Mechanisms for Robust Local Differential Privacy

Milan Lopuhaä-Zwakenberg,Jasper Goseling
DOI: https://doi.org/10.3390/e26030233
IF: 2.738
2024-03-07
Entropy
Abstract:We consider privacy mechanisms for releasing data X=(S,U), where S is sensitive and U is non-sensitive. We introduce the robust local differential privacy (RLDP) framework, which provides strong privacy guarantees, while preserving utility. This is achieved by providing robust privacy: our mechanisms do not only provide privacy with respect to a publicly available estimate of the unknown true distribution, but also with respect to similar distributions. Such robustness mitigates the potential privacy leaks that might arise from the difference between the true distribution and the estimated one. At the same time, we mitigate the utility penalties that come with ordinary differential privacy, which involves making worst-case assumptions and dealing with extreme cases. We achieve robustness in privacy by constructing an uncertainty set based on a Rényi divergence. By analyzing the structure of this set and approximating it with a polytope, we can use robust optimization to find mechanisms with high utility. However, this relies on vertex enumeration and becomes computationally inaccessible for large input spaces. Therefore, we also introduce two low-complexity algorithms that build on existing LDP mechanisms. We evaluate the utility and robustness of the mechanisms using numerical experiments and demonstrate that our mechanisms provide robust privacy, while achieving a utility that is close to optimal.
physics, multidisciplinary
What problem does this paper attempt to address?
This paper attempts to address the problem of how to maintain data utility while protecting privacy when releasing data containing sensitive information (S) and non-sensitive information (U). Specifically, the authors propose a Robust Local Differential Privacy (RLDP) framework aimed at providing strong privacy protection while reducing the utility loss caused by extreme assumptions in traditional differential privacy methods. ### Main Issues 1. **Balancing Privacy Protection and Data Utility**: - In traditional Local Differential Privacy (LDP) methods, to ensure privacy, worst-case assumptions are often made, which leads to a significant decline in data utility. - The authors propose a new framework—Robust Local Differential Privacy (RLDP), which improves data utility while ensuring privacy by considering the uncertainty in distribution estimation. 2. **Handling Partially Sensitive Data**: - When data contains partially sensitive information (S) and partially non-sensitive information (U), how to design a privacy mechanism that allows the released data to retain as much information as possible without disclosing too much sensitive information. - The authors address this by constructing an uncertainty set (based on Rényi divergence) to handle the differences between the true distribution and the estimated distribution, thereby providing robust privacy protection. ### Solutions 1. **Robust Local Differential Privacy (RLDP) Framework**: - By constructing an uncertainty set \( F \), which includes all possible true distributions \( P^* \). - Designing a privacy mechanism \( Q \) such that for all distributions in \( F \), the local differential privacy condition is satisfied. 2. **Optimizing Privacy Mechanism**: - Using robust optimization techniques to find a privacy mechanism with high utility over the uncertainty set \( F \). - Proposing two low-complexity privacy mechanisms: Independent Reporting (IR) and Secret Randomized Response (SRR), and validating their effectiveness through numerical experiments. ### Main Contributions 1. **Constructing the Uncertainty Set \( F \)**: - Using Rényi divergence to define the uncertainty set \( F \) and analyzing its structure and statistical properties. - Proving that the projected set remains spherical and providing bounds for the \( \ell_1 \) norm. 2. **Robust Optimization Method**: - Approximating the uncertainty set \( F \) as a polytope and using robust optimization techniques to find the optimal privacy mechanism PolyOpt. - Proposing two low-complexity privacy mechanisms: Independent Reporting (IR) and Secret Randomized Response (SRR), and proving their effectiveness. 3. **Numerical Experiments**: - Validating the effectiveness of the RLDP framework through numerical experiments, particularly on synthetic datasets and real census data. - Comparing with traditional LDP methods, demonstrating the advantage of RLDP in maintaining data utility. ### Conclusion This paper addresses the problem of balancing privacy protection and data utility in the release of partially sensitive data by introducing the Robust Local Differential Privacy (RLDP) framework. By constructing an uncertainty set and using robust optimization techniques, the authors propose a new method for designing privacy mechanisms that maximizes data utility while protecting privacy.