Guy rothblum microsoft




















For the task of sanitizing with a synthetic dataset output, we map the boundary between computational feasibility and infeasibility with respect to a variety of utility measures. For the potentially easier task of sanitizing with unrestricted output format, we show a tight qualitative and quantitative connection between hardness of sanitizing and the existence of traitor tracing schemes.

The goal of a statistical database is to provide statistics about a population while simultaneously protecting the privacy of the individual records in the database. The tension between privacy and usability of statistical databases has attracted much attention in statistics, theoretical computer science, security, and database communities in recent years.

A line of research initiated by Dinur and Nissim investigates for a particular type of queries, lower bounds on the distortion needed in order to prevent gross violations of privacy. The first result in the current paper simplifies and sharpens the Dinur and Nissim result. The Dinur-Nissim style results are strong because they demonstrate insecurity of all low-distortion privacy mechanisms.

Restricting attention to a wide and realistic subset of possible low-distortion mechanisms, our second result is a more acute attack, requiring only a fixed number of queries for each bit revealed.

Consider a pollster who wishes to collect private, sensitive data from a number of distrustful individuals. How might the pollster convince the respondents that it is trustworthy? Alternately, what mechanism could the respondents insist upon to ensure that mismanagement of their data is detectable and publicly demonstrable? We detail this problem, and provide simple data submission protocols with the properties that a leakage of private data by the pollster results in evidence of the transgression and b the evidence cannot be fabricated without breaking cryptographic assumptions.

The respondents are assured that appropriate penalties are applied to a leaky pollster, while the protection from spurious indictment ensures that any honest pollster has no disincentive to participate in such a scheme. In this work we provide efficient distributed protocols for generating shares of random noise, secure against malicious participants.

The purpose of the noise generation is to create a distributed implementation of the privacy-preserving statistical databases described in recent papers [14,4,13]. In these databases, privacy is obtained by perturbing the true answer to a database query by the addition of a small amount of Gaussian or exponentially distributed random noise. A distributed implementation eliminates the need for a trusted database administrator. The results for noise generation are of independent interest.

The generation of Gaussian noise introduces a technique for distributing shares of many unbiased coins with fewer executions of verifiable secret sharing than would be needed using previous approaches reduced by a factor of n.

The generation of exponentially distributed noise uses two shallow circuits: one for generating many arbitrarily but identically biased coins at an amortized cost of two unbiased random bits apiece, independent of the bias, and the other to combine bits of appropriate biases to obtain an exponential distribution.

We initiate a theoretical study of the census problem. Informally, in a census individual respondents give private information to a trusted party the census bureau , who publishes a sanitized version of the data. We also obtain two utility results involving clustering. In a recent paper Dinur and Nissim considered a statistical database in which a trusted database administrator monitors queries and introduces noise to the responses with the goal of maintaining data privacy.

As databases grow increasingly large, the possibility of being able to query only a sub-linear number of times becomes realistic. In addition, we show how to use our techniques for datamining on published noisy statistics. Follow us:. Share this page:. Database Privacy Established: November 24, Overview Publications Downloads Overview The problem of statistical disclosure control—revealing accurate statistics about a population while preserving the privacy of individuals—has a venerable history.

For selected publications organized by topic and chronological ordered scroll down. Expand all Collapse all. Privacy Workshop , October 10—11, We present a learning algorithm that Eve can use to successfully learn to impersonate Bob in the information-theoretic setting. We also show that in the computational setting an efficient Eve can learn to impersonate any efficient Bob if and only if one-way function do not exist. Follow us:. Share this page:. Learning to impersonate. Ashkan Aazami Senior Data Scientist.

Najeeb G. Abdulhamid Researcher. Robin Abraham Senior Director. Mahmoud Adada Principal Engineering Manager. Logan Adams Hardware Engineer. Deanne Adams Xbox Researcher. Kaska Adoteye Senior Data Scientist. Vidhan Agarwal Senior Software Engineer. Sharad Agarwal Senior Principal Researcher.



0コメント

  • 1000 / 1000