Skip to main content
QUICK REVIEW

[論文レビュー] On the Tradeoff between Privacy and Distortion in Differential Privacy.

Weina Wang, Lei Ying|arXiv (Cornell University)|Feb 16, 2014
Privacy-Preserving Technologies in Data参考文献 5被引用数 5
ひとこと要約

本稿は、合成データベース生成における微分プライバシーの根本的トレードオフを特定するために、歪み制約下で達成可能な最小の微分プライバシー水準を定量化するプライバシー・歪み関数 ∗(D) を導入した。この関数により、一様事前分布下での最適性を達成する計算効率の良いメカニズム E が提案され、新たな「事後微分プライバシー」という概念を用いて、プライバシー・歪み理論と情報理論的レート・歪み理論との深い関連性が明らかにされた。

ABSTRACT

In this paper, we consider the setting in which the output of a differentially private mechanism is in the same universe as the input, and investigate the usefulness in terms of (the negative of) the distortion between the output and the input. This setting can be regarded as the synthetic database release problem. We define a privacy–distortion function ∗(D), which is the smallest (best) achievable differential privacy level given a distortion upper bound D, and quantify the fundamental privacy–distortion tradeoff by characterizing ∗. Specifically, we first obtain an upper bound on ∗ by designing a mechanism E. Then we derive a lower bound on ∗ that deviates from the upper bound only by a constant. It turns out that E is an optimal mechanism when the database is drawn uniformly from the universe, i.e., the upper bound and the lower bound meet. A significant advantage of mechanism E is that its distortion guarantee does not depend on the prior and its implementation is computationally efficient, although it may not be optimal always. From a learning perspective, we further introduce a new notion of differential privacy that is defined on the posterior probabilities, which we call a posteriori differential privacy. Under this notion, the exact form of the privacy–distortion function is obtained for a wide range of distortion values. We then establish a fundamental connection between the privacy–distortion tradeoff and the information-theoretic rate–distortion theory. An interesting finding is that there exists a consistency between the rate– distortion and the privacy–distortion under a posteriori differential privacy, which is shown by devising a mechanism that minimizes the mutual information and the privacy level simultaneously. 1

研究の動機と目的

  • 合成データベース公開における微分プライバシーと歪みの根本的トレードオフを特定すること。
  • 与えられた歪みバウンドに対して達成可能な最小のプライバシー水準を捉えるプライバシー・歪み関数 ∗(D) を定義・分析すること。
  • 計算コストが低く、事前分布に依存しない歪み保証を持つ近似的に最適なプライバシー・歪みトレードオフを達成するメカニズム E を設計すること。
  • プライバシー・歪み理論と情報理論的レート・歪み理論との理論的関連を確立すること。
  • 正確なプライバシー・歪み関数の特徴付けを可能にするために、新たな「事後微分プライバシー」という概念を導入・分析すること。

提案手法

  • プライバシー・歪み関数 ∗(D) は、歪み制約 D の下で達成可能な最小の微分プライバシー水準として定義される。
  • 歪みがデータの事前分布に依存しないように、上界を提供するメカニズム E が構築される。
  • ∗(D) の下界が導出され、上界と下界の差が定数にしかならないことが示される。
  • データベースが宇宙上を一様分布すると仮定した場合、メカニズム E が最適であることが証明される。
  • 事前分布ではなく事後確率に基づく新しいプライバシーの概念「事後微分プライバシー」が導入される。
  • プライバシー・歪みとレート・歪み理論の関連が明確化され、同時に相互情報量とプライバシー水準の両方を最小化するメカニズムが示される。

実験結果

リサーチクエスチョン

  • RQ1合成データベース生成における微分プライバシーと歪みの根本的トレードオフは何か?
  • RQ2データの事前分布に依存しない歪み保証を持つ微分プライバシー機構を設計できるか?
  • RQ3プライバシー・歪みトレードオフは、古典的レート・歪み理論とどのように関連するか?
  • RQ4提案されたメカニズム E が最適となる条件は何か?
  • RQ5新たなプライバシー概念「事後微分プライバシー」は、プライバシー・歪み関数の正確な特徴付けを可能にするか?

主な発見

  • メカニズム E は、∗(D) の上界と下界の差が定数要因にしかならない近似的に最適なプライバシー・歪みトレードオフを達成する。
  • データベースが宇宙上を一様分布する場合、メカニズム E は最適であることが確認され、この設定における理論的最適性が裏付けられる。
  • E の歪み保証はデータの事前分布に依存しないため、さまざまなデータ分布にわたるロバスト性を提供する。
  • 新たな事後微分プライバシーフレームワークの下で、レート・歪み理論とプライバシー・歪み理論の整合性が確立された。
  • 相互情報量と微分プライバシー水準の両方を同時に最小化するメカニズムが構築され、情報理論的測度とプライバシー測度との緊密な関連性が示された。
  • 事後微分プライバシーの下で、広範な歪み値の範囲においてプライバシー・歪み関数 ∗(D) が正確に特徴付けられた。

より良い研究を、今すぐ始めましょう

論文の読解から最終レビューまで、研究時間を劇的に削減しましょう。

クレジットカード登録不要

このレビューはAIが作成し、人間の編集者が確認しました。