1 of 51

A Gentle Introduction to �Privacy-Enhancing Technologies for the Working Data Scientist

Nitin Kohli

UC Berkeley Center for Effective Global Action

Econ 148: Data Science for Economists

April 10, 2025

1

2 of 51

Motivating Example

2

3 of 51

3

Novissi in Togo

TOGO

  • Digital Emergency Cash Transfer Program
    • “Poorest individuals in the poorest regions”
    • $13-15 per month for 5 months
    • Launched: April 2020
    • Reach: 800K individuals

  • Challenge: Targeting transfers without administrative data

4 of 51

Two Stages of Novissi

Goal: Reach “poorest individuals in the poorest regions”

Challenge: Targeting transfers without administrative data

  • Stage 1: Identify poorest regions
  • Stage 2: Identify poorest individuals in these regions

4

5 of 51

Stage 1: Identify Poorest Regions

5

Extended Data Figure 1A: Aiken et al. (2022) Nature.

6 of 51

Key Insight: Individual phone usage (via metadata) is predictive of poverty

6

Stage 2: Identify Poorest Individuals

Source: Aiken et al. (2022) Journal of Development Economics; Figure 4 Supplemental Information

Poor

Non-poor

7 of 51

7

Predicting poverty from phone metadata and ML

Sources: Blumenstock et al. (2015), Science; Aiken et al. (2022), Journal of Development Economics; Aiken et al. (2022) Nature; Courtesy of Emily Aiken

 

 

Afghanistan 2015 (N=1,234)

Rwanda 2010 (N=856)

Togo 2020 (N=15,044)

 

8 of 51

Stage 2: Identify Poorest Individuals (Strategy)

  • Conduct a nationally representative phone survey of individuals in Togo from 2020
  • Construct an estimate of household consumption from the survey
  • Derive mobile phone usage features for these individuals
  • Build a ML model to predict household consumption from the mobile phone data
  • Apply the ML model on the entire population of the poorest regions
  • Provide emergency cash transfer to the poorest 29% (budget constraint)

8

9 of 51

Validation of Step 2 on Old (2018) Data

9

Figure 1B: Aiken et al. (2022)

10 of 51

Mobile phone metadata and privacy concerns?

10

11 of 51

11

Issue: Data can reveal sensitive information

Fig. 2 in de Montjoye et al. (2013); Scientific Reports

12 of 51

Brief Philosophical Interlude��If I asked you�what is privacy, �what would you say?

12

13 of 51

Some Common Answers

Common One-Line Responses

  • “Right to Be Let Alone”
  • “Control Over Information”
  • Secrecy
  • Consent
  • Limited intrusion upon one’s body, thought, or actions

13

Appeals to Literary or Cinematic Fiction

14 of 51

These are particular conceptions of privacy that were meant to address a particular social ill of the time

14

15 of 51

Example: Within the US

15

1890’s

1960’s & 1970’s

16 of 51

These concerns may not be the main privacy concerns in other parts of the world

16

17 of 51

Actions that “violate privacy” are context specific

  • Surveillance is not automatically problematic in all cases
    • US search and seizure law
      • Police investigations with vs. without a warrant (4th Amendment of US Constitution)

    • International Human Rights Law
      • Privacy is a derogable human right (Article 4 of ICCPR)
      • Necessary and Proportionate

  • Privacy is more than a “right to be let alone” or secrecy
    • Otherwise, data would not be allowed to “flow”

  • Privacy is more than “control over information” and consent
    • Privacy harms can still arise when consent has been given
    • Some situations (e.g., public health) may forgo consent in certain settings*

17

18 of 51

Defining privacy in the abstract or as one singular thing is “hard”

  • Pluralistic
  • Social
  • Contextual
  • Essentially contested

18

Finding an “appropriate” notion of privacy is a critical component for a particular setting

19 of 51

Be less abstract: �Tailor privacy solutions to the problem at hand

For example:

  • Who infringes upon privacy?
  • What does this infringement look like?
  • When did it occur?
  • Where did the vulnerability come from?
  • Why and how did it occur?

19

Different privacy problems may need different privacy solutions

20 of 51

For Remainder of Talk: �Data Privacy for Computational Tasks

20

Person 1

Data 1

Data N

Data 2

DATASET

Data 1

Data 2

Data N

Data Analyst

An “Observer”

The “Institution”

Person 2

Person N

Output

21 of 51

Developing Intuition

21

[2] Computational Data

Privacy Defenses

[1] Computational Data

Privacy Attacks

  • For this talk, I will refer to computational data privacy (loosely) as data privacy concerns that arise from computational processes
  • I do so to delineate it from other data privacy concerns, such as the unauthorized sharing of data to third parties, that are important yet distinct from computational concerns

22 of 51

22

[1] Computational Data

Privacy Attacks

[2] Computational Data

Privacy Defenses

23 of 51

*Offenders of Privacy: Adversaries

23

Hacker

Data Scientist

While hackers steal information, data scientists can learn it

*Mulligan, Koopman, Doty (2016) "Privacy is an essentially contested concept"

24 of 51

Thinking Adversarially:�Learning Information About Individuals

24

25 of 51

Example 1: Basic Math Breaks Poorly Protected Query Systems

25

Super Secret Health Database on Tuberculosis

Question

Answer

“Tuberculosis, the number one infectious killer, affects mostly people on low incomes. All 30 countries with a high burden of tuberculosis, which comprise 87% of all new tuberculosis cases, are low-income and middle-income countries (LMICs).” [Trajman 2023, The social drivers of tuberculosis, reconfirmed]

26 of 51

“Protection” #1: Suppress answers computed on “not enough” individuals

  •  

26

27 of 51

“Protection” #2: Add noise to every answer, forever

  •  

27

*Question: How can you to patch this to prevent LLN from doing its magic?

28 of 51

Example 2: Auxiliary Information Breaks of Poorly “Anonymized” Data�

28

Figure 1 in Sweeney (2002),

k-anonymity: A model for protecting privacy

Linkage Attack

29 of 51

Example 3: Basic Math Breaks Some* Statistical Releases

29

Statistics Released

Number of Data Subjects = 2

Number of International Phone Calls

  • Average = 16
  • Pop. SD = 2

Credit Score

  • Average = 760
  • Pop. SD = 30

Correlation > 0

Super Secret Database

30 of 51

Perform a Reconstruction Attack

30

Statistics Released

Number of Data Subjects = 2

Number of International Phone Calls

  • Average = 16
  • Pop. SD = 2

Credit Score

  • Average = 760
  • Pop. SD = 30

Correlation > 0

?

Super Secret Database

31 of 51

31

#International Phone Calls

Credit Score

???

???

???

???

Statistics Released

Number of Data Subjects = 2

Number of International Phone Calls

  • Average = 16
  • Pop. SD = 2

Credit Score

  • Average = 760
  • Pop. SD = 30

Correlation > 0

32 of 51

32

Statistics Released

Number of Data Subjects = 2

Number of International Phone Calls

  • Average = 16
  • Pop. SD = 2

Credit Score

  • Average = 760
  • Pop. SD = 30

Correlation > 0

16

760

33 of 51

33

Statistics Released

Number of Data Subjects = 2

Number of International Phone Calls

  • Average = 16
  • Pop. SD = 2

Credit Score

  • Average = 760
  • Pop. SD = 30

Correlation > 0

16

760

2

2

30

30

34 of 51

34

16

760

2

2

30

30

14

18

730

790

Statistics Released

Number of Data Subjects = 2

Number of International Phone Calls

  • Average = 16
  • Pop. SD = 2

Credit Score

  • Average = 760
  • Pop. SD = 30

Correlation > 0

35 of 51

35

#International Phone Calls

Credit Score

14

730

18

790

Statistics Released

Number of Data Subjects = 2

Number of International Phone Calls

  • Average = 16
  • Pop. SD = 2

Credit Score

  • Average = 760
  • Pop. SD = 30

Correlation > 0

#International Phone Calls

Credit Score

14

790

18

730

or

36 of 51

36

#International Phone Calls

Credit Score

14

730

18

790

Statistics Released

Number of Data Subjects = 2

Number of International Phone Calls

  • Average = 16
  • Pop. SD = 2

Credit Score

  • Average = 760
  • Pop. SD = 30

Correlation > 0

#International Phone Calls

Credit Score

14

790

18

730

or

More general approach: Solve using Mixed-Integer Linear Programming

37 of 51

37

Using 2010 statistics on

  • Census Block
  • Sex
  • Age
  • Race
  • Ethnicity

Reconstructed 46% of US population (~142 million people)

Using auxiliary data, matched names 52 million of them (linkage attack)

38 of 51

Putting it All Together:�Key Insights of the Example Attacks

38

Secret DB

Question

Answer

?

Secret DB

 

Figure 1 in Sweeney (2002)

Incorporate the defense as

part of the attack strategy

Incorporate auxiliary information

that the defense does not consider

Incorporate existing information

in unison and have a big think

Linkage Attack

Reconstruction Attack

Differencing & Averaging Attacks

39 of 51

Ever-Expanding Universe of �Computational Data Privacy Threats

39

Reconstruction

Membership

Inference

Singling-Out

Attribute

Inference

Linkage

Homogeneity

Timing

Differencing

Averaging

40 of 51

Not all data privacy threats are computational data privacy threats

40

Computational

Data Privacy

Threats

Data Privacy

Threats

41 of 51

Not all privacy threats are related to data privacy

41

Computational

Data Privacy

Threats

Data Privacy

Threats

Privacy Threats

42 of 51

Existing PETs can help sometimes in some settings, �but there is no privacy panacea (tech or otherwise)

42

Privacy Threats

Privacy-Enhancing

Technologies

Computational

Data Privacy

Threats

Data Privacy

Threats

43 of 51

43

[1] Computational Data

Privacy Attacks

[2] Computational Data

Privacy Defenses

44 of 51

Some PETs for Some Computational Privacy Concerns

  • Differential Privacy
  • Local Differential Privacy
  • Homomorphic Encryption
  • Secure Multiparty Computation
  • Federated Learning
  • And many more…

44

45 of 51

Differential Privacy (DP)

  • Well-suited for “classic statistics”
  • Goal:
    • Learn about a population,
    • Without learning “too much” about any individual
  • Approach:
    • Add “carefully-calibrated” noise to mask the value of any individual datapoint

45

 

 

 

Dataset with your data

Randomized Computation

Output

Dataset without your data

 

With

“essentially the same” probability

 

 

 

 

DP can* prevent differencing, linkage, and

reconstruction attacks, among others

46 of 51

 

46

47 of 51

Applications to Humanitarian Response

47

Source: Figure 1 in Kohli, Aiken, and Blumenstock (2023):

Privacy Guarantees for Personal Mobility Data in Humanitarian Response

Source: OpenDP Blog, Harvard University. March 4, 2025

48 of 51

Revisiting the Motivating Example

48

49 of 51

Forthcoming paper*:�Extending DP to facilitate data sharing for targeting

49

 

 

D: Targets

B: Private Projection Algorithm

0

1

0

0

1

1

0

1

1

0

0

1

0

1

0

0

0

0

1

1

0

1

0

0

0

0

1

1

1

0

1

0

1

1

0

0

0

1

0

0

0

0

1

1

1

0

0

1

1

0

0

1

0

0

1

1

E: Machine Learning

Conceptual Overview

0

0

0

1

1

1

0

1

1

0

1

1

1

1

1

0

1

0

0

1

0

1

0

0

0

0

1

1

1

0

0

0

1

0

0

0

0

1

0

1

0

0

0

1

0

0

1

1

0

1

0

1

0

0

1

1

Digital Loans

Humanitarian aid

F: Applications

*Collaboration with Professor Joshua Blumenstock. Upcoming slides showcase preliminary results.

50 of 51

Targeting requires new privacy notions to enable individual-learning

50

192K and 398K additional

exclusion errors

3.4K additional exclusion errors

No Privacy

Differential Privacy

k-Anonymity

Targeted Diff.

Privacy

A: Targeting of humanitarian aid (Togo)

*Note: This does not invalidate differential privacy, as it was created for a different task (group-level analysis). Rather, this demonstrates that new PETs may be needed for new tasks (individual-analysis).

Strongest protections,

Many additional errors

Strong protections,

Few additional errors

Baseline: no privacy protections

51 of 51

51

Moral of the Story

  • In popular discourse, privacy is often treated in a binary sense
    • “We either have or we don’t”
  • But privacy is not an “all or nothing” value
    • It is pluralistic, social, contextual, and essentially contested
  • This is not a curse, but rather a blessing
  • In different contexts, certain notions of privacy may be “more appropriate” than others
  • Various technologies, policies, and practices can be used in conjunction with one another to attend to diverse privacy concerns
  • Additionally, these technologies, policies, and practices can be tailored to domain-specific needs
  • As such, privacy protections operate on a spectrum
  • It is our job to intelligently leverage different tools and processes based on the context-specific goals