English

Setting the Privacy Budget in Differential Privacy by Bounding Adversaries' Odds of Learning Sensitive Information

Methodology 2026-07-04 v1

Abstract

Differential privacy is a mathematical definition of what it means to protect data subjects' privacy in data releases. Differential privacy depends on a parameter ϵ\epsilon known as the privacy budget. The value of ε\varepsilon determines the nature of the privacy guarantee, with smaller values generally offering more privacy. However, reducing ε\varepsilon also tends to decrease the accuracy of results protected with differentially private algorithms. Setting a value for ε\varepsilon that satisfactorily balances this risk/accuracy trade off is complicated in practice, and there is not a standard approach to doing so. In part this is because practitioners may struggle to understand the privacy guarantee afforded by ε\varepsilon. We present an approach to interpreting and setting ε\varepsilon in which (i) the practitioner establishes bounds on the posterior odds that adversaries can learn sensitive information, and (ii) the practitioner converts these bounds to values of ε\varepsilon. We illustrate the approach using data from a case control study.

Keywords

Cite

@article{arxiv.2607.04004,
  title  = {Setting the Privacy Budget in Differential Privacy by Bounding Adversaries' Odds of Learning Sensitive Information},
  author = {Ruwimal Y. Pathiraja and Jerome P. Reiter},
  journal= {arXiv preprint arXiv:2607.04004},
  year   = {2026}
}