Skip to main content
QUICK REVIEW

[논문 리뷰] Robust Privatization with Multiple Tasks and the Optimal Privacy-Utility Tradeoff

Ta-Yuan Liu, I-Hsiang Wang|arXiv (Cornell University)|2020. 10. 20.
Privacy-Preserving Technologies in Data참고 문헌 30인용 수 5
한 줄 요약

이 논문은 특정 작업이 알려지지 않은 상황에서 데이터 공개를 위한 강건한 프라이버시 보호 프레임워크를 제안하며, 다양한 가능한 작업에 대해 유틸리티 제약 조건을 만족하면서도 프라이버시 泄露를 최소화한다. 문제를 가중치가 부여된 병렬 프라이버시 퓨널 문제로 분해함으로써, 결정론적 프라이빗 특징에 대한 닫힌 형태의 해를 도출하고, 선형 프로그래밍을 통해 최적의 가중치를 찾을 수 있음을 보여주며, 충분한 공개 비율을 확보함으로써 최소 프라이버시 泄露를 달성한다.

ABSTRACT

In this work, fundamental limits and optimal mechanisms of privacy-preserving data release that aims to minimize the privacy leakage under utility constraints of a set of multiple tasks are investigated. While the private feature to be protected is typically determined and known by the sanitizer, the target task is usually unknown. To address the lack of information on the specific task, utility constraints laid on a set of multiple possible tasks are considered. The mechanism protects the specific privacy feature of the to-be-released data while satisfying utility constraints of all possible tasks in the set. First, the single-letter characterization of the rate-leakage-distortion region is derived, where the utility of each task is measured by a distortion function. It turns out that the minimum privacy leakage problem with log-loss distortion constraints and the unconstrained released rate is a non-convex optimization problem. Second, focusing on the case where the raw data consists of multiple independent components, we show that the above non-convex optimization problem can be decomposed into multiple parallel privacy funnel (PF) problems with different weightings. We explicitly derive the optimal solution to each PF problem when the private feature is a component-wise deterministic function of a data vector. The solution is characterized by a leakage-free threshold: when the utility constraint is below the threshold, the minimum leakage is zero; once the required utility level is above the threshold, the privacy leakage increases linearly. Finally, we show that the optimal weighting of each privacy funnel problem can be found by solving a linear program (LP). A sufficient released rate to achieve the minimum leakage is also derived. Numerical results are shown to illustrate the robustness of our approach against the task non-specificity.

연구 동기 및 목표

  • 공개된 데이터를 사용하는 후속 작업이 알려지지 않은 상황에서 프라이버시를 보호하는 데 도전하는 것.
  • 다양한 가능한 작업에 대해 유틸리티 제약 조건 하에서 프라이버시 泄露를 최소화하고, 작업 비특이성에 대해 강건성을 확보하는 것.
  • 로그 손실 왜곡을 사용한 정보이론적 프레임워크에서 프라이버시-유틸리티 트레이드오프의 기본 한계를 도출하는 것.
  • 최적의 해가 가중치가 부여된 병렬 프라이버시 퓨널 문제로 분해함으로써 도출될 수 있음을 보여주는 것.
  • 최소 프라이버시 泄露를 달성하기 위한 충분한 공개 비율을 제공하고, 최적의 가중치를 위한 선형 프로그래밍 설정을 수립하는 것.

제안 방법

  • 논문은 유틸리티 지표로 로그 손실 왜곡을, 프라이버시 지표로 상호정보량을 사용하여 프라이버시-유틸리티 트레이드오프를 수립한다.
  • 다중 유틸리티 제약 조건에 대해 레이트-레이크리지-왜곡 영역의 단일 기호 특성화를 도출한다.
  • 독립적인 데이터 구성요소와 결정론적 프라이빗 특징을 가정할 때, 문제는 서로 다른 가중치가 부여된 병렬 프라이버시 퓨널 문제로 분해된다.
  • 각 프라이버시 퓨널 문제는 닫힌 형태로 해결되며, 프라이버시 泄露가 선형적으로 증가하는 레이크리지-프리 임계값 이상에서 프라이버시 泄露가 증가함을 드러낸다.
  • 각 구성요소에 대한 최적의 가중치는 선형 프로그래밍(LP)을 풀어 결정되며, 이는 최소 泄露를 효율적으로 계산할 수 있도록 한다.
  • 최소 泄露를 달성하기 위한 충분한 공개 비율을 유도하고, 최적의 해가 타당함을 보장한다.
Figure 1: The privacy preserving data release model with $K$ possible tasks $\{C_{1},...,C_{K}\}$ .
Figure 1: The privacy preserving data release model with $K$ possible tasks $\{C_{1},...,C_{K}\}$ .

실험 결과

연구 질문

  • RQ1후속 작업이 알려지지 않은 상황에서 프라이버시-유틸리티 트레이드오프의 기본 한계는 무엇인가?
  • RQ2다양한 가능한 작업에 대해 유틸리티 제약 조건 하에서 프라이버시 泄露를 어떻게 최소화할 수 있는가?
  • RQ3최소 프라이버시 泄뢰를 위한 비볼록 최적화 문제는 간단한 하位 문제로 분해될 수 있는가?
  • RQ4다중 유틸리티 제약 조건 하에서 프라이버시 보호 메커니즘의 데이터 구성요소에 대한 최적의 가중치는 무엇인가?
  • RQ5강건한 설정에서 최적의 프라이버시-유틸리티 트레이드오프를 달성하기 위해 필요한 충분한 공개 비율은 무엇인가?

주요 결과

  • 다중 유틸리티 제약 조건이 있는 최소 프라이버시 泄뢰 문제는 비볼록이지만, 독립성과 결정론적 프라이빗 특징을 가정할 경우 병렬 프라이버시 퓨널 문제로 분해된다.
  • 각 구성요소에 대해, 레이크리지-프리 임계값 이하에서는 프라이버시 泄露가 0이며, 이 이상에서는 요구되는 유틸리티 수준에 따라 선형적으로 증가한다.
  • 각 프라이버시 퓨널 구성요소에 대한 최적의 가중치는 선형 프로그래밍을 통해 계산될 수 있으며, 이는 효율적인 최적화를 가능하게 한다.
  • 최소 泄뢰를 달성하기 위한 충분한 공개 비율은 도출되었으며, 병렬화된 프라이버시 보호를 사용할 경우 타당함이 입증된다.
  • 수치적 결과는 작업 비특이성에 대한 이 접근법의 강건성을 확인하고, 작업 집합 선택이 프라이버시-유틸리티 트레이드오프에 미치는 영향을 보여준다.
  • 이 프레임워크는 차별적 프라이버시로도 확장 가능하며, 이 경우 최소 泄뢰 문제 역시 병렬 단일 제약 문제로 분해되지만, 닫힌 형태의 해는 여전히 열려 있다.
Figure 2: The privacy and utility tradeoff for the non-specific task $C_{1}$ under the privatization based on different possible sets.
Figure 2: The privacy and utility tradeoff for the non-specific task $C_{1}$ under the privatization based on different possible sets.

더 나은 연구,지금 바로 시작하세요

논문 읽기부터 검토까지, 연구 시간을 획기적으로 줄여보세요.

카드 등록 없음 · 무료 플랜 제공

이 리뷰는 AI가 만들고, 인간 에디터가 검토했습니다.