[Paper Review] Restricted Local Differential Privacy for Distribution Estimation with High Data Utility.
This paper introduces Utility-optimized Local Differential Privacy (ULDP), a novel framework that reduces noise for non-sensitive data while preserving strong privacy for sensitive data, achieving significantly higher data utility than standard LDP mechanisms—especially when most data are non-sensitive, approaching non-private utility in low-privacy regimes.
LDP (Local Differential Privacy) has been widely studied to estimate statistics of personal data (e.g., distribution underlying the data) while protecting users' privacy. Although LDP does not require a trusted third party, it regards all personal data equally sensitive, which causes excessive obfuscation hence the loss of utility. In this paper, we introduce the notion of ULDP (Utility-optimized LDP), which provides a privacy guarantee equivalent to LDP only for sensitive data. We first consider the setting where all users use the same obfuscation mechanism, and propose two mechanisms providing ULDP: utility-optimized randomized response and utility-optimized RAPPOR. We then consider the setting where the distinction between sensitive and non-sensitive data can be different from user to user. For this setting, we propose a personalized ULDP mechanism with semantic tags to estimate the distribution of personal data with high utility while keeping secret what is sensitive for each user. We show theoretically and experimentally that our mechanisms provide much higher utility than the existing LDP mechanisms when there are a lot of non-sensitive data. We also show that when most of the data are non-sensitive, our mechanisms even provide almost the same utility as non-private mechanisms in the low privacy regime.
Motivation & Objective
- To address the inefficiency of standard Local Differential Privacy (LDP), which applies uniform noise to all data regardless of sensitivity, leading to excessive utility loss.
- To design a mechanism that preserves strong privacy guarantees only for sensitive data, while minimizing obfuscation for non-sensitive data.
- To enable personalized privacy protection where users can define their own sensitive data, improving utility without compromising privacy.
- To theoretically and empirically demonstrate that ULDP achieves higher utility than existing LDP mechanisms, especially when most data are non-sensitive.
Proposed method
- Proposes utility-optimized randomized response, a mechanism that adjusts noise injection based on data sensitivity, improving utility for non-sensitive data.
- Introduces utility-optimized RAPPOR, a variant of RAPPOR that optimizes the obfuscation process to preserve utility while maintaining privacy for sensitive data.
- Designs a personalized ULDP mechanism using semantic tags to allow users to label sensitive data individually, enabling user-specific noise allocation.
- Applies a privacy budget allocation strategy that assigns higher privacy protection only to sensitive data, reducing overall noise.
- Uses a distribution estimation framework that leverages the structure of non-sensitive data to improve estimation accuracy.
- Employs theoretical analysis and empirical evaluation to compare utility against standard LDP mechanisms under varying data sensitivity ratios.
Experimental results
Research questions
- RQ1Can we design a local differential privacy mechanism that reduces noise for non-sensitive data while preserving strong privacy for sensitive data?
- RQ2How does the utility of ULDP compare to standard LDP mechanisms when the proportion of non-sensitive data is high?
- RQ3Can personalized sensitivity labeling improve data utility without degrading privacy guarantees?
- RQ4To what extent can ULDP approach the utility of non-private mechanisms in low-privacy regimes?
Key findings
- ULDP mechanisms achieve significantly higher utility than standard LDP mechanisms when a large portion of the data are non-sensitive.
- In the low-privacy regime, ULDP approaches the utility of non-private mechanisms when most data are non-sensitive.
- The personalized ULDP mechanism with semantic tags enables fine-grained privacy control while maintaining high estimation accuracy.
- Utility-optimized randomized response and RAPPOR reduce noise for non-sensitive data, leading to improved distribution estimation performance.
- Theoretical and experimental results confirm that ULDP provides equivalent privacy to LDP only for sensitive data, without compromising the overall privacy guarantee.
Better researchstarts right now
From reading papers to final review, dramatically reduce your research time.
No credit card · Free plan available
This review was created by AI and reviewed by human editors.