This paper proposes concentrated geo-privacy (CGP), a privacy notion that can be considered as the counterpart of concentrated differential privacy (CDP) for geometric data. Compared with the previous notion of geo-privacy [ABCP13, CABP13], which is the counterpart of standard differential privacy, CGP offers many benefits including simplicity of the mechanism, lower noise scale in high dimensions, and better composability known as advanced composition. The last one is the most important, as it allows us to design complex mechanisms using smaller building blocks while achieving better utilities. To complement this result, we show that the previous notion of geo-privacy inherently does not admit advanced composition even using its approximate version. Next, we study three problems on private geometric data: the identity query, k nearest neighbors, and convex hulls. While the first problem has been previously studied, we give the first mechanisms for the latter two under geo-privacy. For all three problems, composability is essential in obtaining good utility guarantees on the privatized query answer.
翻译:本文提出集中地理隐私(CGP),一种可视为几何数据对应集中差分隐私(CDP)的隐私概念。相较于先前作为标准差分隐私对应物的地理隐私概念[ABCP13, CABP13],CGP具有多项优势,包括机制简洁性、高维度下更低的噪声尺度以及更优的组合性(即高级组合)。其中后者最为重要,因为它允许我们通过更小的构建模块设计复杂机制,同时获得更优的效用。为补充这一结论,我们证明了先前的地理隐私概念本质上不支持高级组合,即便采用其近似版本。接下来,我们研究了私有几何数据的三个问题:身份查询、k近邻和凸包。尽管第一个问题已有研究,我们首次给出了后两者在地理隐私下的机制。对于所有三个问题,组合性对于在私有化查询答案上获得良好效用保证至关重要。