Differential Privacy and Swapping: Examining De-Identification's Impact on Minority Representation and Privacy Preservation in the U.S. Census
Miranda Christ, Sarah Radway, Steven M. Bellovin
Abstract
There has been considerable controversy regarding the accuracy and privacy of de-identification mechanisms used in the U.S. Decennial Census. We theoretically and experimentally analyze two such classes of mechanisms, swapping and differential privacy, especially examining their effects on ethnoracial minority groups.We first prove that the expected error of queries made on swapped demographic datasets is greater in sub-populations whose racial distributions differ more from the racial distribution of the global population. We also prove that the probability that m unique entries exist in a sub-population shrinks exponentially as the sub-population size grows. These properties suggest that swapping, which prioritizes unique entries, will produce poor accuracy for minority groups.We then empirically analyze the impact of swapping and differential privacy on the accuracy and privacy of a demographic dataset. We evaluate accuracy in several ways, including methods that stress the effect on minority groups. We evaluate privacy by counting the number of re-identified entries in a simulated linkage attack. Finally, we explore the disproportionate presence of minority groups in identified entries.Our empirical lindings corroborate our theoretical results: for minority representation, the utility of differential privacy is comparable to the utility of swapping, while providing a stronger privacy guarantee. Swapping places a disproportionate privacy burden on minority groups, whereas an ε-differentially private mechanism is ε-differentially private for all subgroups.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Cited by top-tier papers4
- Epistemic Parity: Reproducibility as an Evaluation Metric for Differential PrivacyLucas Rosenblatt, Bernease Herman, Anastasia Holovenko, Wonkwon Lee et al.VLDB 2023 · 11 citations
- "Having Confidence in My Confidence Intervals": How Data Users Engage with Privacy-Protected Wikipedia DataHarold Triedman, Jayshree Sarathy, Priyanka Nanayakkara, Rachel Cummings et al.CHI 2026 · 2 citations
- A Qualitative Analysis of Practical De-Identification GuidesWentao Guo, Aditya Kishore, Adam J. Aviv, Michelle L. MazurekCCS 2024 · 1 citation
- How Researchers De-Identify Data in PracticeWentao Guo, Paige Pepitone, Adam J. Aviv, Michelle L. MazurekUSENIX Security 2025
Related papers
- Robin Hood and Matthew Effects: Differential Privacy Has Disparate Impact on Synthetic DataGeorgi Ganev, Bristena Oprisanu, Emiliano De CristofaroICML 2022 · 78 citations
- An Uncertainty Principle is a Price of Privacy-Preserving MicrodataJohn M. Abowd, Robert Ashmead, Ryan Cumings-Menon, Simson L. Garfinkel et al.NeurIPS 2021 · 17 citations
- Integer Subspace Differential PrivacyPrathamesh Dharangutte, Jie Gao, Ruobin Gong, Fang-Yi YuAAAI 2023 · 8 citations
- Removing Disparate Impact on Model Accuracy in Differentially Private Stochastic Gradient DescentDepeng Xu, Wei Du, Xintao WuKDD 2021 · 32 citations
- SMOTE and Mirrors: Exposing Privacy Leakage from Synthetic Minority OversamplingGeorgi Ganev, MohammadReza Nazari, Rees Davison, Amirhassan Fallah Dizche et al.ICLR 2026 · 6 citations
