Differentially-private software frequency profiling under linear constraints
Differentially-private software frequency profiling under linear constraints
复制标题
线性约束下的差分私有软件频率分析
DOI:
10.1145/3428271
复制
发表时间:
2020
影响因子:
--
通讯作者:
Rountev, Atanas
中科院分区:
文献类型:
--
作者:
Zhang, Hailong;Hao, Yu;Latif, Sufian;Bassily, Raef;Rountev, Atanas
Differential privacy has emerged as a leading theoretical framework for privacy-preserving data gathering and analysis. It allows meaningful statistics to be collected for a population without revealing ``too much'' information about any individual member of the population. For software profiling, this machinery allows profiling data from many users of a deployed software system to be collected and analyzed in a privacy-preserving manner. Such a solution is appealing to many stakeholders, including software users, software developers, infrastructure providers, and government agencies.We propose an approach for differentially-private collection of frequency vectors from software executions. Frequency information is reported with the addition of random noise drawn from the Laplace distribution. A key observation behind the design of our scheme is that event frequencies are closely correlated due to the static code structure. Differential privacy protections must account for such relationships; otherwise, a seemingly-strong privacy guarantee is actually weaker than it appears. Motivated by this observation, we propose a novel and general differentially-private profiling scheme when correlations between frequencies can be expressed through linear inequalities. Using a linear programming formulation, we show how to determine the magnitude of random noise that should be added to achieve meaningful privacy protections under such linear constraints. Next, we develop an efficient instance of this general machinery for an important subclass of constraints. Instead of LP, our solution uses a reachability analysis of a constraint graph. As an exemplar, we employ this approach to implement differentially-private method frequency profiling for Android apps.Any differentially-private scheme has to balance two competing aspects: privacy and accuracy. Through an experimental study to characterize these trade-offs, we (1) show that our proposed randomization achieves much higher accuracy compared to related prior work, (2) demonstrate that high accuracy and high privacy protection can be achieved simultaneously, and (3) highlight the importance of linear constraints in the design of the randomization. These promising results provide evidence that our approach is a good candidate for privacy-preserving frequency profiling of deployed software.
登录
查看更多内容
DOI:
10.1145/1993498.1993551
发表时间:
2011-06
期刊:
--
影响因子:
--
作者:
Aditya Budi;D. Lo;Lingxiao Jiang;Lucia
通讯作者:
Aditya Budi;D. Lo;Lingxiao Jiang;Lucia
DOI:
--
发表时间:
2013
期刊:
影响因子:
--
作者:
M. Nielsen
通讯作者:
M. Nielsen
DOI:
10.1145/1007512.1007522
发表时间:
2004
期刊:
2011 33rd International Conference on Software Engineering (ICSE)
影响因子:
--
作者:
Sebastian G. Elbaum;M. Hardojo
通讯作者:
M. Hardojo
DOI:
--
发表时间:
2017-08
期刊:
--
影响因子:
--
作者:
Tianhao Wang;Jeremiah Blocki;Ninghui Li;S. Jha
通讯作者:
Tianhao Wang;Jeremiah Blocki;Ninghui Li;S. Jha
DOI:
10.1145/302405.302637
发表时间:
1999
期刊:
Proceedings of the 1999 International Conference on Software Engineering (IEEE Cat. No.99CB37002)
影响因子:
--
作者:
C. Pavlopoulou;M. Young
通讯作者:
M. Young