What Are the Chances? Explaining the Epsilon Parameter in Differential Privacy

03/01/2023
by   Priyanka Nanayakkara, et al.
0

Differential privacy (DP) is a mathematical privacy notion increasingly deployed across government and industry. With DP, privacy protections are probabilistic: they are bounded by the privacy budget parameter, ϵ. Prior work in health and computational science finds that people struggle to reason about probabilistic risks. Yet, communicating the implications of ϵ to people contributing their data is vital to avoiding privacy theater – presenting meaningless privacy protection as meaningful – and empowering more informed data-sharing decisions. Drawing on best practices in risk communication and usability, we develop three methods to convey probabilistic DP guarantees to end users: two that communicate odds and one offering concrete examples of DP outputs. We quantitatively evaluate these explanation methods in a vignette survey study (n=963) via three metrics: objective risk comprehension, subjective privacy understanding of DP guarantees, and self-efficacy. We find that odds-based explanation methods are more effective than (1) output-based methods and (2) state-of-the-art approaches that gloss over information about ϵ. Further, when offered information about ϵ, respondents are more willing to share their data than when presented with a state-of-the-art DP explanation; this willingness to share is sensitive to ϵ values: as privacy protections weaken, respondents are less likely to share data.

READ FULL TEXT

page 1

page 2

page 3

page 4

research
03/31/2020

Towards Effective Differential Privacy Communication for Users' Data Sharing Decision and Comprehension

Differential privacy protects an individual's privacy by perturbing data...
research
08/04/2022

New Differential Privacy Communication Pipeline and Design Framework

Organizations started to adopt differential privacy (DP) techniques hopi...
research
08/23/2022

"Am I Private and If So, how Many?" - Communicating Privacy Guarantees of Differential Privacy with Risk Communication Formats

Decisions about sharing personal information are not trivial, since ther...
research
04/08/2022

"Am I Private and If So, how Many?" – Using Risk Communication Formats for Making Differential Privacy Understandable

Mobility data is essential for cities and communities to identify areas ...
research
09/02/2022

DPXPlain: Privately Explaining Aggregate Query Answers

Differential privacy (DP) is the state-of-the-art and rigorous notion of...
research
07/13/2023

To share or not to share: What risks would laypeople accept to give sensitive data to differentially-private NLP systems?

Although the NLP community has adopted central differential privacy as a...

Please sign up or login with your details

Forgot password? Click here to reset