Passer à la navigation principale Passer à la recherche Passer au contenu principal

Beyond Epsilon: A Principled QIF Framework for Local Differential Privacy

  • Ramon G. Gonze
  • , Natasha Fernandes
  • , Heber H. Arcolezi
  • , Catuscia Palamidessi
  • , Nataliia Bielova
  • Universidade Federal de Minas Gerais
  • Macquarie University
  • ÉTS Montréal
  • Institut Polytechnique de Paris
  • INRIA

Résultats de recherche: Chapitre dans un livre, rapport, actes de conférenceParticipation à un ouvrage collectif lié à un colloque ou une conférenceRevue par des pairs

Résumé

Local Differential Privacy (LDP) has become the de facto standard for privacy-preserving data collection in large-scale systems, in particular for the purpose of estimating frequencies. However, the current research landscape lacks a systematic and principled way to compare LDP protocols. The parameter varepsilon of LDP is considered the measure of privacy, but it only bounds worst-case distinguishability. Other comparisons rely on utility-driven analyses, where mechanisms are ranked based on their ability to preserve data utility for a given privacy budget varepsilon. Both such kinds of comparisons fail to account for the strength of protocols against diverse attacker models. In this paper, we propose a framework for analyzing LDP frequency estimation protocols through the lens of Quantitative Information Flow (QIF). By modeling LDP mechanisms as probabilistic channels, we leverage the concept of refinement (Blackwell ordering) to establish more principled classifications. This approach allows us to determine when one protocol is intrinsically superior to another for all possible adversaries, and to discuss the implications for utility. In particular, our analysis uncovers cases where protocols previously deemed 'optimal' are, in fact, incomparable with, or strictly dominated by, other protocols. We provide a formal QIF-based treatment of seven state-of-the-art LDP protocols, including Generalized Randomized Response (GRR), Subset Selection (SS), local hashing variants (BLH, OLH), unary encoding schemes (SUE, OUE), and Thresholding with Histogram Encoding (THE). This perspective bridges the gap between the LDP and formal methods communities and enables principled, adversary-aware reasoning about locally private systems.

langue originaleAnglais
titreProceedings - 2026 IEEE 39th Computer Security Foundations Symposium, CSF 2026
rédacteurs en chefDeepak Garg, Dominique Unruh, Dominique Unruh
EditeurIEEE Computer Society
Pages483-496
Nombre de pages14
ISBN (Electronique)9798319518064
Les DOIs
étatPublié - 2026
Modification externeOui
Evénement39th IEEE Computer Security Foundations Symposium, CSF 2026 - Lisbon, Portugal
Durée: 26 juil. 202629 juil. 2026

Série de publications

NomProceedings - IEEE Computer Security Foundations Symposium
ISSN (imprimé)1940-1434

Conférence

Conférence39th IEEE Computer Security Foundations Symposium, CSF 2026
Pays/TerritoirePortugal
La villeLisbon
période26/07/2629/07/26

Empreinte digitale

Voici les principaux termes ou expressions associés à « Beyond Epsilon: A Principled QIF Framework for Local Differential Privacy ». Ces libellés thématiques sont générés à partir du titre et du résumé de la publication. Ensemble, ils forment une empreinte digitale unique.

Citer cette ressource