DP4SQL: Differentially Private SQL with Flexible Privacy Policies
Andrew Cascio, KinChin Tong, Daniel Kifer, Zeyu Ding, Danfeng Zhang
摘要
The plausible deniability model of differential privacy for singletable datasets is well-understood. However, applying differential privacy to relational databases is much trickier: each application needs flexibility in specifying the pieces of information about an entity, spread across multiple relations, that require plausible deniability guarantees. Existing differentially private SQL systems only support rigid privacy policies. Even seemingly small changes, such as specifying that some tables need to protect the existence of records while others only need to protect the record contents, require significant manual effort in updating their privacy accountants and proving their correctness. One example of a challenge is the presence of partially public data. Public columns in a table (e.g., faculty names in a university dataset and partial course enrollment information) can cause some queries to require more noise (compared to fully private data), while others require less noise. This kind of reasoning is not supported in existing systems. Another example is when different parts of records (e.g., demographics, financial data) require different levels of privacy protection. Again, existing differentially private SQL systems need to rewrite their rules for calculating query stability in order to support such a feature. This paper presents DP4SQL, a differentially private SQL system that allows data curators to better customize the plausible deniability requirements for their relational databases. This avoids the drawbacks of the "one-sizefits-all" systems that would either underprotect the data or inject too much noise into query answers. CCS Concepts • Security and privacy → Database and storage security.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
它引用的顶会 Paper2
相关 Paper
- DProvDB: Differentially Private Query Processing with Multi-Analyst ProvenanceShufan Zhang, Xi HeSIGMOD 2024 · 被引用 10 次
- Residual Sensitivity for Differentially Private Multi-Way JoinsWei Dong, Ke YiSIGMOD 2021 · 被引用 32 次
- Don't Be a Tattle-Tale: Preventing Leakages through Data Dependencies on Access Control Protected DataPrimal Pappachan, Shufan Zhang, Xi He, Sharad MehrotraVLDB 2022 · 被引用 14 次
- Kamino: Constraint-Aware Differentially Private Data SynthesisChang Ge, Shubhankar Mohapatra, Xi He, Ihab F. IlyasVLDB 2021 · 被引用 55 次
- DPXPlain: Privately Explaining Aggregate Query AnswersYuchao Tao, Amir Gilad, Ashwin Machanavajjhala, Sudeepa RoyVLDB 2023 · 被引用 15 次
