USENIX Security2023Top-tier venue
What Are the Chances? Explaining the Epsilon Parameter in Differential Privacy
Priyanka Nanayakkara, Mary Anne Smart, Rachel Cummings, Gabriel Kaptchuk, Elissa M. Redmiles
Abstract
Differential privacy (DP) is a mathematical privacy notion increasingly deployed across government and industry. With DP, privacy protections are probabilistic: they are bounded by the privacy budget parameter, . Prior work in health and computational science finds that people struggle to reason about probabilistic risks. Yet, communicating the implications of to people contributing their data is vital to avoiding privacy theater -- presenting meaningless privacy protection as meaningful -- and empowering more informed data-sharing decisions. Drawing on best practices in risk communication and usability, we develop three methods to convey probabilistic DP guarantees to end users: two that communicate odds and one offering concrete examples of DP outputs. We quantitatively evaluate these explanation methods in a vignette survey study () via three metrics: objective risk comprehension, subjective privacy understanding of DP guarantees, and self-efficacy. We find that odds-based explanation methods are more effective than (1) output-based methods and (2) state-of-the-art approaches that gloss over information about . Further, when offered information about , respondents are more willing to share their data than when presented with a state-of-the-art DP explanation; this willingness to share is sensitive to values: as privacy protections weaken, respondents are less likely to share data.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers15
- Prior-itizing Privacy: A Bayesian Approach to Setting the Privacy Budget in Differential PrivacyZeki Kazan, Jerome P. ReiterNeurIPS 2024 · 23 citations
- Attack-Aware Noise Calibration for Differential PrivacyBogdan Kulynych, Juan Felipe Gómez, Georgios Kaissis, Flávio P. Calmon et al.NeurIPS 2024 · 23 citations
- Unifying Re-Identification, Attribute Inference, and Data Reconstruction Risks in Differential PrivacyBogdan Kulynych, Juan Felipe Gómez, Georgios Kaissis, Jamie Hayes et al.NeurIPS 2025 · 15 citations
- Privacy and Accuracy-Aware AI/ML Model DeduplicationHong Guan, Lei Yu, Lixi Zhou, Li Xiong et al.SIGMOD 2025 · 3 citations
- "Having Confidence in My Confidence Intervals": How Data Users Engage with Privacy-Protected Wikipedia DataHarold Triedman, Jayshree Sarathy, Priyanka Nanayakkara, Rachel Cummings et al.CHI 2026 · 2 citations
Builds on4
- Towards Effective Differential Privacy Communication for Users' Data Sharing Decision and ComprehensionAiping Xiong, Tianhao Wang, Ninghui Li, Somesh JhaS&P 2020 · 72 citations
- "I need a better description": An Investigation Into User Expectations For Differential PrivacyRachel Cummings, Gabriel Kaptchuk, Elissa M. RedmilesCCS 2021 · 45 citations
- Investigating Perceptual Biases in Icon ArraysCindy Xiong, Ali Sarvghad, Daniel G. Goldstein, Jake M. Hofman et al.CHI 2022 · 35 citations
- Understanding Risks of Privacy Theater with Differential PrivacyMary Anne Smart, Dhruv Sood, Kristen VaccaroCSCW 2022 · 27 citations
Related papers
- Casual Users and Rational Choices within Differential PrivacyNarges Ashena, Oana Inel, Badrie L. Persaud, Abraham BernsteinS&P 2024 · 3 citations
- Communicating the Privacy-Utility Trade-off: Supporting Informed Data Donation with Privacy Decision Interfaces for Differential PrivacyDaniel Franzen, Claudia Müller-Birn, Odette WegwarthCSCW 2024 · 11 citations
- Am I Private and If So, how Many?: Communicating Privacy Guarantees of Differential Privacy with Risk Communication FormatsDaniel Franzen, Saskia Nuñez von Voigt, Peter Sörries, Florian Tschorsch et al.CCS 2022 · 13 citations
- Don't Look at the Data! How Differential Privacy Reconfigures the Practices of Data ScienceJayshree Sarathy, Sophia Song, Audrey Haque, Tania Schlatter et al.CHI 2023 · 24 citations
- Private Counting from Anonymous Messages: Near-Optimal Accuracy with Vanishing Communication OverheadBadih Ghazi, Ravi Kumar, Pasin Manurangsi, Rasmus PaghICML 2020 · 59 citations
