Unifying Re-Identification, Attribute Inference, and Data Reconstruction Risks in Differential Privacy
Fuente:
arXiv
Gespeichert in:
| Hauptverfasser: | , , , , , , |
|---|---|
| Format: | Preprint |
| Veröffentlicht: |
2025
|
| Schlagworte: | |
| Online-Zugang: | |
| Tags: |
Tag hinzufügen
Keine Tags, Fügen Sie den ersten Tag hinzu!
|
| _version_ | 1866911421514645504 |
|---|---|
| author | Kulynych, Bogdan Gomez, Juan Felipe Kaissis, Georgios Hayes, Jamie Balle, Borja Calmon, Flavio P. Raisaro, Jean Louis |
| author_facet | Kulynych, Bogdan Gomez, Juan Felipe Kaissis, Georgios Hayes, Jamie Balle, Borja Calmon, Flavio P. Raisaro, Jean Louis |
| contents | Differentially private (DP) mechanisms are difficult to interpret and calibrate because existing methods for mapping standard privacy parameters to concrete privacy risks -- re-identification, attribute inference, and data reconstruction -- are both overly pessimistic and inconsistent. In this work, we use the hypothesis-testing interpretation of DP ($f$-DP), and determine that bounds on attack success can take the same unified form across re-identification, attribute inference, and data reconstruction risks. Our unified bounds are (1) consistent across a multitude of attack settings, and (2) tunable, enabling practitioners to evaluate risk with respect to arbitrary, including worst-case, levels of baseline risk. Empirically, our results are tighter than prior methods using $\varepsilon$-DP, Rényi DP, and concentrated DP. As a result, calibrating noise using our bounds can reduce the required noise by 20% at the same risk level, which yields, e.g., an accuracy increase from 52% to 70% in a text classification task. Overall, this unifying perspective provides a principled framework for interpreting and calibrating the degree of protection in DP against specific levels of re-identification, attribute inference, or data reconstruction risk. |
| format | Preprint |
| id |
arxiv_https___arxiv_org_abs_2507_06969 |
| institution | arXiv |
| publishDate | 2025 |
| record_format | arxiv |
| spellingShingle | Unifying Re-Identification, Attribute Inference, and Data Reconstruction Risks in Differential Privacy Kulynych, Bogdan Gomez, Juan Felipe Kaissis, Georgios Hayes, Jamie Balle, Borja Calmon, Flavio P. Raisaro, Jean Louis Machine Learning Artificial Intelligence Cryptography and Security Computers and Society Differentially private (DP) mechanisms are difficult to interpret and calibrate because existing methods for mapping standard privacy parameters to concrete privacy risks -- re-identification, attribute inference, and data reconstruction -- are both overly pessimistic and inconsistent. In this work, we use the hypothesis-testing interpretation of DP ($f$-DP), and determine that bounds on attack success can take the same unified form across re-identification, attribute inference, and data reconstruction risks. Our unified bounds are (1) consistent across a multitude of attack settings, and (2) tunable, enabling practitioners to evaluate risk with respect to arbitrary, including worst-case, levels of baseline risk. Empirically, our results are tighter than prior methods using $\varepsilon$-DP, Rényi DP, and concentrated DP. As a result, calibrating noise using our bounds can reduce the required noise by 20% at the same risk level, which yields, e.g., an accuracy increase from 52% to 70% in a text classification task. Overall, this unifying perspective provides a principled framework for interpreting and calibrating the degree of protection in DP against specific levels of re-identification, attribute inference, or data reconstruction risk. |
| title | Unifying Re-Identification, Attribute Inference, and Data Reconstruction Risks in Differential Privacy |
| topic | Machine Learning Artificial Intelligence Cryptography and Security Computers and Society |
| url | https://arxiv.org/abs/2507.06969 |