[Paper Review] Redrawing the Boundaries on Purchasing Data from Privacy-Sensitive Individuals
This paper strengthens impossibility results for truthful and individually rational mechanisms in private data purchasing, showing that even with per-database privacy valuations or non-zero δ in differential privacy, truthful mechanisms cannot exist under general conditions. To bypass this, the authors propose a novel mechanism for monotonic privacy valuations—where higher data sensitivity increases privacy valuation—achieving truthfulness for bounded valuations, individual rationality, and accuracy, with matching lower bounds proving optimality in key aspects.
We prove new positive and negative results concerning the existence of truthful and individually rational mechanisms for purchasing private data from individuals with unbounded and sensitive privacy preferences. We strengthen the impossibility results of Ghosh and Roth (EC 2011) by extending it to a much wider class of privacy valuations. In particular, these include privacy valuations that are based on (ε, δ)-differentially private mechanisms for non-zero δ, ones where the privacy costs are measured in a per-database manner (rather than taking the worst case), and ones that do not depend on the payments made to players (which might not be observable to an adversary). To bypass this impossibility result, we study a natural special setting where individuals have mono- tonic privacy valuations, which captures common contexts where certain values for private data are expected to lead to higher valuations for privacy (e.g. having a particular disease). We give new mech- anisms that are individually rational for all players with monotonic privacy valuations, truthful for all players whose privacy valuations are not too large, and accurate if there are not too many players with too-large privacy valuations. We also prove matching lower bounds showing that in some respects our mechanism cannot be improved significantly.
Motivation & Objective
- To address the challenge of incentivizing privacy-sensitive individuals to share private data in a way that is both truthful and individually rational.
- To extend prior impossibility results by Ghosh and Roth to broader classes of privacy valuations, including (ε,δ)-differential privacy with δ > 0 and per-database valuation functions.
- To design a mechanism that remains truthful and individually rational under monotonic privacy valuations, where privacy costs increase with data sensitivity.
- To establish matching lower bounds demonstrating that the proposed mechanism cannot be significantly improved in terms of accuracy or truthfulness.
- To provide a framework for data purchasing that respects privacy preferences while ensuring accurate aggregation of private data.
Proposed method
- Introduces a hybrid input sequence to analyze privacy loss and distinguishability across mechanism outputs, using statistical distance to bound privacy leakage.
- Employs a sequence of hybrid inputs $x^{(i,0)}$ and $x^{(i,1)}$ to model incremental changes in data bits and valuations, enabling analysis of truthfulness and privacy guarantees.
- Applies triangle inequality to bound the statistical distance between the output distributions of consecutive hybrids, leading to a contradiction if accuracy is too high.
- Uses the concept of monotonic neighbors and privacy loss functions that grow with statistical distance to derive distinguishability bounds.
- Establishes that if a mechanism is $([ u, au], eta)$-accurate, then the output distributions of extreme hybrids must be close, leading to a contradiction when intervals $A(1)$ and $A(h+2 au n+1)$ are disjoint.
- Proves that no mechanism can be both $([ u+ au, au], eta)$-accurate and satisfy the privacy and truthfulness constraints under the given valuation model.
Experimental results
Research questions
- RQ1Can truthful and individually rational mechanisms for purchasing private data exist when privacy valuations are unbounded and sensitive?
- RQ2To what extent do existing impossibility results for data purchasing mechanisms extend to (ε,δ)-differentially private valuations with δ > 0?
- RQ3Can mechanisms be designed that are truthful and individually rational under monotonic privacy valuations, where privacy cost increases with data sensitivity?
- RQ4What are the fundamental limits on accuracy for mechanisms that are truthful for players with bounded privacy valuations?
- RQ5Is the proposed mechanism optimal in terms of accuracy and truthfulness, or can it be significantly improved?
Key findings
- The paper proves that no mechanism can be both truthful and $([ u+ au, au], eta)$-accurate when privacy valuations are monotonic and unbounded, under the given assumptions.
- A contradiction is derived by showing that the statistical distance between the output distributions of the first and last hybrid inputs exceeds the required accuracy threshold, violating the accuracy condition.
- The mechanism achieves truthfulness for players with bounded privacy valuations and individual rationality for all players with monotonic valuations.
- The mechanism is accurate when the number of players with high privacy valuations is limited, ensuring that the output remains close to the true sum of data bits.
- Matching lower bounds are proven, showing that the mechanism’s accuracy and truthfulness guarantees cannot be significantly improved without violating core constraints.
- The impossibility result extends to settings where privacy valuations are not dependent on payments, and where valuations are measured per-database rather than in worst-case scenarios.
Better researchstarts right now
From reading papers to final review, dramatically reduce your research time.
No credit card · Free plan available
This review was created by AI and reviewed by human editors.