Privacy

What is Privacy?

Privacy as Secrecy
  • A secret that can only be viewed by us (It's either private or it's not)
    • Is privacy really about secrecy?
    • Are there other definitions of privacy that work better?
Privacy involves context
  • ex:
    • What is the data?
    • Who is it going to?
    • How did they receive it?
    • What are they going to do with it?
Privacy as Contextual Integrity
  • It acknowledges that data transmissions occur in society, so you can't have secrecy as your definition of privacy

    • Because data are going to be transmitted and it's a bit naive to just say secret, not secret and that's not really helpful in a society where data is transmitted all the time
  • It makes the observation that data transmissions occur within a life domain

  • Data transmissions are different for every domain and these differences have to be taken into account under contextual integrity

  • Data transmissions should be allowed/disallowed based on the CI-tuple (Contextual Integrity Tuple) and we have to apply some rules based on this

    • There's information about every data transmission

    • The CI-tuple consists of the

    • Actors = sender, receiver and the subject

    • Information Type (IT) = What type of information am I giving you? (ex: Medical records, etc.) and often times the information type is going to imply a domain (ex: The medical records imply that this information is in the medical domain.)

    • Transmission Principle (TP) = Other information about how the data is being transmitted that could be relevant to making an allow or disallow decision (ex: A medical record WITH consent)

    • CI-tuple = {actors, IT, TP}

    • Acceptability

    • After we collect the CI-tuple, we have to make a decision about the acceptability of the transmission of data

      • Who determines the acceptability of a CI-tuple?

      • The idea is that societal norms (Rules or expectations that exist in law or in expected social conduct, ex: HIPAA, COPA, etc.) will decide whether or not a CI-tuple is acceptable for transmission or not

        • Norms are like Mandatory Access Control

        • The person who defines acceptability rules is the subject of the data (Individual choice) is like Discretionary Access Control and if that's the case, we kind of move away from the theory of contextual integrity into the idea of privacy as data autonomy

        • ex: A person has the right to determine where their data goes, what is considered private with their data and what is considered a violation of privacy with their data, etc.

Privacy as Data Autonomy
  • A person has the right to determine where their data goes, what is considered private with their data and what is considered a violation of privacy with their data, etc.

  • This is a lot stronger because of the individual control but it also makes some things that we societally want to claim are not a violation of privacy as potentially being a violation of privacy

Differential Privacy (DP)

A system for publicly sharing information about a dataset by describing the patterns of groups within the dataset while withholding information about individuals in the dataset

We want the following criteria to be true:

  • Given two adjacent datasets, meaning they are differing in only one member:

    • We can't get the information about the one differing member in the two adjacent datasets by using Differential Privacy

    • We don't want an adversary to be able to determine about one specific person in the dataset using an adjacent dataset

    • So we're going to have each individual add noise to their response before it arrives in the database

    • Or we ourselves add noise to the dataset to obscure the actual answers and give a noisy answer that's close enough to the truth to still be useful but not so close that they can tell the difference between two adjacent datasets

    • Differential Privacy

    • Method of providing utility and privacy

    • Basic idea: Don't give the exact answer to queries (Close enough to the correct answer to not be useless), but noisy enough that you can't determine any information about one individual in two adjacent data sets

    • Differential Privacy is achieved if the output of a given dataset in S is less than or equal to E to the epsilon times the probability of A with D2 as an input being an S (INSERT FORMULA)

      • For low values of epsilon that are not 0, we say that it's going to be 1 + epsilon, where the epsilon here is a small number
    • Epsilon is our privacy loss parameter

      • Epsilon is tuned to a number that represents how much privacy loss we can tolerate before we say the attacker is getting too much information