TY - GEN
T1 - Beyond Epsilon
T2 - 39th IEEE Computer Security Foundations Symposium, CSF 2026
AU - Gonze, Ramon G.
AU - Fernandes, Natasha
AU - Arcolezi, Heber H.
AU - Palamidessi, Catuscia
AU - Bielova, Nataliia
N1 - Publisher Copyright:
© 2026 IEEE.
PY - 2026
Y1 - 2026
N2 - Local Differential Privacy (LDP) has become the de facto standard for privacy-preserving data collection in large-scale systems, in particular for the purpose of estimating frequencies. However, the current research landscape lacks a systematic and principled way to compare LDP protocols. The parameter varepsilon of LDP is considered the measure of privacy, but it only bounds worst-case distinguishability. Other comparisons rely on utility-driven analyses, where mechanisms are ranked based on their ability to preserve data utility for a given privacy budget varepsilon. Both such kinds of comparisons fail to account for the strength of protocols against diverse attacker models. In this paper, we propose a framework for analyzing LDP frequency estimation protocols through the lens of Quantitative Information Flow (QIF). By modeling LDP mechanisms as probabilistic channels, we leverage the concept of refinement (Blackwell ordering) to establish more principled classifications. This approach allows us to determine when one protocol is intrinsically superior to another for all possible adversaries, and to discuss the implications for utility. In particular, our analysis uncovers cases where protocols previously deemed 'optimal' are, in fact, incomparable with, or strictly dominated by, other protocols. We provide a formal QIF-based treatment of seven state-of-the-art LDP protocols, including Generalized Randomized Response (GRR), Subset Selection (SS), local hashing variants (BLH, OLH), unary encoding schemes (SUE, OUE), and Thresholding with Histogram Encoding (THE). This perspective bridges the gap between the LDP and formal methods communities and enables principled, adversary-aware reasoning about locally private systems.
AB - Local Differential Privacy (LDP) has become the de facto standard for privacy-preserving data collection in large-scale systems, in particular for the purpose of estimating frequencies. However, the current research landscape lacks a systematic and principled way to compare LDP protocols. The parameter varepsilon of LDP is considered the measure of privacy, but it only bounds worst-case distinguishability. Other comparisons rely on utility-driven analyses, where mechanisms are ranked based on their ability to preserve data utility for a given privacy budget varepsilon. Both such kinds of comparisons fail to account for the strength of protocols against diverse attacker models. In this paper, we propose a framework for analyzing LDP frequency estimation protocols through the lens of Quantitative Information Flow (QIF). By modeling LDP mechanisms as probabilistic channels, we leverage the concept of refinement (Blackwell ordering) to establish more principled classifications. This approach allows us to determine when one protocol is intrinsically superior to another for all possible adversaries, and to discuss the implications for utility. In particular, our analysis uncovers cases where protocols previously deemed 'optimal' are, in fact, incomparable with, or strictly dominated by, other protocols. We provide a formal QIF-based treatment of seven state-of-the-art LDP protocols, including Generalized Randomized Response (GRR), Subset Selection (SS), local hashing variants (BLH, OLH), unary encoding schemes (SUE, OUE), and Thresholding with Histogram Encoding (THE). This perspective bridges the gap between the LDP and formal methods communities and enables principled, adversary-aware reasoning about locally private systems.
KW - Channel Refinement
KW - Information Leakage
KW - Local Differential Privacy
KW - Quantitative Information Flow
UR - https://www.scopus.com/pages/publications/105049412315
U2 - 10.1109/CSF68417.2026.00032
DO - 10.1109/CSF68417.2026.00032
M3 - Contribution to conference proceedings
AN - SCOPUS:105049412315
T3 - Proceedings - IEEE Computer Security Foundations Symposium
SP - 483
EP - 496
BT - Proceedings - 2026 IEEE 39th Computer Security Foundations Symposium, CSF 2026
A2 - Garg, Deepak
A2 - Unruh, Dominique
A2 - Unruh, Dominique
PB - IEEE Computer Society
Y2 - 26 July 2026 through 29 July 2026
ER -