Does Differential Privacy Protect Terry Gross’ Privacy?
The concept of differential privacy was motivated through the example of Terry Gross’ height in Dwork (2006). In this paper, we show that when a procedure based on differential privacy is implemented, it neither protects Terry Gross’ privacy nor does it provide meaningful responses to queries. We also provide an additional illustration using income data from the US Census. These illustrations raise serious questions regarding the efficacy of using differential privacy based masking mechanism for numerical data.
KeywordsDifferential privacy Laplace noise addition Numerical data
Unable to display preview. Download preview PDF.
- 1.American Factfinder, U.S. Census Bureau, http://factfinder.census.gov/home/
- 2.Dalenius, T.: Towards a Methodology for Statistical Disclosure Control. Statistisktidskrift 5, 429–444 (1977)Google Scholar
- 4.Nissim, K., Raskhodnokova, S., Smith, A.: Smooth Sensitivity and Sampling in Private Data Analysis. In: Proceedings of the thirty-ninth annual ACM symposium on Theory of computing, pp. 75–84 (2007)Google Scholar
- 5.Story, L.: Top Hedge Fund Managers Do Well in a Down Year. New York Times, March 24 (2009), http://www.nytimes.com/2009/03/25/business/25hedge.html