pith. sign in

Usable Differential Privacy: A Case Study with PSI

1 Pith paper cite this work. Polarity classification is still indexing.

1 Pith paper citing it
abstract

Differential privacy is a promising framework for addressing the privacy concerns in sharing sensitive datasets for others to analyze. However differential privacy is a highly technical area and current deployments often require experts to write code, tune parameters, and optimize the trade-off between the privacy and accuracy of statistical releases. For differential privacy to achieve its potential for wide impact, it is important to design usable systems that enable differential privacy to be used by ordinary data owners and analysts. PSI is a tool that was designed for this purpose, allowing researchers to release useful differentially private statistical information about their datasets without being experts in computer science, statistics, or privacy. We conducted a thorough usability study of PSI to test whether it accomplishes its goal of usability by non-experts. The usability test illuminated which features of PSI are most user-friendly and prompted us to improve aspects of the tool that caused confusion. The test also highlighted some general principles and lessons for designing usable systems for differential privacy, which we discuss in depth.

fields

cs.DB 1

years

2023 1

verdicts

UNVERDICTED 1

representative citing papers

Within-Dataset Disclosure Risk for Differential Privacy

cs.DB · 2023-10-19 · unverdicted · novelty 5.0

Derives a relative disclosure risk indicator (RDR) and algorithms for selecting epsilon in differential privacy based on within-dataset individual risks, plus a multi-query leakage bound.

citing papers explorer

Showing 1 of 1 citing paper.

  • Within-Dataset Disclosure Risk for Differential Privacy cs.DB · 2023-10-19 · unverdicted · none · ref 35 · internal anchor

    Derives a relative disclosure risk indicator (RDR) and algorithms for selecting epsilon in differential privacy based on within-dataset individual risks, plus a multi-query leakage bound.