A New Lower Bound of Privacy Budget for Distributed Differential Privacy
Title | A New Lower Bound of Privacy Budget for Distributed Differential Privacy |
Publication Type | Conference Paper |
Year of Publication | 2017 |
Authors | Lu, Z., Shen, H. |
Conference Name | 2017 18th International Conference on Parallel and Distributed Computing, Applications and Technologies (PDCAT) |
ISBN Number | 978-1-5386-3151-5 |
Keywords | composability, data aggregation, data curator, data privacy, Differential privacy, distributed computing, distributed data aggregation, distributed data aggregation system, Distributed databases, distributed differential privacy, distributed processing, global differential privacy, global privacy performance, Human Behavior, local differential privacy, low data utility, malicious collusion attacks, Mathematical model, privacy, privacy budget, privacy preservation, pubcrawl, Resiliency, Scalability, security of data, Sensitivity, unconditional aggregation sensitivity |
Abstract | Distributed data aggregation via summation (counting) helped us to learn the insights behind the raw data. However, such computing suffered from a high privacy risk of malicious collusion attacks. That is, the colluding adversaries infer a victim's privacy from the gaps between the aggregation outputs and their source data. Among the solutions against such collusion attacks, Distributed Differential Privacy (DDP) shows a significant effect of privacy preservation. Specifically, a DDP scheme guarantees the global differential privacy (the presence or absence of any data curator barely impacts the aggregation outputs) by ensuring local differential privacy at the end of each data curator. To guarantee an overall privacy performance of a distributed data aggregation system against malicious collusion attacks, part of the existing work on such DDP scheme aim to provide an estimated lower bound of privacy budget for the global differential privacy. However, there are two main problems: low data utility from using a large global function sensitivity; unknown privacy guarantee when the aggregation sensitivity of the whole system is less than the sum of the data curator's aggregation sensitivity. To address these problems while ensuring distributed differential privacy, we provide a new lower bound of privacy budget, which works with an unconditional aggregation sensitivity of the whole distributed system. Moreover, we study the performance of our privacy bound in different scenarios of data updates. Both theoretical and experimental evaluations show that our privacy bound offers better global privacy performance than the existing work. |
URL | https://ieeexplore.ieee.org/document/8326802 |
DOI | 10.1109/PDCAT.2017.00014 |
Citation Key | lu_new_2017 |
- Human behavior
- unconditional aggregation sensitivity
- Sensitivity
- security of data
- Scalability
- Resiliency
- pubcrawl
- privacy preservation
- privacy budget
- privacy
- Mathematical model
- malicious collusion attacks
- low data utility
- local differential privacy
- composability
- global privacy performance
- global differential privacy
- distributed processing
- distributed differential privacy
- Distributed databases
- distributed data aggregation system
- distributed data aggregation
- distributed computing
- differential privacy
- data privacy
- data curator
- data aggregation