DIFFERENTIAL PRIVACY IN PRACTICE: EXPOSE YOUR EPSILONS!

142Citations
Citations of this article
84Readers
Mendeley users who have this article in their library.

Abstract

Differential privacy is at a turning point. Implementations have been successfully leveraged in private industry, the public sector, and academia in a wide variety of applications, allowing scientists, engineers, and researchers to learn about populations of interest without specifically learning about individuals. Because differential privacy permits us to quantify cumulative privacy loss, these differentially private systems will, for the first time, enable the measurement and comparison of the total privacy loss incurred by these data-intensive activities. Appropriately leveraged, this could be a watershed moment for privacy. Like other technologies and techniques that allow for a range of instantiations, implementation details matter. When meaningfully implemented, differential privacy supports deep data-driven insights with minimal worst-case privacy loss. When not meaningfully implemented, differential privacy delivers privacy mostly in name. Using differential privacy to maximize learning while providing a meaningful degree of privacy requires judicious choices with respect to the privacy parameter ɛ (among other factors). However, there is little understanding of what is the optimal value of ɛ for a given system or classes of systems, purposes, data, etc., or how to go about figuring it out. To understand current differential privacy implementations and how organizations make these key choices in practice, we conducted interviews with differential privacy practitioners to learn from their experiences. We found no clear consensus on how to choose ɛ, nor agreement on how to approach this and other key implementation decisions. Given the importance of these details there is a need for shared learning amongst the differential privacy community. To serve these purposes, and foster competition, we propose the creation of the Epsilon Registry – a publicly available communal body of knowledge about differential privacy implementations that can be used by various stakeholders to drive the identification and adoption of judicious differentially private implementations.

Cite

CITATION STYLE

APA

Dwork, C., Kohli, N., & Mulligan, D. (2019). DIFFERENTIAL PRIVACY IN PRACTICE: EXPOSE YOUR EPSILONS! Journal of Privacy and Confidentiality, 9(2). https://doi.org/10.29012/jpc.689

Register to see more suggestions

Mendeley helps you to discover research relevant for your work.

Already have an account?

Save time finding and organizing research with Mendeley

Sign up for free