Protecting individual privacy in public use summary tables, created by statistical agencies is a critical task. This is obvious, based on the amount of resources currently being spent by U. S. Census for this task. Back in 1990s I developed a concept of synthetic tabular data to achieve that objective. In the initial Microsoft 2006 paper on differential privacy of data summarized in contingency tables, Microsoft cites my work and states "Our approach can be viewed as a special case of a more general approach for producing synthetic data".
When I first saw that paper, I contacted Microsoft authors of the paper and asked them to demonstrate the merits of their work by using real life data I used in my 2004 paper "Maximum Utility-Minimum Information Loss Table Server Design for Statistical Disclosure Control of Tabular Data", Ramesh A. Dandekar, June 9-11, 2004, Barcelona, Spain. In that paper I used Current Population Survey (CPS) file from UC Irvine available in the public domain as a practical example for real life application of the method.
After 13 years of research on the differential privacy, I have not seen a practical example that demonstrates the merits of using differential privacy on tabular data. I would like to encourage DP researchers to use public domain microdata such as CPS file, to evaluate the relative merits of their research papers.
To benefit future research on this topic, I have uploaded on Research gate website, a pdf file containing 55 pages of information pertaining to my work in 2004 paper along with a copy of my email to Microsoft authors June 2007 (and a copy of Microsoft 2006 paper for easy access). The file also contains 2D and 3D summary statistics of CTA protected CPS data, relative to original CPS data on pages from 39 to 55.
I Hope you will all find this information useful in your future research activities on the topic.
Ramesh A. Dandekar
Retired
------------------------------
Ramesh Dandekar
Math Stat, Retired
------------------------------
Original Message:
Sent: 03-12-2019 12:58
From: Ramesh Dandekar
Subject: new Census Bureau privacy policy
Counter example for logic used to protect census 2020 data by Differential Privacy Mechanism
Before I begin, let me ask you one question. What is more important a) preserving individual privacy or b) preserving individual human life? Of course preserving individual human life is far more important than preserving individual privacy.
Now let us apply the "zero risk" reasoning used to protect individual privacy in census 2020 data; to the decision to preserve individual life from events such as a) tornados b) flooding c) potential nuclear attack.
To protect individual human life from events such as these, the ultimate (almost) zero risk solution is to force individuals to live in harden concrete bunkers (to protect from extreme tornados and potential nuclear attack) constructed 100 feet above ground level (to protect from extreme flooding).
I am sure none of you will agree with me on above proposed solution to the perceived threats to individual human life. The reason for that is I have failed to take in to considerations aspects such as a) probabilities of occurrence of events and b) total cost of implementation of proposed solutions along with degradation of quality of human life.
Current proposed method to protect individual privacy in 2020 census fails to consider probability of occurrence of extreme attacks and cost benefit analysis of using extreme solution typical of differential privacy mechanism. Instead, new laws and or regulations should be used to protect from perceived threat to individual privacy.
Ramesh A Dandekar
Retired
------------------------------
Ramesh Dandekar
Math Stat - Retired
------------------------------
Original Message:
Sent: 12-07-2018 07:33
From: Andrew Beveridge
Subject: new Census Bureau privacy policy
Here is a link to an excellent analysis of this policy by those around IPUMS (full disclosure, I have collaborated with them, and with John Abowd who is the main advocate. It could make the 2020 Census and the American Community Survey virtually useless for many analyses.
https://assets.ipums.org/_files/mpc/MPC-Working-Paper-2018-6.pdf
Implications of Differential Privacy for Census Bureau Data and Research Task Force on Differential Privacy for Census Data
Institute for Social Research and Data Innovation (ISRDI) University of Minnesota
The Census Bureau has announced a new set of standards and methods for disclosure control in public use data products. The new approach, known as differential privacy, represents a radical departure from current practice. In its pure form, differential privacy techniques may make the release of useful microdata impossible and severely limit the utility of tabular small-area data. Adoption of differential privacy will have far-reaching consequences for research. It is possible-even likely-that scientists, planners, and the public will lose the free access we have enjoyed for six decades to reliable public Census Bureau data describing American social and economic change. We believe that the differential privacy approach is inconsistent with the statutory obligations, history, and core mission of the Census Bureau.
------------------------------
Andrew Beveridge
Professor of Sociology
Queens and Grad Center CUNY