IP Library Granted Patent US 8,375,030
Granted Patent B2
US 8,375,030 · App. 12/960,221 · Granted Feb 12, 2013

Differentially private aggregate classifier for multiple databases

Inventors: Shantanu Rane (Caambridge, MA); Manas A. Pathak (Pittsburgh, PA); Bhiksha Ramakrishnan (Pittsburgh, PA)
Assignee: Mitsubishi Electric Research Laboratories, Inc.
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,375,030
App. No.
12/960,221
Granted
Feb 12, 2013
Kind
B2
Abstract

Embodiments of the invention disclose a system and a method for determining a differentially private aggregate classifier for a set of databases, wherein each database in the set of databases is associated with a classifier and a noise value, wherein the classifier and the noise value are determined locally for each database, such that a combination of the classifier and the noise value ensure a differential data privacy of the database, and wherein the differentially private aggregate classifier preserves the differential data privacy of each database. The differentially private aggregate classifier is a combination of the classifiers of the set of databases modified with the noise value corresponding to a smallest database in the set of databases.

Claims (18)

1. A method for determining a differentially private aggregate classifier for a set of databases, wherein each database in the set of databases is associated with a classifier and a noise value, wherein the classifier and the noise value are determined locally for each database, such that a combination of the classifier and the noise value ensure a differential data privacy of the database, and wherein the differentially private aggregate classifier preserves the differential data privacy of each database, comprising the steps of:

combining classifiers to determine an aggregate classifier;

modifying the aggregate classifier with a noise value corresponding to a smallest database in the set of databases to produce the differentially private aggregate classifier;

determining an obfuscated index of the smallest database resulting from a permutation of indexes of the set of databases;

selecting obliviously, from additive shares of all noise values, a first additive share of the noise value associated with the smallest database based on the obfuscated index, wherein a second additive share of the noise value is stored in one or more databases; and

determining the differentially private aggregate classifier by obliviously combining each classifier, the first and the second additive shares of the noise value, wherein the steps of the method are performed by a processor.

2. The method of claim 1 , wherein the smallest database has a smallest number of entries, wherein data structures of the entries are identical for all databases.

3. The method of claim 1 , wherein the noise value is distributed according to a Laplace distribution.

4. The method of claim 1 , Wherein the noise value for each database is determined based on a size of the database.

5. The method of claim 1 wherein the classifier is a binary logistic regression classifier.

6. The method of claim 5 , wherein the classifier is a multiclass classifier constructed from a combination of binary logistic regression classifiers.

7. The method of claim 1 , wherein the determining of the differentially private classifier is performed by a. cryptographic protocol.

8. The method of claim 1 ., wherein the determining of the differentially private classifier is performed by a secret sharing protocol.

9. A system for determining a differentially private aggregate classifier for a set of databases, wherein each database in the set of databases is associated with a classifier and a noise value, wherein the classifier and the noise value are determined locally for each database, such that a combination of the classifier and the noise value ensure a differential data privacy of the database, and wherein the differentially private aggregate classifier preserves the differential data privacy of each database, comprising:

a processor for combining classifiers to determine an aggregate classifier and for modifying the aggregate classifier with a noise value corresponding to a smallest database in the set of databases to produce the differentially private aggregate classifier, wherein the processor is further configured for determining an obfuscated index of the smallest database resulting from a permutation of indexes of the set of databases; for selecting obliviously, from additive Shares of all noise values, a first additive share of the noise value associated with the smallest database based on the obfuscated index, wherein a second additive share of the noise value is stored in one or more databases; and for determining, the differentially private aggregate classifier by obliviously combining each classifier, the first and the second additive shares of the noise value.

10. The system of claim 9 , wherein the smallest database has a smallest number of entries, wherein data structures of the entries are identical for all databases.

11. The system of claim 9 , wherein the noise value is distributed according to a Laplace distribution.

12. The system of claim 9 , wherein the noise value for each database is determined based on a size of the database.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 15, 2011
From: RANE, SHANTANU; PATHAK, MANA A.; RAMAKRISHNAN, BHIKSHA
To: MITSUBISHI ELECTRIC RESEARCH LABORATORIES, INC.
Reel/Frame 026139/0777 →
Continuity (1)
Related Publication 20120143922A1 · Jun 7, 2012