Privacy
What is Privacy?
Privacy as Secrecy
- A secret that can only be viewed by us (It's either private or it's not)
- Is privacy really about secrecy?
- Are there other definitions of privacy that work better?
Privacy involves context
- ex:
- What is the data?
- Who is it going to?
- How did they receive it?
- What are they going to do with it?
Privacy as Contextual Integrity
It acknowledges that data transmissions occur in society, so you can't have secrecy as your definition of privacy
- Because data are going to be transmitted and it's a bit naive to just say secret, not secret and that's not really helpful in a society where data is transmitted all the time
It makes the observation that data transmissions occur within a life domain
Data transmissions are different for every domain and these differences have to be taken into account under contextual integrity
Data transmissions should be allowed/disallowed based on the CI-tuple (Contextual Integrity Tuple) and we have to apply some rules based on this
There's information about every data transmission
The CI-tuple consists of the
Actors = sender, receiver and the subject
Information Type (IT) = What type of information am I giving you? (ex: Medical records, etc.) and often times the information type is going to imply a domain (ex: The medical records imply that this information is in the medical domain.)
Transmission Principle (TP) = Other information about how the data is being transmitted that could be relevant to making an allow or disallow decision (ex: A medical record WITH consent)
CI-tuple = {actors, IT, TP}
Acceptability
After we collect the CI-tuple, we have to make a decision about the acceptability of the transmission of data
Who determines the acceptability of a CI-tuple?
The idea is that societal norms (Rules or expectations that exist in law or in expected social conduct, ex: HIPAA, COPA, etc.) will decide whether or not a CI-tuple is acceptable for transmission or not
Norms are like Mandatory Access Control
The person who defines acceptability rules is the subject of the data (Individual choice) is like Discretionary Access Control and if that's the case, we kind of move away from the theory of contextual integrity into the idea of privacy as data autonomy
ex: A person has the right to determine where their data goes, what is considered private with their data and what is considered a violation of privacy with their data, etc.
Privacy as Data Autonomy
A person has the right to determine where their data goes, what is considered private with their data and what is considered a violation of privacy with their data, etc.
This is a lot stronger because of the individual control but it also makes some things that we societally want to claim are not a violation of privacy as potentially being a violation of privacy
Differential Privacy (DP)
A system for publicly sharing information about a dataset by describing the patterns of groups within the dataset while withholding information about individuals in the dataset
We want the following criteria to be true:
Given two adjacent datasets, meaning they are differing in only one member:
We can't get the information about the one differing member in the two adjacent datasets by using Differential Privacy
We don't want an adversary to be able to determine about one specific person in the dataset using an adjacent dataset
So we're going to have each individual add noise to their response before it arrives in the database
Or we ourselves add noise to the dataset to obscure the actual answers and give a noisy answer that's close enough to the truth to still be useful but not so close that they can tell the difference between two adjacent datasets
Differential Privacy
Method of providing utility and privacy
Basic idea: Don't give the exact answer to queries (Close enough to the correct answer to not be useless), but noisy enough that you can't determine any information about one individual in two adjacent data sets
Differential Privacy is achieved if the output of a given dataset in S is less than or equal to E to the epsilon times the probability of A with D2 as an input being an S (INSERT FORMULA)
- For low values of epsilon that are not 0, we say that it's going to be 1 + epsilon, where the epsilon here is a small number
Epsilon is our privacy loss parameter
- Epsilon is tuned to a number that represents how much privacy loss we can tolerate before we say the attacker is getting too much information