Lune

ICLR2022Top-tier venue

Privacy Implications of Shuffling

Casey Meehan, Amrita Roy Chowdhury, Kamalika Chaudhuri, Somesh Jha

2022Year
10Citations
4Top-tier citations

Abstract

LDP deployments are vulnerable to inference attacks as an adversary can link the noisy responses to their identity and subsequently, auxiliary information using the order of the data. An alternative model, shuffle DP, prevents this by shuffling the noisy responses uniformly at random. However, this limits the data learnability -only symmetric functions (input order agnostic) can be learned. In this paper, we strike a balance and show that systematic shuffling of the noisy responses can thwart specific inference attacks while retaining some meaningful data learnability. To this end, we propose a novel privacy guarantee, d σ -privacy, that captures the privacy of the order of a data sequence. d σ -privacy allows tuning the granularity at which the ordinal information is maintained, which formalizes the degree the resistance to inference attacks trading it off with data learnability. Additionally, we propose a novel shuffling mechanism that can achieve d σ -privacy and demonstrate the practicality of our mechanism via evaluation on real-world datasets. 1 The analyst and the adversary could be same, we refer to them separately for the ease of understanding.

Ask about this paper

Your agent reads all of it.

Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.

Questions to start from

Your agent calls

Luneget_paper_fulltext

Ask in Lune

Free to start. No credit card required.

lune papers fulltext abe94f3e-c018-4eba-bc68-4a4ab41fb340

Cited by top-tier papers4

Ask how each one uses it

Builds on3

Related papers

Dusk over the sea between two cliffs drawn in fine vertical lines