arXiv:2511.06305cs.CRcs.LG2025-11NeurIPS被引 1

别因难懂隐私预算就放弃差分隐私,它仍是安全的金标准。

Setting $\varepsilon$ is not the Issue in Differential Privacy

  • 指出隐私预算难理解是普遍风险评估难题,非差分隐私独有
  • 强调现有研究下任何可靠隐私评估方法都应可纳入差分隐私框架
  • 适合关注数据安全与合规的技术决策者阅读

本文主张,将隐私预算设定视为差分隐私的主要局限,是对该技术的误解。所谓隐私预算难以解释的问题,常被用来否定差分隐私在真实场景中的应用,并推广其他替代保护方法。我们认为这误导了决策者选择不安全方案。隐私预算的解读困难并非源于差分隐私定义本身,而是源于隐私风险在具体情境中评估的固有挑战——这一挑战对任何严谨的隐私风险评估方法都存在。此外,我们认为,基于当前研究水平,任何可靠的隐私风险评估方法都应在差分隐私框架内表达,或明确说明为何无法实现。

原文摘要 · Abstract (English)

This position paper argues that setting the privacy budget in differential privacy should not be viewed as an important limitation of differential privacy compared to alternative methods for privacy-preserving machine learning. The so-called problem of interpreting the privacy budget is often presented as a major hindrance to the wider adoption of differential privacy in real-world deployments and is sometimes used to promote alternative mitigation techniques for data protection. We believe this misleads decision-makers into choosing unsafe methods. We argue that the difficulty in interpreting privacy budgets does not stem from the definition of differential privacy itself, but from the intrinsic difficulty of estimating privacy risks in context, a challenge that any rigorous method for privacy risk assessment face. Moreover, we claim that any sound method for estimating privacy risks should, given the current state of research, be expressible within the differential privacy framework or justify why it cannot.

差分隐私隐私评估安全决策

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。