Computational Differential Privacy Ilya Mironov

Published  . 0 views
↓ Download
Computational Differential Privacy Ilya Mironov
1 / 1
Computational Differential Privacy Ilya Mironov - slide 1 of 20 Computational Differential Privacy Ilya Mironov - slide 2 of 20 Computational Differential Privacy Ilya Mironov - slide 3 of 20 Computational Differential Privacy Ilya Mironov - slide 4 of 20 Computational Differential Privacy Ilya Mironov - slide 5 of 20 Computational Differential Privacy Ilya Mironov - slide 6 of 20 Computational Differential Privacy Ilya Mironov - slide 7 of 20 Computational Differential Privacy Ilya Mironov - slide 8 of 20 Computational Differential Privacy Ilya Mironov - slide 9 of 20 Computational Differential Privacy Ilya Mironov - slide 10 of 20 Computational Differential Privacy Ilya Mironov - slide 11 of 20 Computational Differential Privacy Ilya Mironov - slide 12 of 20 Computational Differential Privacy Ilya Mironov - slide 13 of 20 Computational Differential Privacy Ilya Mironov - slide 14 of 20 Computational Differential Privacy Ilya Mironov - slide 15 of 20 Computational Differential Privacy Ilya Mironov - slide 16 of 20 Computational Differential Privacy Ilya Mironov - slide 17 of 20 Computational Differential Privacy Ilya Mironov - slide 18 of 20 Computational Differential Privacy Ilya Mironov - slide 19 of 20 Computational Differential Privacy Ilya Mironov - slide 20 of 20
Description: Computational Differential Privacy Ilya Mironov (MICROSOFT) Omkant Pandey (UCLA) Omer Reingold (MICROSOFT) Salil Vadhan (HARVARD) Focus of the Talk Relaxations of differential privacy for computational adversaries How they relate to one

Related Topics

Download Presentation

"Computational Differential Privacy Ilya Mironov" is the property of its rightful owner. Permission is granted to download and print the materials on this website for personal, non-commercial use only, and to display it on your personal computer provided you do not modify the materials and that you retain all copyright notices contained in the materials. By downloading content from our website, you accept the terms of this agreement.

Presentation Transcript

slide1. Computational Differential Privacy Ilya Mironov (MICROSOFT) Omkant Pandey (UCLA) Omer Reingold (MICROSOFT) Salil Vadhan (HARVARD)<br>
slide2. Focus of the Talk Relaxations of differential privacy for computational adversaries

How they relate to one another and other existing notions
Natural protocols demonstrating their benefits<br>
slide3. Motivation Achieve better utility
Standard MPC does not prevent what is leaked by the output
Can we combine computational MPC protocols with DP-functions [DKMMN’06,BNO’08]?
Nontrivial differentially private mechanisms must be randomized
Applications typically use pseudorandom sources. What are the formal privacy guarantees achieved?<br>
slide4. Differential Privacy [Dwork’06] Mechanism K provides privacy to an individual, if individual’s data effects the output of K only “little” “adjacent” means “differ in one individual’s entry”<br>
slide5. Pictorial Representation — bad outcome — probability with record x — probability without record x<br>
slide6. Towards Computational Notions Equivalently,<br>
slide7. First Definition: IND-CDP<br>
slide8. Simulation-based Approach K(D)<br>
slide9. Second Definition: SIM-CDP ε-SIM-CDP : Mechanism K is ε-SIM-CDP if there exists an ε-differentially-private mechanism M such that for all D, distributions M(D) and K(D) are computationally indistinguishable.<br>
slide10. Immediate Questions Are these definitions equivalent?
Not hard to see that

Main question:<br>
slide11. Connection with Dense Models [RTTV’08, Imp’08] Distribution X is α-dense in Y if for all tests T,

X is α-pseudodense in Y if for all PPT tests T, [RTTV’08] : Reingold, O., Trevisan, L., Tulsiani, M., Vadhan, S.
“Dense subsets of Pseudorandom Sets”, FOCS 2008.<br>
slide12. Connection with Dense Models [RTTV’08, Imp’08] Differential Privacy:



In the language of dense models
K(D1) is eε-dense in K(D2)
K(D2) is eε-dense in K(D1) ε-DP: K(D1) and K(D2) are mutually eε-dense<br>
slide13. Connection with Dense Models [RTTV ’08, Imp’08] ε-IND-CDP:



In the language of dense models
K(D1) is eε-pseudodense in K(D2)
K(D2) is eε-pseudodense in K(D1) ε-IND-CDP: K(D1) and K(D2) are mutually eε-pseudodense<br>
slide14. Some Notation<br>
slide15. The Dense Model Theorem [RTTV’08] Thm : If X1 is pseudodense in X2, there exists a model Y (truly) dense in X2 such that X1 is computationally indistinguishable from Y.<br>
slide16. (IND-CDP) Y1 Y2 ? Proof Ideas Extension of DM T<br>
slide17. To Recap We prove an extension of “The Dense Model Theorem” of [RTTV’08].
Sufficient to establish:

Still OPEN: IND-CDP  SIM-CDP<br>
slide18. Benefits: Better Utility CDP : Easily get (1/ε) error w/ constant probability. Protocol: Trusted Party: H(x,y)+Lap(1/ε)<br>
slide19. Other Results A new protocol for Hamming Distance:
Differentially private (standard)
Constant multiplicative error
Differentially Private Two-Party Computation<br>
slide20. Thank you for your attention!<br>