论文标题
网络改组:通过随机步行进行隐私放大
Network Shuffling: Privacy Amplification via Random Walks
论文作者
论文摘要
最近,据表明,改组可以扩增与局部差异隐私随机数据的中央差分隐私保证。在此设置中,一个集中的,值得信赖的改组者通过保持数据匿名的身份来负责改组,这随后可为系统提供更强的隐私保证。但是,将一个集中式实体引入最初的本地隐私模型失去了一些吸引力,因为没有像当地差异隐私一样拥有任何集中实体。此外,由于已知的安全问题和/或安全的计算技术的要求,以可靠的方式实施洗牌者并不是微不足道的。 在这些实际考虑的过程中,我们重新考虑了洗牌模型,以放松需要一个集中的,值得信赖的洗牌者的假设。我们介绍了网络改组,这是一种分散的机制,用户在网络/图形上以随机步行方式交换数据,以替代通过匿名来实现隐私放大的方法。我们在这种设置下分析了威胁模型,并提出了网络改组的分布式协议,这些协议在实践中很容易实施。此外,我们表明隐私放大率类似于其他隐私放大技术,例如统一的改组。据我们所知,在最近研究的中间信任模型中,利用隐私放大技术的中间信任模型,我们的工作是第一个不依靠任何集中式实体来实现隐私放大的工作。
Recently, it is shown that shuffling can amplify the central differential privacy guarantees of data randomized with local differential privacy. Within this setup, a centralized, trusted shuffler is responsible for shuffling by keeping the identities of data anonymous, which subsequently leads to stronger privacy guarantees for systems. However, introducing a centralized entity to the originally local privacy model loses some appeals of not having any centralized entity as in local differential privacy. Moreover, implementing a shuffler in a reliable way is not trivial due to known security issues and/or requirements of advanced hardware or secure computation technology. Motivated by these practical considerations, we rethink the shuffle model to relax the assumption of requiring a centralized, trusted shuffler. We introduce network shuffling, a decentralized mechanism where users exchange data in a random-walk fashion on a network/graph, as an alternative of achieving privacy amplification via anonymity. We analyze the threat model under such a setting, and propose distributed protocols of network shuffling that is straightforward to implement in practice. Furthermore, we show that the privacy amplification rate is similar to other privacy amplification techniques such as uniform shuffling. To our best knowledge, among the recently studied intermediate trust models that leverage privacy amplification techniques, our work is the first that is not relying on any centralized entity to achieve privacy amplification.