Affiliation:
1. Penn State University, PA
Abstract
In statistical privacy,
utility
refers to two concepts:
information preservation,
how much statistical information is retained by a sanitizing algorithm, and
usability,
how (and with how much difficulty) one extracts this information to build statistical models, answer queries, and so forth. Some scenarios incentivize a separation between information preservation and usability, so that the data owner first chooses a sanitizing algorithm to maximize a measure of information preservation, and, afterward, the data consumers process the sanitized output according to their various individual needs [Ghosh et al. 2009; Williams and McSherry 2010].
We analyze the information-preserving properties of utility measures with a combination of two new and three existing utility axioms and study how violations of an axiom can be fixed. We show that the average (over possible outputs of the sanitizer) error of Bayesian decision makers forms the unique class of utility measures that satisfy all of the axioms. The axioms are agnostic to Bayesian concepts such as subjective probabilities and hence strengthen support for Bayesian views in privacy research. In particular, this result connects information preservation to aspects of usability—if the information preservation of a sanitizing algorithm should be measured as the average error of a Bayesian decision maker, shouldn’t Bayesian decision theory be a good choice when it comes to using the sanitized outputs for various purposes? We put this idea to the test in the unattributed histogram problem where our decision-theoretic postprocessing algorithm empirically outperforms previously proposed approaches.
Funder
NSF
National Science Foundation
Publisher
Association for Computing Machinery (ACM)
Reference50 articles.
1. John M. Abowd and Simon D. Woodcock. 2001. Disclosure limitation in longitudinal linked data. Confidentiality Disclosure and Data Access: Theory and Practical Applications for Statistical Agencies (2001) 215--277. John M. Abowd and Simon D. Woodcock. 2001. Disclosure limitation in longitudinal linked data. Confidentiality Disclosure and Data Access: Theory and Practical Applications for Statistical Agencies (2001) 215--277.
2. Charu C. Aggarwal. 2008. On unifying privacy and uncertain data models. In ICDE. 10.1109/ICDE.2008.4497447 Charu C. Aggarwal. 2008. On unifying privacy and uncertain data models. In ICDE. 10.1109/ICDE.2008.4497447
3. Mário S. Alvim Miguel E. Andrés Konstantinos Chatzikokolakis Pierpaolo Degano and Catuscia Palamidessi. 2011b. Differential privacy: On the trade-off between utility and information leakage. http://arxiv.org/abs/1103.5188. (2011). 10.1007/978-3-642-29420-4_3 Mário S. Alvim Miguel E. Andrés Konstantinos Chatzikokolakis Pierpaolo Degano and Catuscia Palamidessi. 2011b. Differential privacy: On the trade-off between utility and information leakage. http://arxiv.org/abs/1103.5188. (2011). 10.1007/978-3-642-29420-4_3
4. Mário S. Alvim Miguel E. Andrés Konstantinos Chatzikokolakis and Catuscia Palamidessi. 2011a. On the relation between differential privacy and quantitative information flow. In ICALP. Mário S. Alvim Miguel E. Andrés Konstantinos Chatzikokolakis and Catuscia Palamidessi. 2011a. On the relation between differential privacy and quantitative information flow. In ICALP.
5. Mario S. Alvim Konstantinos Chatzikokolakis Catuscia Palamidessi and Geoffrey Smith. 2012. Measuring information leakage using generalized gain functions. In CSF. 10.1109/CSF.2012.26 Mario S. Alvim Konstantinos Chatzikokolakis Catuscia Palamidessi and Geoffrey Smith. 2012. Measuring information leakage using generalized gain functions. In CSF. 10.1109/CSF.2012.26
Cited by
11 articles.
订阅此论文施引文献
订阅此论文施引文献,注册后可以免费订阅5篇论文的施引文献,订阅后可以查看论文全部施引文献