Skip to main content
QUICK REVIEW

[论文解读] The Value of Privacy: Strategic Data Subjects, Incentive Mechanisms and Fundamental Limits

Weina Wang, Lei Ying|arXiv (Cornell University)|Mar 22, 2016
Privacy-Preserving Technologies in Data参考文献 5被引用 5
一句话总结

本文研究了在博弈论模型中隐私的战略价值,其中数据收集者通过激励个体报告带有噪声的、保护隐私的数据。研究推导出为获取 $\varepsilon$ 单位隐私所需支付的渐近紧致边界,表明所设计的激励机制在给定学习准确度目标下可实现接近最优的成本。

ABSTRACT

We study the value of data privacy in a game-theoretic model of trading private data, where a data collector purchases private data from strategic data subjects (individuals) through an incentive mechanism. The private data of each individual represents her knowledge about an underlying state, which is the information that the data collector desires to learn. Different from most of the existing work on privacy-aware surveys, our model does not assume the data collector to be trustworthy. Then, an individual takes full control of its own data privacy and reports only a privacy-preserving version of her data. In this paper, the value of $ε$ units of privacy is measured by the minimum payment of all nonnegative payment mechanisms, under which an individual's best response at a Nash equilibrium is to report the data with a privacy level of $ε$. The higher $ε$ is, the less private the reported data is. We derive lower and upper bounds on the value of privacy which are asymptotically tight as the number of data subjects becomes large. Specifically, the lower bound assures that it is impossible to use less amount of payment to buy $ε$ units of privacy, and the upper bound is given by an achievable payment mechanism that we designed. Based on these fundamental limits, we further derive lower and upper bounds on the minimum total payment for the data collector to achieve a given learning accuracy target, and show that the total payment of the designed mechanism is at most one individual's payment away from the minimum.

研究动机与目标

  • 将数据隐私建模为个体控制自身数据隐私并报告噪声数据的市场中的战略权衡。
  • 衡量 $\varepsilon$ 单位隐私的价值,即在纳什均衡下诱导个体以该隐私水平进行真实报告所需的最低支付。
  • 设计一种激励机制,以最小化总支付同时实现目标学习准确度。
  • 推导大规模战略数据主体中成本-准确度权衡的根本极限。
  • 证明所提机制的总支付与理论最小值仅相差一个个体的支付,因而接近最优。

提出的方法

  • 将数据收集建模为数据收集者与 $N$ 个战略个体之间的博弈,每个个体报告其私有信号的隐私保护版本。
  • 采用二元假设检验框架:状态 $W$ 是一个二元随机变量,每个个体的信号 $S_i$ 以概率 $\theta > 0.5$ 匹配 $W$。
  • 将隐私水平 $\varepsilon$ 定义为报告数据 $X_i$ 中噪声的度量,$\varepsilon$ 越高表示隐私保护越弱。
  • 引入一个非负支付机制 $\bm{R}^{(N,\varepsilon)}$,使其在纳什均衡下激励个体选择特定的隐私水平 $\varepsilon$。
  • 应用切尔诺夫信息作为准确度度量,通过巴塔查里亚界将其与错误概率关联。
  • 通过大 $N$ 渐近分析,推导出隐私价值的渐近紧致下界 $V_{\mathrm{LB}}(\varepsilon)$ 和上界 $V_{\mathrm{UB}}(\varepsilon)$。

实验结果

研究问题

  • RQ1在纳什均衡下,为诱导个体报告特定隐私水平 $\varepsilon$ 的数据,所需最低支付是多少?
  • RQ2数据收集者如何设计激励机制,以最小化总支付同时实现期望学习准确度?
  • RQ3当个体对隐私采取战略行为时,成本-准确度权衡的根本极限是什么?
  • RQ4实际支付机制在给定准确度目标下,能多接近理论最小总支付?
  • RQ5如何在参与人数与隐私水平之间取得最优平衡以最小化成本?

主要发现

  • $\varepsilon$ 单位隐私的价值下界为 $V_{\mathrm{LB}}(\varepsilon)$,代表为从个体处获取该隐私水平所需支付的最低金额。
  • 所设计支付机制 $\bm{R}^{(N,\varepsilon)}$ 实现了隐私价值的上界,且当 $N \to \infty$ 时为渐近紧致。
  • 在 $\widetilde{N}$ 名个体和隐私水平 $\widetilde{\varepsilon}$ 下,所设计机制的总期望支付最多为 $\widetilde{N}V_{\mathrm{LB}}(\widetilde{\varepsilon}) + O(\tau \ln(1/\tau))$,其中 $\tau$ 为准确度目标。
  • 该机制的总支付与理论最小值仅相差一个个体的支付,因此接近最优。
  • 最优选择 $\widetilde{N}$ 和 $\widetilde{\varepsilon}$ 最大化隐私的质量-价格比,实现成本与准确度的平衡。
  • 切尔诺夫信息度量为错误概率提供了可处理且准确的代理指标,并具有紧致的指数上界。

更好的研究,从现在开始

从阅读论文到最终审阅,大幅缩短您的研究时间。

无需绑定信用卡

本解读由 AI 生成,并经人工编辑审核。