Differential Privacy: �Meanings and Caveats
Ninghui Li
Department of Computer Science Purdue University
Defining Privacy is Hard
2
10/7/2021
What is Privacy?
It is complicated!
Some concepts from the book “Understanding Privacy” by Daniel J. Solove:
3
10/7/2021
Impossibility of “Privacy as Secrecy”
4
10/7/2021
Another Example
5
10/7/2021
Different Manifestation of the Impossibility Result
6
10/7/2021
Analogies with Crypto
7
10/7/2021
Differential Privacy [Dwork et al. 2006]
8
10/7/2021
Bounded and Unbounded DP
9
10/7/2021
Properties of DP
10
10/7/2021
Need to be careful with conditions for neighboring!
Kasivisiwanathan-Smith’s Formulation of DP’s Real-Ideal World Guarantee
11
10/7/2021
Kasiviswanathan-Smith’s Bayesian Formulation (continued)
12
10/7/2021
Ganta, Kasivisiwanathan and Smith: Composition Attacks and Auxiliary Information in Data Privacy, KDD’08.
Kasivisiwanathan and Smith: On the `Semantics' of Differential Privacy: A Bayesian Formulation. arXic 2013, Journal of Privacy and Confidentiality 2014.
Our Formulation of DP’s Real-World Ideal-World Privacy Guarantee
13
10/7/2021
Genius of Idea Behind DP
14
10/7/2021
DP’s Similar-Decision-Regardless-of-Prior Guarantee
15
10/7/2021
The Personal Data Principle
16
10/7/2021
OECD�Privacy Principles
17
10/7/2021
OECD�Privacy Principles
18
10/7/2021
OECD�Privacy Principles
19
10/7/2021
OECD�Privacy Principles
20
10/7/2021
Critique of DP
21
10/7/2021
Kifer and Machanavajjhala: No Free Lunch in Data Privacy, SIGMOD 2011.
An Attempt at Providing Prior-to-Posterior Bound in [Dwork et al. 2006]
22
10/7/2021
Dwork et al.: Calibrating Noise to Sensitivity in Private Data Analysis. TCC 2006.
An Example Adapted from [Kifer and Machanavajjhala, 2011]
23
10/7/2021
In A Sense, No
24
10/7/2021
Caveats of Applying DP
25
10/7/2021
Defining Neighbors Incorrectly
26
10/7/2021
Local Setting
27
10/7/2021
What Constitutes An Individual’s Personal Data?
28
10/7/2021
Such legal and ethical questions still need to be resolved
29
10/7/2021
https://epic.org/privacy/genetic/iceland_decision.pdf
Lesson
30
10/7/2021
My Personal Data or Personal Data Under My Control?
31
10/7/2021
Our Tentative Answer
32
10/7/2021
Group Privacy as a Potential Challenge to Personal Data Principle
33
10/7/2021
A Moral Challenge to DP
34
10/7/2021
How to Choose ε
35
10/7/2021
Consult This Table of Change in Belief: p is prior; numbers in table are posterior
36
10/7/2021
Apply a Model Learned with DP Arbitrarily.
37
10/7/2021
The Target Pregnancy Prediction Example
38
10/8/2021
https://www.nytimes.com/2012/02/19/magazine/shopping-habits.html
Privacy and Discrimination
39
10/7/2021
Caveats of Applying DP
40
10/7/2021
When is ϵ-DP Good Enough?
41
10/7/2021