Skip to main navigation Skip to search Skip to main content

Beyond Epsilon: A Principled QIF Framework for Local Differential Privacy

  • Ramon G. Gonze
  • , Natasha Fernandes
  • , Heber H. Arcolezi
  • , Catuscia Palamidessi
  • , Nataliia Bielova
  • Universidade Federal de Minas Gerais
  • Macquarie University
  • ÉTS Montréal
  • Institut Polytechnique de Paris
  • INRIA

Research output: Contribution to Book/Report typesContribution to conference proceedingspeer-review

Abstract

Local Differential Privacy (LDP) has become the de facto standard for privacy-preserving data collection in large-scale systems, in particular for the purpose of estimating frequencies. However, the current research landscape lacks a systematic and principled way to compare LDP protocols. The parameter varepsilon of LDP is considered the measure of privacy, but it only bounds worst-case distinguishability. Other comparisons rely on utility-driven analyses, where mechanisms are ranked based on their ability to preserve data utility for a given privacy budget varepsilon. Both such kinds of comparisons fail to account for the strength of protocols against diverse attacker models. In this paper, we propose a framework for analyzing LDP frequency estimation protocols through the lens of Quantitative Information Flow (QIF). By modeling LDP mechanisms as probabilistic channels, we leverage the concept of refinement (Blackwell ordering) to establish more principled classifications. This approach allows us to determine when one protocol is intrinsically superior to another for all possible adversaries, and to discuss the implications for utility. In particular, our analysis uncovers cases where protocols previously deemed 'optimal' are, in fact, incomparable with, or strictly dominated by, other protocols. We provide a formal QIF-based treatment of seven state-of-the-art LDP protocols, including Generalized Randomized Response (GRR), Subset Selection (SS), local hashing variants (BLH, OLH), unary encoding schemes (SUE, OUE), and Thresholding with Histogram Encoding (THE). This perspective bridges the gap between the LDP and formal methods communities and enables principled, adversary-aware reasoning about locally private systems.

Original languageEnglish
Title of host publicationProceedings - 2026 IEEE 39th Computer Security Foundations Symposium, CSF 2026
EditorsDeepak Garg, Dominique Unruh, Dominique Unruh
PublisherIEEE Computer Society
Pages483-496
Number of pages14
ISBN (Electronic)9798319518064
DOIs
Publication statusPublished - 2026
Externally publishedYes
Event39th IEEE Computer Security Foundations Symposium, CSF 2026 - Lisbon, Portugal
Duration: 26 Jul 202629 Jul 2026

Publication series

NameProceedings - IEEE Computer Security Foundations Symposium
ISSN (Print)1940-1434

Conference

Conference39th IEEE Computer Security Foundations Symposium, CSF 2026
Country/TerritoryPortugal
CityLisbon
Period26/07/2629/07/26

!!!Keywords

  • Channel Refinement
  • Information Leakage
  • Local Differential Privacy
  • Quantitative Information Flow

Fingerprint

Dive into the research topics of 'Beyond Epsilon: A Principled QIF Framework for Local Differential Privacy'. These topics are generated from the title and abstract of the publication. Together, they form a unique fingerprint.

Cite this