Inference Control

Ross Anderson · 2020

Inference control goes back to the 1920s when economic data were compiled in ways that masked the contribution of individual firms, but it was first studied systematically in the context of census data. An advance in theory came in 2006, when Cynthia Dwork and colleagues developed the theory of differential privacy, which quantifies the extent to which inferences can be prevented by limiting queries and adding noise, enabling us to add noise where it's needed. Strategic mechanisms like differential privacy focus on keeping the anonymity set large enough, while many tactical mechanisms assess the risk that people with access to some application will overlap readers' privacy set. Dealing with database reconstruction piecemeal is hard; that's the value of differential privacy. The differential-privacy approach will protect everyone, while the old system only protected people who were swapped, and it has to be done all at once.

Read the paper · More papers on PaperTik