发表机构
Aalborg University; Aalborg University Hospital(奥尔堡大学; 奥尔堡大学医院)
机构由 AI 辅助整理,请以论文原文为准。AI 中文总结
该研究针对差分隐私无法直观反映披露风险的问题,推导了有界概率和近似差分隐私下包含信念的后验-先验比率的界,发现高斯机制失效速率远低于理论上限,推论隐私保证强于理论暗示。
AI 中文摘要
差分隐私已成为生成隐私保护数据发布的标准,但它无法直观转化为披露风险,尤其是尚不清楚攻击者在观察到保护后的发布内容后,对个体是否包含在数据集中的信念会发生多大变化。为解决该问题,我们推导了有界概率差分隐私和近似差分隐私下包含信念的后验-先验比率的上下界。通过假设攻击者拥有除一名参与者外的所有辅助信息(即知道数据集中除一名参与者外的所有成员)这一最坏情况,我们得到了适用于任何攻击者的界。由于这些界可能以非零概率失效,我们研究了高斯机制对应的失效概率,推导了该概率的理论上限,并在广泛的参数设置下将其与蒙特卡洛估计值进行比较。观察到的失效速率比其理论上限小几个数量级,表明理论上限具有高度保守性。这些发现表明,差分隐私机制提供的推论隐私保证在实践中可能比理论上限所暗示的要强得多。
英文摘要
Differential privacy has become the standard for generating privacy-protected data releases. However, differential privacy does not translate intuitively to disclosure risk. In particular, it remains unclear how much an adversary's belief about an individual's inclusion in a dataset can change after observing a protected release. To address this question, we derive upper and lower bounds on the posterior-to-prior ratios of inclusion beliefs under bounded probabilistic and approximate differential privacy. By assuming a worst-case adversary with all-but-one auxiliary information, i.e., knowledge of all except for one of the participants in a dataset, we obtain bounds that apply to any adversary. Because these bounds may fail with non-zero probability, we study the corresponding failure probability for the Gaussian mechanism. We derive a theoretical upper limit on this probability and compare it with Monte Carlo estimates across a wide range of parameter settings. The observed failure rate is several orders of magnitude smaller than its theoretical upper limit, indicating that the latter is highly conservative. These findings suggest that the inferential privacy guarantees provided by differentially private mechanisms may be substantially stronger in practice than what is implied by the theoretical upper limit.
Comments24 pages, 3 figures