Unifying Re-Identification, Attribute Inference, and Data Reconstruction Risks in Differential Privacy

Fuente: arXiv
Gespeichert in:
Bibliographische Detailangaben
Hauptverfasser: Kulynych, Bogdan, Gomez, Juan Felipe, Kaissis, Georgios, Hayes, Jamie, Balle, Borja, Calmon, Flavio P., Raisaro, Jean Louis
Format: Preprint
Veröffentlicht: 2025
Schlagworte:
Online-Zugang:
Tags: Tag hinzufügen
Keine Tags, Fügen Sie den ersten Tag hinzu!
_version_ 1866911421514645504
author Kulynych, Bogdan
Gomez, Juan Felipe
Kaissis, Georgios
Hayes, Jamie
Balle, Borja
Calmon, Flavio P.
Raisaro, Jean Louis
author_facet Kulynych, Bogdan
Gomez, Juan Felipe
Kaissis, Georgios
Hayes, Jamie
Balle, Borja
Calmon, Flavio P.
Raisaro, Jean Louis
contents Differentially private (DP) mechanisms are difficult to interpret and calibrate because existing methods for mapping standard privacy parameters to concrete privacy risks -- re-identification, attribute inference, and data reconstruction -- are both overly pessimistic and inconsistent. In this work, we use the hypothesis-testing interpretation of DP ($f$-DP), and determine that bounds on attack success can take the same unified form across re-identification, attribute inference, and data reconstruction risks. Our unified bounds are (1) consistent across a multitude of attack settings, and (2) tunable, enabling practitioners to evaluate risk with respect to arbitrary, including worst-case, levels of baseline risk. Empirically, our results are tighter than prior methods using $\varepsilon$-DP, Rényi DP, and concentrated DP. As a result, calibrating noise using our bounds can reduce the required noise by 20% at the same risk level, which yields, e.g., an accuracy increase from 52% to 70% in a text classification task. Overall, this unifying perspective provides a principled framework for interpreting and calibrating the degree of protection in DP against specific levels of re-identification, attribute inference, or data reconstruction risk.
format Preprint
id arxiv_https___arxiv_org_abs_2507_06969
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle Unifying Re-Identification, Attribute Inference, and Data Reconstruction Risks in Differential Privacy
Kulynych, Bogdan
Gomez, Juan Felipe
Kaissis, Georgios
Hayes, Jamie
Balle, Borja
Calmon, Flavio P.
Raisaro, Jean Louis
Machine Learning
Artificial Intelligence
Cryptography and Security
Computers and Society
Differentially private (DP) mechanisms are difficult to interpret and calibrate because existing methods for mapping standard privacy parameters to concrete privacy risks -- re-identification, attribute inference, and data reconstruction -- are both overly pessimistic and inconsistent. In this work, we use the hypothesis-testing interpretation of DP ($f$-DP), and determine that bounds on attack success can take the same unified form across re-identification, attribute inference, and data reconstruction risks. Our unified bounds are (1) consistent across a multitude of attack settings, and (2) tunable, enabling practitioners to evaluate risk with respect to arbitrary, including worst-case, levels of baseline risk. Empirically, our results are tighter than prior methods using $\varepsilon$-DP, Rényi DP, and concentrated DP. As a result, calibrating noise using our bounds can reduce the required noise by 20% at the same risk level, which yields, e.g., an accuracy increase from 52% to 70% in a text classification task. Overall, this unifying perspective provides a principled framework for interpreting and calibrating the degree of protection in DP against specific levels of re-identification, attribute inference, or data reconstruction risk.
title Unifying Re-Identification, Attribute Inference, and Data Reconstruction Risks in Differential Privacy
topic Machine Learning
Artificial Intelligence
Cryptography and Security
Computers and Society
url https://arxiv.org/abs/2507.06969