You work at a hospital and want to publish the median salary of your staff so researchers can compare pay across institutions. Publishing the raw list is off the table â that would expose individual employees. Publishing just the median sounds safe. It is not.
Suppose the true median is $72,000. Now one employee changes jobs and her salary of $71,500 is replaced by an outside hire at $200,000. The median jumps to $73,000. An attacker who sees both published numbers can deduce that someone earning between $71,500 and $73,000 left the dataset. A single record leaves a fingerprint.
Differential privacy (DP) fixes this. Instead of the exact median, you release a slightly noisy version. The noise is calibrated so that whether or not any one person is in the dataset, the output looks almost the same â making it mathematically impossible to detect individuals. The formal guarantee, introduced by Cynthia Dwork and colleagues in 2006, is:
for any two datasets and that differ in exactly one record, and any measurable output set . The parameter ("epsilon") controls the privacyâaccuracy tradeoff: smaller means more privacy but a noisier answer.
Comments
Loading comments...