Enregistré dans:
Détails bibliographiques
Auteurs principaux: Tholoniat, Pierre, Kostopoulou, Kelly, McNeely, Peter, Sodhi, Prabhpreet Singh, Varanasi, Anirudh, Case, Benjamin, Cidon, Asaf, Geambasu, Roxana, Lécuyer, Mathias
Format: Preprint
Publié: 2024
Sujets:
Accès en ligne:https://arxiv.org/abs/2405.16719
Tags: Ajouter un tag
Pas de tags, Soyez le premier à ajouter un tag!
_version_ 1866913526040231936
author Tholoniat, Pierre
Kostopoulou, Kelly
McNeely, Peter
Sodhi, Prabhpreet Singh
Varanasi, Anirudh
Case, Benjamin
Cidon, Asaf
Geambasu, Roxana
Lécuyer, Mathias
author_facet Tholoniat, Pierre
Kostopoulou, Kelly
McNeely, Peter
Sodhi, Prabhpreet Singh
Varanasi, Anirudh
Case, Benjamin
Cidon, Asaf
Geambasu, Roxana
Lécuyer, Mathias
contents With the impending removal of third-party cookies from major browsers and the introduction of new privacy-preserving advertising APIs, the research community has a timely opportunity to assist industry in qualitatively improving the Web's privacy. This paper discusses our efforts, within a W3C community group, to enhance existing privacy-preserving advertising measurement APIs. We analyze designs from Google, Apple, Meta and Mozilla, and augment them with a more rigorous and efficient differential privacy (DP) budgeting component. Our approach, called Cookie Monster, enforces well-defined DP guarantees and enables advertisers to conduct more private measurement queries accurately. By framing the privacy guarantee in terms of an individual form of DP, we can make DP budgeting more efficient than in current systems that use a traditional DP definition. We incorporate Cookie Monster into Chrome and evaluate it on microbenchmarks and advertising datasets. Across workloads, Cookie Monster significantly outperforms baselines in enabling more advertising measurements under comparable DP protection.
format Preprint
id arxiv_https___arxiv_org_abs_2405_16719
institution arXiv
publishDate 2024
record_format arxiv
spellingShingle Cookie Monster: Efficient On-device Budgeting for Differentially-Private Ad-Measurement Systems
Tholoniat, Pierre
Kostopoulou, Kelly
McNeely, Peter
Sodhi, Prabhpreet Singh
Varanasi, Anirudh
Case, Benjamin
Cidon, Asaf
Geambasu, Roxana
Lécuyer, Mathias
Cryptography and Security
With the impending removal of third-party cookies from major browsers and the introduction of new privacy-preserving advertising APIs, the research community has a timely opportunity to assist industry in qualitatively improving the Web's privacy. This paper discusses our efforts, within a W3C community group, to enhance existing privacy-preserving advertising measurement APIs. We analyze designs from Google, Apple, Meta and Mozilla, and augment them with a more rigorous and efficient differential privacy (DP) budgeting component. Our approach, called Cookie Monster, enforces well-defined DP guarantees and enables advertisers to conduct more private measurement queries accurately. By framing the privacy guarantee in terms of an individual form of DP, we can make DP budgeting more efficient than in current systems that use a traditional DP definition. We incorporate Cookie Monster into Chrome and evaluate it on microbenchmarks and advertising datasets. Across workloads, Cookie Monster significantly outperforms baselines in enabling more advertising measurements under comparable DP protection.
title Cookie Monster: Efficient On-device Budgeting for Differentially-Private Ad-Measurement Systems
topic Cryptography and Security
url https://arxiv.org/abs/2405.16719