[论文解读] A Feasibility Study of Differentially Private Summary Statistics and Regression Analyses for Administrative Tax Data.
本文评估了使用差分隐私(DP)方法在敏感行政税收数据上构建验证服务器的可行性,提出了并测试了用于汇总统计和回归分析的DP技术。结果表明,DP汇总统计在可接受的精度下是可行的,但DP回归估计和置信区间仍过于不准确,难以可靠使用。
Federal administrative tax data are invaluable for research, but because of privacy concerns, access to these data is typically limited to select agencies and a few individuals. An alternative to sharing microlevel data are validation servers, which allow individuals to query statistics without accessing the confidential data. This paper studies the feasibility of using differentially private (DP) methods to implement such a server. We provide an extensive study on existing DP methods for releasing tabular statistics, means, quantiles, and regression estimates. We also include new methodological adaptations to existing DP regression algorithms for using new data types and returning standard error estimates. We evaluate the selected methods based on the accuracy of the output for statistical analyses, using real administrative tax data obtained from the Internal Revenue Service Statistics of Income (SOI) Division. Our findings show that a validation server would be feasible for simple statistics but would struggle to produce accurate regression estimates and confidence intervals. We outline challenges and offer recommendations for future work on validation servers. This is the first comprehensive statistical study of DP methodology on a real, complex dataset, that has significant implications for the direction of a growing research field.
研究动机与目标
- 评估差分隐私(DP)方法是否能够通过验证服务器实现对联邦行政税收数据的安全、隐私保护访问。
- 评估DP方法在真实IRS SOI数据上发布表格统计、均值、分位数和回归估计的准确性。
- 开发并改进现有DP回归算法,以适应新型数据类型,并返回标准误估计。
- 识别在DP约束下实现准确回归输出的挑战,并为未来工作提供改进建议。
提出的方法
- 将现有的差分隐私算法(用于表格统计、均值和分位数)改进以处理现实世界中的行政税收数据结构。
- 扩展DP回归算法以支持新型数据类型,并输出标准误估计,提升其在统计推断中的可用性。
- 实现一种验证服务器架构,使用户能够在不访问原始微观数据的情况下查询DP保护的统计结果。
- 使用真实的IRS收入统计(SOI)数据评估方法的准确性,测量汇总统计和回归输出的误差。
- 比较多种DP机制(如拉普拉斯、正态)及噪声校准策略,以在隐私保护与准确性之间取得平衡。
- 采用隐私预算(ε)分配策略,在确保差分隐私的同时最小化效用损失。
实验结果
研究问题
- RQ1差分隐私方法能否为敏感行政税收数据生成准确的汇总统计(如均值、分位数、计数)?
- RQ2当应用于真实IRS SOI数据时,DP回归算法在多大程度上能产生可靠的估计和标准误?
- RQ3隐私预算(ε)设置如何影响DP统计和回归输出的准确性?
- RQ4在复杂统计分析的税务数据上实现DP验证服务器面临哪些关键挑战?
- RQ5DP方法能否在不损害个人隐私的前提下,支持对行政数据进行有意义的统计推断?
主要发现
- 差分隐私汇总统计(包括均值和分位数)可实现可接受的精度,因此适用于验证服务器。
- DP回归估计表现出显著的精度损失,尤其在小效应量和高维模型中更为明显。
- DP回归算法返回的标准误估计通常不可靠,限制了置信区间的实用性。
- 随着隐私预算(ε)降低,DP输出的准确性显著下降,尤其在回归模型中更为明显。
- 尽管DP表格统计表现良好,但DP回归在方法论上的挑战使其当前形式不适合高精度推断。
- 本研究识别出DP方法论在回归分析中的关键缺口,未来需进一步研究以实现在受保护数据上的稳健统计分析。
更好的研究,从现在开始
从阅读论文到最终审阅,大幅缩短您的研究时间。
无需绑定信用卡
本解读由 AI 生成,并经人工编辑审核。