α-Information-theoretic Privacy Watchdog and Optimal Privatization Scheme

01/26/2021
by   Ni Ding, et al.
0

This paper proposes an α-lift measure for data privacy and determines the optimal privatization scheme that minimizes the α-lift in the watchdog method. To release data X that is correlated with sensitive information S, the ratio l(s,x) = p(s|x)/p(s) denotes the `lift' of the posterior belief on S and quantifies data privacy. The α-lift is proposed as the L_α-norm of the lift: ℓ_α(x) = (·,x) _α = (E[l(S,x)^α])^1/α. This is a tunable measure: When α < ∞, each lift is weighted by its likelihood of appearing in the dataset (w.r.t. the marginal probability p(s)); For α = ∞, α-lift reduces to the existing maximum lift. To generate the sanitized data Y, we adopt the privacy watchdog method using α-lift: Obtain 𝒳_ϵ containing all x's such that ℓ_α(x) > e^ϵ; Apply the randomization r(y|x) to all x ∈𝒳_ϵ, while all other x ∈𝒳∖𝒳_ϵ are published directly. For the resulting α-lift ℓ_α(y), it is shown that the Sibson mutual information I_α^S(S;Y) is proportional to E[ ℓ_α(y)]. We further define a stronger measure I̅_α^S(S;Y) using the worst-case α-lift: max_yℓ_α(y). We prove that the optimal randomization r^*(y|x) that minimizes both I_α^S(S;Y) and I̅_α^S(S;Y) is X-invariant, i.e., r^*(y|x) = R(y), ∀ x∈𝒳_ϵ for any probability distribution R over y ∈𝒳_ϵ. Numerical experiments show that α-lift can provide flexibility in the privacy-utility tradeoff.

READ FULL TEXT

page 1

page 2

page 3

page 4

research
10/19/2020

On Properties and Optimization of Information-theoretic Privacy Watchdog

We study the problem of privacy preservation in data sharing, where S is...
research
01/24/2021

A Linear Reduction Method for Local Differential Privacy and Log-lift

This paper considers the problem of publishing data X while protecting c...
research
02/04/2020

The Privacy Funnel from the viewpoint of Local Differential Privacy

We consider a database X⃗ = (X_1,...,X_n) containing the data of n users...
research
01/05/2018

Optimal Utility-Privacy Trade-off with the Total Variation Distance as the Privacy Measure

Three reasons are provided in favour of L^1-norm as a measure of privacy...
research
03/14/2023

Inferential Privacy: From Impossibility to Database Privacy

We investigate the possibility of guaranteeing inferential privacy for m...
research
05/03/2021

Optimal Maximal Leakage-Distortion Tradeoff

Most methods for publishing data with privacy guarantees introduce rando...
research
09/23/2020

An Information Theoretic approach to Post Randomization Methods under Differential Privacy

Post Randomization Methods (PRAM) are among the most popular disclosure ...

Please sign up or login with your details

Forgot password? Click here to reset