Cornell University
Library
Cornell UniversityLibrary

eCommons

Help
Log In(current)
DigitalCollections@ILR
ILR School
  1. Home
  2. ILR School
  3. Centers, Institutes, Programs
  4. Labor Dynamics Institute
  5. NSF Census Research Network
  6. Cornell University NCRN node
  7. Utility Cost of Formal Privacy for Releasing National Employer-Employee Statistics

Utility Cost of Formal Privacy for Releasing National Employer-Employee Statistics

File(s)
Utility_Cost_of_Formal_Privacy.pdf (2.29 MB)
Permanent Link(s)
https://hdl.handle.net/1813/49652
Collections
Cornell University NCRN node
Sloan Foundation: The Economics of Socially-Efficient Privacy and Confidentiality Management for Statistical Agencies
Author
Haney, Samuel
Machanavajjhala, Ashwin
Abowd, John M.
Graham, Matthew
Kutzbach, Mark
Vilhuber, Lars
Abstract

National statistical agencies around the world publish tabular summaries based on combined employeremployee (ER-EE) data. The privacy of both individuals and business establishments that feature in these data are protected by law in most countries. These data are currently released using a variety of statistical disclosure limitation (SDL) techniques that do not reveal the exact characteristics of particular employers and employees, but lack provable privacy guarantees limiting inferential disclosures. In this work, we present novel algorithms for releasing tabular summaries of linked ER-EE data with formal, provable guarantees of privacy. We show that state-of-the-art differentially private algorithms add too much noise for the output to be useful. Instead, we identify the privacy requirements mandated by current interpretations of the relevant laws, and formalize them using the Pufferfish framework. We then develop new privacy definitions that are customized to ER-EE data and satisfy the statutory privacy requirements. We implement the experiments in this paper on production data gathered by the U.S. Census Bureau. An empirical evaluation of utility for these data shows that for reasonable values of the privacy-loss parameter ϵ≥1, the additive error introduced by our provably private algorithms is comparable, and in some cases better, than the error introduced by existing SDL techniques that have no provable privacy guarantees. For some complex queries currently published, however, our algorithms do not have utility comparable to the existing traditional

Sponsorship
Authors acknowledge support from NSF grants 1253327, 1408982, 1443014, BCS-0941226, TC-1012593 and SES-1131848, DARPA & SPAWAR N66001-15-C-4067, and Alfred P. Sloan Foundation.
Date Issued
2017-05-14
Related Version
Published as Samuel Haney , Ashwin Machanavajjhala , John M. Abowd , Matthew Graham , Mark Kutzbach , Lars Vilhuber (2017) "Utility Cost of Formal Privacy for Releasing National Employer-Employee Statistics", SIGMOD’17, May 14-19, 2017, Chicago, Illinois, USA.
Related To
http://doi.org/10.1145/3035918.3035940
Type
article

Site Statistics | Help

About eCommons | Policies | Terms of use | Contact Us

copyright © 2002-2026 Cornell University Library | Privacy | Web Accessibility Assistance