Skip to Main content Skip to Navigation
Journal articles

Refinement Orders for Quantitative Information Flow and Differential Privacy

Abstract : Quantitative Information Flow (QIF) and Differential Privacy (DP) are both concerned with the protection of sensitive information, but they are rather different approaches. In particular, QIF considers the expected probability of a successful attack, while DP (in both its standard and local versions) is a max-case measure, in the sense that it is compromised by the existence of a possible attack, regardless of its probability. Comparing systems is a fundamental task in these areas: one wishes to guarantee that replacing a system A by a system B is a safe operation that is the privacy of B is no worse than that of A. In QIF, a refinement order provides strong such guarantees, while, in DP, mechanisms are typically compared w.r.t. the privacy parameter ε in their definition. In this paper, we explore a variety of refinement orders, inspired by the one of QIF, providing precise guarantees for max-case leakage. We study simple structural ways of characterising them, the relation between them, efficient methods for verifying them and their lattice properties. Moreover, we apply these orders in the task of comparing DP mechanisms, raising the question of whether the order based on ε provides strong privacy guarantees. We show that, while it is often the case for mechanisms of the same "family" (geometric, randomised response, etc.), it rarely holds across different families.
Document type :
Journal articles
Complete list of metadata
Contributor : Catuscia Palamidessi Connect in order to contact the contributor
Submitted on : Thursday, December 31, 2020 - 4:04:58 PM
Last modification on : Saturday, May 1, 2021 - 3:39:37 AM
Long-term archiving on: : Thursday, April 1, 2021 - 6:52:24 PM


jcp-01-00004 (1).pdf
Publisher files allowed on an open archive



Konstantinos Chatzikokolakis, Natasha Fernandes, Catuscia Palamidessi. Refinement Orders for Quantitative Information Flow and Differential Privacy. Journal of Cybersecurity and Privacy, MDPI, 2020, 1, pp.40 - 77. ⟨10.3390/jcp1010004⟩. ⟨hal-03091754⟩



Les métriques sont temporairement indisponibles