Please use this identifier to cite or link to this item:
Title: Individual differential privacy: A utility-preserving formulation of differential privacy guarantees
Author: Soria Comas, Jordi
Domingo-Ferrer, Josep  
Sánchez Ruenes, David
Megias, David  
Others: Universitat Oberta de Catalunya. Internet Interdisciplinary Institute (IN3)
Universitat Rovira i Virgili (URV)
Citation: Soria-Comas, J., Domingo Ferrer, J., Sánchez Ruenes, D. & Megías, D. (2017). Individual Differential Privacy: A Utility-Preserving Formulation of Differential Privacy Guarantees. IEEE Transactions on Information Forensics and Security, 12(6), 1418-1429. doi: 10.1109/TIFS.2017.2663337
Abstract: Differential privacy is a popular privacy model within the research community because of the strong privacy guarantee it offers, namely that the presence or absence of any individual in a data set does not significantly influence the results of analyses on the data set. However, enforcing this strict guarantee in practice significantly distorts data and/or limits data uses, thus diminishing the analytical utility of the differentially private results. In an attempt to address this shortcoming, several relaxations of differential privacy have been proposed that trade off privacy guarantees for improved data utility. In this paper, we argue that the standard formalization of differential privacy is stricter than required by the intuitive privacy guarantee it seeks. In particular, the standard formalization requires indistinguishability of results between any pair of neighbor data sets, while indistinguishability between the actual data set and its neighbor data sets should be enough. This limits the data controller's ability to adjust the level of protection to the actual data, hence resulting in significant accuracy loss. In this respect, we propose individual differential privacy, an alternative differential privacy notion that offers the same privacy guarantees as standard differential privacy to individuals (even though not to groups of individuals). This new notion allows the data controller to adjust the distortion to the actual data set, which results in less distortion and more analytical accuracy. We propose several mechanisms to attain individual differential privacy and we compare the new notion against standard differential privacy in terms of the accuracy of the analytical results.
Keywords: data privacy
data utility
differential privacy
DOI: 10.1109/TIFS.2017.2663337
Document type: info:eu-repo/semantics/article
Version: info:eu-repo/semantics/acceptedVersion
Issue Date: 13-Jul-2016
Publication license:  
Appears in Collections:Articles cientÍfics

Files in This Item:
File Description SizeFormat 
postprint-IDP-TIFS.pdf1,97 MBAdobe PDFThumbnail