Priyanka Nanayakkara, Johes Bater, Xi He, Jessica Hullman, Jennie Rogers
Abstract
Organizations often collect private data and release aggregate statistics for the public's benefit. If no steps toward preserving privacy are taken, adversaries may use released statistics to deduce unauthorized information about the individuals described in the private dataset. Differentially private algorithms address this challenge by slightly perturbing underlying statistics with noise, thereby mathematically limiting the amount of information that may be deduced from each data release. Properly calibrating these algorithms -- and in turn the disclosure risk for people described in the dataset -- requires a data curator to choose a value for a privacy budget parameter, . However, there is little formal guidance for choosing , a task that requires reasoning about the probabilistic privacy-utility trade-off. Furthermore, choosing in the context of statistical inference requires reasoning about accuracy trade-offs in the presence of both measurement error and differential privacy (DP) noise. We present Visualizing Privacy (ViP), an interactive interface that visualizes relationships between , accuracy, and disclosure risk to support setting and splitting