Statistical Data Privacy: A Song of Privacy and Utility

Statistical Data Privacy: A Song of Privacy and Utility
复制标题

DOI:
10.1146/annurev-statistics-033121-112921
复制
发表时间:
2023-01-01
影响因子:
7.9
通讯作者:
Seeman, Jeremy
Seeman, Jeremy
中科院分区:
数学1区
文献类型:
--
作者:
Slavkovic, Aleksandra;Seeman, Jeremy

文献摘要

被引文献

相似文献

为了量化开放数据共享需求的增加与敏感信息泄露的担忧之间的权衡,统计数据隐私(SDP)方法分析了基于机密数据清理输出的数据发布机制。两个主要的框架存在:统计披露控制(SDC)和最近的差异隐私(DP)。尽管框架不同,但SDC和DP在核心上都有相同的统计问题。对于推理问题,我们可以设计最佳的释放机制和相关的估计,满足披露风险措施的界限,或者我们可以调整现有的净化输出,以创建新的统计有效的和最佳的估计。无论设计或调整如何,在评价风险和效用时,来自机制输出的有效统计推断需要不确定性量化,以说明引入偏倚和/或方差的消毒机制的影响。在这篇评论中,我们讨论了共同的统计基础,SDC和DP,强调SDP的主要发展,并提出了令人兴奋的开放式研究问题的私人推理。
To quantify trade-offs between increasing demand for open data sharing and concerns about sensitive information disclosure, statistical data privacy (SDP) methodology analyzes data release mechanisms that sanitize outputs based on confidential data. Two dominant frameworks exist: statistical disclosure control (SDC) and the more recent differential privacy (DP). Despite framing differences, both SDC and DP share the same statistical problems at their core. For inference problems, either we may design optimal release mechanisms and associated estimators that satisfy bounds on disclosure risk measures, or we may adjust existing sanitized output to create new statistically valid and optimal estimators. Regardless of design or adjustment, in evaluating risk and utility, valid statistical inferences from mechanism outputs require uncertainty quantification that accounts for the effect of the sanitization mechanism that introduces bias and/or variance. In this review, we discuss the statistical foundations common to both SDC and DP, highlight major developments in SDP, and present exciting open research problems in private inference.