11
3

Prior-itizing Privacy: A Bayesian Approach to Setting the Privacy Budget in Differential Privacy

Abstract

When releasing outputs from confidential data, agencies need to balance the analytical usefulness of the released data with the obligation to protect data subjects' confidentiality. For releases satisfying differential privacy, this balance is reflected by the privacy budget, ε\varepsilon. We provide a framework for setting ε\varepsilon based on its relationship with Bayesian posterior probabilities of disclosure. The agency responsible for the data release decides how much posterior risk it is willing to accept at various levels of prior risk, which implies a unique ε\varepsilon. Agencies can evaluate different risk profiles to determine one that leads to an acceptable trade-off in risk and utility.

View on arXiv
Comments on this paper