General Inferential Limits Under Differential and Pufferfish Privacy
Abstract
Differential privacy (DP) is a class of mathematical standards for assessing the privacy provided by a data-release mechanism. This work concerns two important flavors of DP that are related yet conceptually distinct: pure -differential privacy (-DP) and Pufferfish privacy. We restate -DP and Pufferfish privacy as Lipschitz continuity conditions and provide their formulations in terms of an object from the imprecise probability literature: the interval of measures. We use these formulations to derive limits on key quantities in frequentist hypothesis testing and in Bayesian inference using data that are sanitised according to either of these two privacy standards. Under very mild conditions, the results in this work are valid for arbitrary parameters, priors and data generating models. These bounds are weaker than those attainable when analysing specific data generating models or data-release mechanisms. However, they provide generally applicable limits on the ability to learn from differentially private data - even when the analyst's knowledge of the model or mechanism is limited. They also shed light on the semantic interpretations of the two DP flavors under examination, a subject of contention in the current literature.
Cite
@article{arxiv.2401.15491,
title = {General Inferential Limits Under Differential and Pufferfish Privacy},
author = {James Bailie and Ruobin Gong},
journal= {arXiv preprint arXiv:2401.15491},
year = {2024}
}
Comments
This is an extended version of the conference paper [9]. Along with some lesser additions, Sections 7 and 8 on Pufferfish privacy are new; and Lemma 57, Theorem 9 (these two results correspond to Theorem 9 in [9]), Theorem 11 (Theorem 8 in [9]) and Theorem 14 (Theorem 10 in [9]) all contain minor corrections