We consider a platform's problem of collecting data from privacy sensitive users to estimate an underlying parameter of interest. We formulate this question as a Bayesian-optimal mechanism design problem, in which an individual can share her (verifiable) data in exchange for a monetary reward or services, but at the same time has a (private) heterogeneous privacy cost which we quantify using differential privacy. We consider two popular differential privacy settings for providing privacy guarantees for the users: central and local. In both settings, we establish minimax lower bounds for the estimation error and derive (near) optimal estimators for given heterogeneous privacy loss levels for users. Building on this characterization, we pose the mechanism design problem as the optimal selection of an estimator and payments that will elicit truthful reporting of users' privacy sensitivities. Under a regularity condition on the distribution of privacy sensitivities we develop efficient algorithmic mechanisms to solve this problem in both privacy settings. Our mechanism in the central setting can be implemented in time $\mathcal{O}(n \log n)$ where $n$ is the number of users and our mechanism in the local setting admits a Polynomial Time Approximation Scheme (PTAS).
翻译:我们考虑一个平台从隐私敏感用户处收集数据以估计潜在感兴趣参数的问题。我们将此问题形式化为贝叶斯最优机制设计问题,其中个体可共享其(可验证的)数据以换取货币奖励或服务,但同时具备(私有的)异质性隐私成本,我们使用差分隐私对此进行量化。我们考虑了两种主流的用于为用户提供隐私保证的差分隐私设置:集中式与本地化。在这两种设置中,我们建立了估计误差的极小化下界,并针对用户给定的异质性隐私损失水平推导出(接近)最优的估计器。基于这一刻画,我们将机制设计问题表述为最优选择估计器与支付方案,以激励用户如实报告其隐私敏感度。在隐私敏感度分布满足正则性条件的前提下,我们开发了高效算法机制以在两种隐私设置下求解该问题。在集中式设置下,我们的机制可在 $\mathcal{O}(n \log n)$ 时间内实现,其中 $n$ 为用户数量;在本地化设置下,我们的机制容许一个多项式时间近似方案(PTAS)。