Differential Privacy Guarantees in Small Area Estimation

📅 2026-09-08
📈 Citations: 0
Influential: 0
📄 PDF
🤖 AI Summary
本文探讨了在小区域估计中如何保证差分隐私,通过使用贝叶斯Fay-Herriot模型的后验分布抽样,并分析了该方法在不同隐私定义下的有效性。
📝 Abstract
Statistical agencies increasingly rely on small area estimation to produce reliable estimates for subpopulations with limited sample sizes. These estimates are built from individual survey responses, so agencies must ensure that releasing them does not reveal information about any single respondent. We show that when a single draw from the posterior distribution of the Bayesian Fay-Herriot model is released, pure $\varepsilon$-differential privacy is unattainable, but the release satisfies formal privacy guarantees under Rényi differential privacy and zero-concentrated differential privacy without any noise being added, provided we treat the variance components as fixed. The key insight is that the posterior draw equals the posterior mean plus the Gaussian noise whose variance equals the posterior variance. The guarantee is thus governed by the sensitivity of the direct survey estimate and the posterior variance, and applies equally to a release of the posterior mean with that amount of noise added. For binary outcomes estimated with the Hájek estimator, the sensitivity equals the largest survey weight in the area divided by the sum of the weights. For the intercept-only model we derive exact coefficients describing how a change in one record propagates to every area's posterior mean, giving finite-sample per-area guarantees and a joint guarantee for releasing all areas at once that exceeds the largest per-area guarantee by at most a few percent in our applications. Two applications, poverty prevalence across 2,462 Public Use Microdata Areas in the American Community Survey and smoking prevalence across 52 substrata in the Washington state Behavioral Risk Factor Surveillance System, show that the guarantee is driven far more by the inequality of the survey weights than by the sample size, and that the shrinkage of the model tightens it substantially.
Problem

Research questions and friction points this paper is trying to address.

Differential Privacy
Small Area Estimation
Bayesian Fay-Herriot Model
Innovation

Methods, ideas, or system contributions that make the work stand out.

Rényi differential privacy
zero-concentrated differential privacy
Bayesian Fay-Herriot model
posterior distribution
sensitivity
🔎 Similar Papers
No similar papers found.
S
Soumojit Das
Washington State University, Pullman, WA, USA.
J
Jörg Drechsler
Institute for Employment Research, Germany.