制
发表时间:
2017
期刊:
影响因子:
--
通讯作者:
B. Pierce
B. Pierce
中科院分区:
--
文献类型:
--
作者:
Daniel Winograd;Andreas Haeberlen;Aaron Roth;B. Pierce

文献摘要

被引文献

相似文献

差异隐私是一种被广泛研究的理论,用于分析具有强大隐私保证的敏感数据-个人数据的任何变化都只能对结果产生很小的统计影响-并且越来越多的编程语言现在支持差异隐私数据分析。这些语言的一个共同缺点是对自适应性的支持不足。在实践中,数据分析师很少希望在敏感数据库上运行一个函数,甚至也不希望使用固定隐私参数的预定函数序列;相反,她希望参与交互,在每个步骤中,下一个函数及其隐私参数的选择都由先前函数的结果通知。现有的语言使用一个简单的复合定理来支持这种情况,这通常会对复合函数的实际隐私成本给出相当宽松的界限,从而大大减少了在给定隐私预算内可以执行的计算量。分布式隐私理论包括其他具有更好边界的定理,但这些尚未被纳入编程语言。我们提出了一个新的框架,自适应组合,是优雅的,实用的,可实现的。它包括基于Rogers et al.(2016)的隐私过滤器的类型化函数编程的重新表述,以及该框架在一种名为Adaptive Fuzz的新语言的设计和实现中的具体实现。Adaptive Fuzz将Fuzz的核心静态类型系统(Haeberlen et al. 2011)移植到自适应设置中,将Fuzz类型检查器和运行时系统包装在外部自适应层中,允许Fuzz程序在y上方便地构造和类型检查。我们描述了自适应模糊解释器和报告结果,从两个案例研究表明其ectiveness实现常见的统计算法在真实的数据集。
Di erential privacy is a widely studied theory for analyzing sensitive data with a strong privacy guarantee— any change in an individual’s data can have only a small statistical e ect on the result—and a growing number of programming languages now support di erentially private data analysis. A common shortcoming of these languages is poor support for adaptivity. In practice, a data analyst rarely wants to run just one function over a sensitive database, nor even a predetermined sequence of functions with xed privacy parameters; rather, she wants to engage in an interaction where, at each step, both the choice of the next function and its privacy parameters are informed by the results of prior functions. Existing languages support this scenario using a simple composition theorem, which often gives rather loose bounds on the actual privacy cost of composite functions, substantially reducing how much computation can be performed within a given privacy budget. The theory of di erential privacy includes other theorems with much better bounds, but these have not yet been incorporated into programming languages. We propose a novel framework for adaptive composition that is elegant, practical, and implementable. It consists of a reformulation based on typed functional programming of the privacy lters of Rogers et al. (2016), together with a concrete realization of this framework in the design and implementation of a new language, called Adaptive Fuzz. Adaptive Fuzz transplants the core static type system of Fuzz (Haeberlen et al. 2011) to the adaptive setting by wrapping the Fuzz typechecker and runtime system in an outer adaptive layer, allowing Fuzz programs to be conveniently constructed and typechecked on the y. We describe an interpreter for Adaptive Fuzz and report results from two case studies demonstrating its e ectiveness for implementing common statistical algorithms over real data sets.