Tunable Measures for Information Leakage and Applications to Privacy-Utility Tradeoffs

Tunable Measures for Information Leakage and Applications to Privacy-Utility Tradeoffs
复制标题

DOI:
10.1109/tit.2019.2935768
复制
发表时间:
2019-12-01
影响因子:
2.5
通讯作者:
Calmon, Flavio du Pin
Calmon, Flavio du Pin
中科院分区:
计算机科学2区
文献类型:
--
作者:
Liao, Jiachun;Kosut, Oliver;Calmon, Flavio du Pin

文献摘要

被引文献

相似文献

我们引入了一个可调的信息泄漏措施,称为最大α泄漏。该度量量化了对手从数据的发布中推断数据集的任何(潜在随机)函数的最大收益。反过来,对手的推理能力又由我们引入的一类对抗损失函数量化为α损失,α是[1,无穷大)布尔OR {无穷大}的元素。alpha的选择决定了具体的对抗行为,范围从细化alpha = 1的信念(关于数据的任何函数)到猜测alpha =无穷大的最可能值,同时细化alpha的信念的alpha阶矩。最大α泄漏然后量化在所有可能的数据函数上的α损失下的对抗增益。特别地,对于α = 1和α =无穷大的极值,最大α泄漏分别简化为互信息和最大泄漏。对于alpha是(1,无穷大)的元素,该度量被示出为α阶的Arimoto信道容量。我们表明,最大的α-泄漏满足数据处理不等式和次加性属性,从而允许一个弱的组合物的结果。在这些属性的基础上,我们使用最大α泄漏作为隐私措施和研究的问题,数据发布的隐私保证,其中发布的数据的效用是通过一个硬失真约束确保。与平均失真不同,硬失真提供了保真度的确定性保证。我们证明了在硬失真约束下,对于alpha > 1,最优机制与alpha无关,因此,对于所有alpha > 1的值,所得的最优折衷是相同的。最后,最大阿尔法泄漏作为隐私措施的可调性也说明了平均汉明失真作为实用措施的二进制数据。
We introduce a tunable measure for information leakage called maximal alpha-leakage. This measure quantifies the maximal gain of an adversary in inferring any (potentially random) function of a dataset from a release of the data. The inferential capability of the adversary is, in turn, quantified by a class of adversarial loss functions that we introduce as alpha-loss, alpha is an element of [1, infinity) boolean OR {infinity}. The choice of alpha determines the specific adversarial action and ranges from refining a belief (about any function of the data) for alpha = 1 to guessing the most likely value for alpha = infinity while refining the alpha th moment of the belief for alpha in between. Maximal alpha-leakage then quantifies the adversarial gain under alpha-loss over all possible functions of the data. In particular, for the extremal values of alpha = 1 and alpha = infinity, maximal alpha-leakage simplifies to mutual information and maximal leakage, respectively. For alpha is an element of (1, infinity) this measure is shown to be the Arimoto channel capacity of order alpha. We show that maximal alpha-leakage satisfies data processing inequalities and a sub-additivity property thereby allowing for a weak composition result. Building upon these properties, we use maximal alpha-leakage as the privacy measure and study the problem of data publishing with privacy guarantees, wherein the utility of the released data is ensured via a hard distortion constraint. Unlike average distortion, hard distortion provides a deterministic guarantee of fidelity. We show that under a hard distortion constraint, for alpha > 1 the optimal mechanism is independent of alpha, and therefore, the resulting optimal tradeoff is the same for all values of alpha > 1. Finally, the tunability of maximal alpha-leakage as a privacy measure is also illustrated for binary data with average Hamming distortion as the utility measure.