Amplification by Shuffling: From Local to Central Differential Privacy via Anonymity

11/29/2018
by   Úlfar Erlingsson, et al.
4

Sensitive statistics are often collected across sets of users, with repeated collection of reports done over time. For example, trends in users' private preferences or software usage may be monitored via such reports. We study the collection of such statistics in the local differential privacy (LDP) model, and describe an algorithm whose privacy cost is polylogarithmic in the number of changes to a user's value. More fundamentally---by building on anonymity of the users' reports---we also demonstrate how the privacy cost of our LDP algorithm can actually be much lower when viewed in the central model of differential privacy. We show, via a new and general privacy amplification technique, that any permutation-invariant algorithm satisfying ε-local differential privacy will satisfy (O(ε√((1/δ)/n)), δ)-central differential privacy. By this, we explain how the high noise and √(n) overhead of LDP protocols is a consequence of them being significantly more private in the central model. As a practical corollary, our results imply that several LDP-based industrial deployments may have much lower privacy cost than their advertised ε would indicate---at least if reports are anonymized.

READ FULL TEXT

page 1

page 2

page 3

page 4

research
07/27/2019

Local Differential Privacy: a tutorial

In the past decade analysis of big data has proven to be extremely valua...
research
04/06/2020

Can Two Walk Together: Privacy Enhancing Methods and Preventing Tracking of Users

We present a new concern when collecting data from individuals that aris...
research
05/18/2019

Quantifying Differential Privacy of Gossip Protocols in General Networks

In this work, we generalize the study of quantifying the differential pr...
research
01/06/2020

ARA : Aggregated RAPPOR and Analysis for Centralized Differential Privacy

Differential privacy(DP) has now become a standard in case of sensitive ...
research
03/28/2022

FLDP: Flexible strategy for local differential privacy

Local differential privacy (LDP), a technique applying unbiased statisti...
research
06/17/2023

Online Local Differential Private Quantile Inference via Self-normalization

Based on binary inquiries, we developed an algorithm to estimate populat...
research
08/29/2019

Private Heavy Hitters and Range Queries in the Shuffled Model

An exciting new development in differential privacy is the shuffled mode...

Please sign up or login with your details

Forgot password? Click here to reset