On the Relation between Differential Privacy and Quantitative Information Flow

被引:0
|
作者
Alvim, Mario S. [1 ]
Andres, Miguel E.
Chatzikokolakis, Konstantinos
Palamidessi, Catuscia
机构
[1] Ecole Polytech, INRIA, F-91128 Palaiseau, France
关键词
D O I
暂无
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
Differential privacy is a notion that has emerged in the community of statistical databases, as a response to the problem of protecting the privacy of the database's participants when performing statistical queries. The idea is that a randomized query satisfies differential privacy if the likelihood of obtaining a certain answer for a database x is not too different from the likelihood of obtaining the same answer on adjacent databases, i.e. databases which differ from x for only one individual. Information flow is an area of Security concerned with the problem of controlling the leakage of confidential information in programs and protocols. Nowadays, one of the most established approaches to quantify and to reason about leakage is based on the Renyi min entropy version of information theory. In this paper, we analyze critically the notion of differential privacy in light of the conceptual framework provided by the Renyi min information theory. We show that there is a close relation between differential privacy and leakage, due to the graph symmetries induced by the adjacency relation. Furthermore, we consider the utility of the randomized answer, which measures its expected degree of accuracy. We focus on certain kinds of utility functions called "binary", which have a close correspondence with the Renyi min mutual information. Again, it turns out that there can be a tight correspondence between differential privacy and utility, depending on the symmetries induced by the adjacency relation and by the query. Depending on these symmetries we can also build an optimal-utility randomization mechanism while preserving the required level of differential privacy. Our main contribution is a study of the kind of structures that can be induced by the adjacency relation and the query, and how to use them to derive bounds on the leakage and achieve the optimal utility.
引用
收藏
页码:60 / 76
页数:17
相关论文
共 50 条
  • [1] Quantitative information flow and applications to differential privacy
    Alvim M.S.
    Andrés M.E.
    Chatzikokolakis K.
    Palamidessi C.
    Lecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics), 2011, 6858 LNCS : 211 - 230
  • [2] On the Relation Between Identifiability, Differential Privacy, and Mutual-Information Privacy
    Wang, Weina
    Ying, Lei
    Zhang, Junshan
    2014 52ND ANNUAL ALLERTON CONFERENCE ON COMMUNICATION, CONTROL, AND COMPUTING (ALLERTON), 2014, : 1086 - 1092
  • [3] On the Relation Between Identifiability, Differential Privacy, and Mutual-Information Privacy
    Wang, Weina
    Ying, Lei
    Zhang, Junshan
    IEEE TRANSACTIONS ON INFORMATION THEORY, 2016, 62 (09) : 5018 - 5029
  • [4] Explaining ε in local differential privacy through the lens of quantitative information flow
    Fernandes, Natasha
    McIver, Annabelle
    Sadeghi, Parastoo
    2024 IEEE 37TH COMPUTER SECURITY FOUNDATIONS SYMPOSIUM, CSF 2024, 2024, : 419 - 432
  • [5] Relation between quantitative and qualitative measures of information use
    Booske, BC
    Sainfort, F
    INTERNATIONAL JOURNAL OF HUMAN-COMPUTER INTERACTION, 1998, 10 (01) : 1 - 21
  • [6] Differential Privacy for Information Retrieval
    Yang, Grace Hui
    Zhang, Sicong
    ICTIR'17: PROCEEDINGS OF THE 2017 ACM SIGIR INTERNATIONAL CONFERENCE THEORY OF INFORMATION RETRIEVAL, 2017, : 325 - 326
  • [7] Differential Privacy for Information Retrieval
    Yang, Grace Hui
    Zhang, Sicong
    WSDM'18: PROCEEDINGS OF THE ELEVENTH ACM INTERNATIONAL CONFERENCE ON WEB SEARCH AND DATA MINING, 2018, : 777 - 778
  • [8] Differential privacy: On the trade-off between utility and information leakage
    INRIA, LIX, Ecole Polytechnique, France
    不详
    Lect. Notes Comput. Sci., (39-54):
  • [9] On the Concept of Privacy: the Relation between Privacy and Intimacy
    Toscano, Manuel
    ISEGORIA, 2017, (57): : 533 - 552
  • [10] Estimating the quantitative relation between incongruent information and response time
    Kerzel, Dirk
    Weigelt, Matthias
    Bosbach, Simone
    ACTA PSYCHOLOGICA, 2006, 122 (03) : 267 - 279