Abstract
Data analysis has high value both for commercial and research purposes. However, disclosing analysis results may pose severe privacy risk to individuals. Privug is a method to quantify privacy risks of data analytics programs by analyzing their source code. The method uses probability distributions to model attacker knowledge and Bayesian inference to update said knowledge based on observable outputs. Currently, Privug uses Markov Chain Monte Carlo (MCMC) to perform inference, which is a flexible but approximate solution. This paper presents an exact Bayesian inference engine based on multivariate Gaussian distributions to accurately and efficiently quantify privacy risks. The inference engine is implemented for a subset of Python programs that can be modeled as multivariate Gaussian models. We evaluate the method by analyzing privacy risks in programs to release public statistics. The evaluation shows that our method accurately and efficiently analyzes privacy risks, and outperforms existing methods. Furthermore, we demonstrate the use of our engine to analyze the effect of differential privacy in public statistics.
Originalsprog | Engelsk |
---|---|
Titel | Proceedings of Software Engineering and Formal Methods (SEFM'23) |
Antal sider | 18 |
Vol/bind | 14323 |
Forlag | Springer, Cham |
Publikationsdato | 31 okt. 2023 |
Sider | 263-281 |
ISBN (Trykt) | 978-3-031-47114-8 |
ISBN (Elektronisk) | 978-3-031-47115-5 |
DOI | |
Status | Udgivet - 31 okt. 2023 |
Begivenhed | 21st International Conference on Software Engineering and Formal Methods - Eindhoven, Holland Varighed: 6 nov. 2023 → 10 nov. 2023 https://sefm-conference.github.io/2023/ |
Konference
Konference | 21st International Conference on Software Engineering and Formal Methods |
---|---|
Land/Område | Holland |
By | Eindhoven |
Periode | 06/11/2023 → 10/11/2023 |
Internetadresse |
Navn | Lecture Notes in Computer Science |
---|---|
ISSN | 0302-9743 |
Emneord
- Data analysis
- Privacy risks
- Bayesian inference
- Markov Chain Monte Carlo
- Differential privacy