Taking online decisions is a part of everyday life. Think of buying a house, parking a car or taking part in an auction. We often take those decisions publicly, which may breach our privacy - a party observing our choices may learn a lot about our preferences. In this paper we investigate the online stopping algorithms from the privacy preserving perspective, using a mathematically rigorous differential privacy notion. In differentially private algorithms there is usually an issue of balancing the privacy and utility. In this regime, in most cases, having both optimality and high level of privacy at the same time is impossible. We propose a natural mechanism to achieve a controllable trade-off, quantified by a parameter, between the accuracy of the online algorithm and its privacy. Depending on the parameter, our mechanism can be optimal with weaker differential privacy or suboptimal, yet more privacy-preserving. We conduct a detailed accuracy and privacy analysis of our mechanism applied to the optimal algorithm for the classical secretary problem. Thereby the classical notions from two distinct areas - optimal stopping and differential privacy - meet for the first time.
翻译:在线决策是日常生活的一部分。想想买房、停车或参与拍卖。我们往往公开做出这些决策,这可能会侵犯我们的隐私——观察我们选择的第三方可能了解大量关于我们偏好的信息。本文从隐私保护的角度研究在线停止算法,采用数学上严谨的差分隐私概念。在差分隐私算法中,通常存在隐私与效用之间的平衡问题。在此框架下,大多数情况下同时实现最优性和高隐私保护水平是不可能的。我们提出了一种自然机制,通过参数控制在线算法的准确度与其隐私之间的可调节权衡。根据参数的不同,我们的机制可以在较弱差分隐私下达到最优,或牺牲最优性而实现更强的隐私保护。我们将该机制应用于经典秘书问题的最优算法,并对其准确度和隐私性能进行详细分析。由此,两个不同领域的经典概念——最优停止与差分隐私——首次实现了交汇。