pith. sign in

arxiv: 1708.07975 · v1 · pith:X3PMVUC2new · submitted 2017-08-26 · 💻 cs.CR · cs.DB· cs.LG· stat.ML

Plausible Deniability for Privacy-Preserving Data Synthesis

classification 💻 cs.CR cs.DBcs.LGstat.ML
keywords dataprivacydeniabilityplausiblereleasingbackgrounddatasetshand
0
0 comments X
read the original abstract

Releasing full data records is one of the most challenging problems in data privacy. On the one hand, many of the popular techniques such as data de-identification are problematic because of their dependence on the background knowledge of adversaries. On the other hand, rigorous methods such as the exponential mechanism for differential privacy are often computationally impractical to use for releasing high dimensional data or cannot preserve high utility of original data due to their extensive data perturbation. This paper presents a criterion called plausible deniability that provides a formal privacy guarantee, notably for releasing sensitive datasets: an output record can be released only if a certain amount of input records are indistinguishable, up to a privacy parameter. This notion does not depend on the background knowledge of an adversary. Also, it can efficiently be checked by privacy tests. We present mechanisms to generate synthetic datasets with similar statistical properties to the input data and the same format. We study this technique both theoretically and experimentally. A key theoretical result shows that, with proper randomization, the plausible deniability mechanism generates differentially private synthetic data. We demonstrate the efficiency of this generative technique on a large dataset; it is shown to preserve the utility of original data with respect to various statistical analysis and machine learning measures.

This paper has not been read by Pith yet.

discussion (0)

Sign in with ORCID, Apple, or X to comment. Anyone can read and Pith papers without signing in.

Forward citations

Cited by 1 Pith paper

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score.

  1. Differentially-Private Text Rewriting reshapes Linguistic Style

    cs.CL 2026-04 unverdicted novelty 6.0

    Differentially-private sentence-level text rewriting using language models causes systematic loss of interactive markers, contextual references, and complex subordination, homogenizing texts toward a non-involved and ...