4.5 Article

Tunable Measures for Information Leakage and Applications to Privacy-Utility Tradeoffs

期刊

IEEE TRANSACTIONS ON INFORMATION THEORY
卷 65, 期 12, 页码 8043-8066

出版社

IEEE-INST ELECTRICAL ELECTRONICS ENGINEERS INC
DOI: 10.1109/TIT.2019.2935768

关键词

Mutual information; maximal leakage; maximal alpha-leakage; Sibson mutual information; Arimoto mutual information; f-divergence; privacy-utility tradeoff; hard distortion

资金

  1. National Science Foundation [CCF-1422358, CCF-1350914, CIF-1815361, CIF-1901243]

向作者/读者索取更多资源

We introduce a tunable measure for information leakage called maximal alpha-leakage. This measure quantifies the maximal gain of an adversary in inferring any (potentially random) function of a dataset from a release of the data. The inferential capability of the adversary is, in turn, quantified by a class of adversarial loss functions that we introduce as alpha-loss, alpha is an element of [1, infinity) boolean OR {infinity}. The choice of alpha determines the specific adversarial action and ranges from refining a belief (about any function of the data) for alpha = 1 to guessing the most likely value for alpha = infinity while refining the alpha th moment of the belief for alpha in between. Maximal alpha-leakage then quantifies the adversarial gain under alpha-loss over all possible functions of the data. In particular, for the extremal values of alpha = 1 and alpha = infinity, maximal alpha-leakage simplifies to mutual information and maximal leakage, respectively. For alpha is an element of (1, infinity) this measure is shown to be the Arimoto channel capacity of order alpha. We show that maximal alpha-leakage satisfies data processing inequalities and a sub-additivity property thereby allowing for a weak composition result. Building upon these properties, we use maximal alpha-leakage as the privacy measure and study the problem of data publishing with privacy guarantees, wherein the utility of the released data is ensured via a hard distortion constraint. Unlike average distortion, hard distortion provides a deterministic guarantee of fidelity. We show that under a hard distortion constraint, for alpha > 1 the optimal mechanism is independent of alpha, and therefore, the resulting optimal tradeoff is the same for all values of alpha > 1. Finally, the tunability of maximal alpha-leakage as a privacy measure is also illustrated for binary data with average Hamming distortion as the utility measure.

作者

我是这篇论文的作者
点击您的名字以认领此论文并将其添加到您的个人资料中。

评论

主要评分

4.5
评分不足

次要评分

新颖性
-
重要性
-
科学严谨性
-
评价这篇论文

推荐

暂无数据
暂无数据