Measure-Observe-Remeasure: An Interactive Paradigm for Differentially-Private Exploratory Analysis
Priyanka Nanayakkara, Hyeok Kim, Yifan Wu, Ali Sarvghad, Narges Mahyar, Gerome Miklau, Jessica Hullman
Abstract
Differential privacy (DP) has the potential to enable privacy-preserving analysis on sensitive data, but requires analysts to judiciously spend a limited "privacy loss budget" ϵ across queries. Analysts conducting exploratory analyses do not, however, know all queries in advance and seldom have DP expertise. Thus, they are limited in their ability to specify ϵ allotments across queries prior to an analysis. To support analysts in spending ϵ efficiently, we propose a new interactive analysis paradigm, MEASURE-OBSERVE-REMEASURE, where analysts "measure" the database with a limited amount of ϵ, observe estimates and their errors, and remeasure with more ϵ as needed.
We instantiate the paradigm in an interactive visualization interface which allows analysts to spend increasing amounts of ϵ under a total budget. To observe how analysts interact with the MEASURE-OBSERVE-REMEASURE paradigm via the interface, we conduct a user study that compares the utility of ϵ allocations and findings from sensitive data participants make to the allocations and findings expected of a rational agent who faces the same decision task. We find that participants are able to use the workflow relatively successfully, including using budget allocation strategies that maximize over half of the available utility stemming from ϵ allocation. Their loss in performance relative to a rational agent appears to be driven more by their inability to access information and report it than to allocate ϵ.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 64c23493-0ced-413f-91d2-0bbb1f51360aCited by top-tier papers2
- "Having Confidence in My Confidence Intervals": How Data Users Engage with Privacy-Protected Wikipedia DataHarold Triedman, Jayshree Sarathy, Priyanka Nanayakkara, Rachel Cummings et al.CHI 2026 · 2 citations
- Accuracy-First Rényi Differential Privacy and Post-Processing ImmunityOssi Räisä, Antti Koskela, Antti HonkelaICML 2026
Builds on3
- Don't Look at the Data! How Differential Privacy Reconfigures the Practices of Data ScienceJayshree Sarathy, Sophia Song, Audrey Haque, Tania Schlatter et al.CHI 2023 · 24 citations
- DPVisCreator: Incorporating Pattern Constraints to Privacy-preserving Visualizations via Differential PrivacyJiehui Zhou, Xumeng Wang, Jason K. Wong, Huanliang Wang et al.IEEE VIS 2022 · 16 citations
- The Rational Agent Benchmark for Data VisualizationYifan Wu, Ziyang Guo, Michalis Mamakos, Jason D. Hartline et al.IEEE VIS 2023 · 8 citations
Related papers
- Cache Me If You Can: Accuracy-Aware Inference Engine for Differentially Private Data ExplorationMiti Mazmudar, Thomas Humphries, Jiaxiang Liu, Matthew Rafuse et al.VLDB 2023 · 15 citations
- Defogger: A Visual Analysis Approach for Data Exploration of Sensitive Data Protected by Differential PrivacyXumeng Wang, Shuangcheng Jiao, Chris BryanIEEE VIS 2024 · 3 citations
- Budget Sharing for Multi-Analyst Differential PrivacyDavid Pujol, Yikai Wu, Brandon Fain, Ashwin MachanavajjhalaVLDB 2021 · 7 citations
- Multi-Analyst Differential Privacy for Online Query AnsweringDavid Pujol, Albert Sun, Brandon Fain, Ashwin MachanavajjhalaVLDB 2023 · 6 citations
- DProvDB: Differentially Private Query Processing with Multi-Analyst ProvenanceShufan Zhang, Xi HeSIGMOD 2024 · 10 citations
