Profile-based Privacy for Locally Private Computations

Profile-based Privacy for Locally Private Computations
复制标题

用于本地私有计算的基于配置文件的隐私

DOI:
10.1109/isit.2019.8849549
复制
发表时间:
2019
期刊:
2019 IEEE International Symposium on Information Theory (ISIT)
影响因子:
--
通讯作者:
Kamalika Chaudhuri
Kamalika Chaudhuri
中科院分区:
--
文献类型:
--
作者:
J. Geumlek;Kamalika Chaudhuri

文献摘要

被引文献

相似文献

差分隐私已成为隐私保护数据分析中的黄金标准。一种广受欢迎的变体是局部差分隐私,在这种情况下数据持有者是受信任的管理者。然而,该模型更广泛应用的一个主要障碍在于,它在隐私 - 效用权衡方面表现不佳。在这项研究中,我们通过引入一种名为基于轮廓隐私的局部隐私新变体来解决这一问题。其核心思想是,问题设定伴随着一个数据生成分布的图G,图的边对那些应变得难以区分的敏感分布对进行编码。这能提供更高的效用,因为与局部差分隐私不同,我们不再需要使域中的每对隐私值都难以区分,而是仅保护潜在分布的身份。我们确立了基于轮廓隐私定义的隐私属性,如后处理不变性和适度组合性。最后,我们给出在此框架下具有隐私性的机制,并通过模拟表明,这些机制比相应的局部差分隐私机制能实现更高的效用。
Differential privacy has emerged as a gold standard in privacy-preserving data analysis. A popular variant is local differential privacy, where the data holder is the trusted curator. A major barrier, however, towards a wider adoption of this model is that it offers a poor privacy-utility trade-off.In this work, we address this problem by introducing a new variant of local privacy called profile-based privacy. The central idea is that the problem setting comes with a graph G of data generating distributions, whose edges encode sensitive pairs of distributions that should be made indistinguishable. This provides higher utility because unlike local differential privacy, we no longer need to make every pair of private values in the domain indistinguishable, and instead only protect the identity of the underlying distribution. We establish privacy properties of the profile-based privacy definition, such as post-processing invariance and graceful composition. Finally, we provide mechanisms that are private in this framework, and show via simulations that they achieve higher utility than the corresponding local differential privacy mechanisms.