Generating privacy-preserving kernel density estimates
Privacy-preserving Kernel Density Estimations (KDEs) may be provided. A data set with data subject to privacy restrictions may be sampled to generate a set of linear measurements. An amount of noise may be added to the set of linear measurements to ensure privacy. Then when shared with a recipient, the noise-modified set of linear measurements can be used to generate privacy-preserving KDE values for features in the data set using a corresponding estimation function with the same values of parameters in the linear measurement function. Privacy-preserving KDE values may then be used to generate synthetic data sets that do not violate privacy restrictions on the source data set.
1 . A system, comprising:
at least one processor; and
a memory, storing program instructions that when executed by the at least one processor, cause the at least one processor to implement a data management system, configured to:
receive, via an interface of the data management system, a request to generate a privacy-preserving kernel density estimation (KDE) value for a feature in a data set, wherein the KDE value does not violate a privacy restriction enforced with respect to the data set and is less than a deviation value from a true KDE value for the feature in the dataset;
obtain a set of noise-modified linear measurements initially generated from a feature space that represents a plurality of items in the data set using one or more values as parameters for one or more variables of a linear measurement function, wherein respective amounts of noise are added to an initial set of linear measurements determined from the feature space for the plurality of items to generate the set of noise-modified linear measurements that satisfy the privacy restriction for the plurality of items in the data set, and wherein the one or more values were randomly selected before generating the set of noise-modified linear measurements;
respectively multiply a result of a corresponding estimation function paired with the linear measurement function and applied to the feature of the data set with individual ones of the set of noise-modified linear measurements, wherein the one or more values are used as estimation function variables to generate the result; and
provide, via the interface of the data management system, the privacy-preserving KDE value for the feature in the data set that does not violate the privacy restriction enforced with respect to the data set in response to the request, wherein the privacy-preserving KDE value is determined based on product values generated by the respective multiplication of the corresponding KDE estimation function with the individual ones of the set of noise-modified linear measurements.
2 . The system of claim 1 , wherein the data management system is further configured to:
receive, via the interface, a request to generate a synthetic data set that does not violate the privacy restriction enforced with respect to the data set;
sample a plurality of synthetic items to include in the synthetic data set from a plurality of privacy-preserving KDE values generated for features in the data set according to the set of noise-modified linear measurements multiplied with respective results of the corresponding estimation function for the features; and
store the synthetic data set including the plurality of synthetic items.
3 . The system of claim 1 , wherein the data management system is further configured to:
receive, via the interface, a search request for data sets according to one or more search criteria; and
provide, via the interface, a result of the search request according to the one or more search criteria including the data set.
4 . The system of claim 1 , wherein the data management system is further configured to provide to a remote computing system, a privacy-preserving KDE client application, wherein the privacy-preserving KDE client application is configured to:
randomly select the one or more values as the parameters for the one or more variables for the linear measurement function;
apply the linear measurement function using the selected one or more values to the data set to generate the initial set of linear measurements; and
apply, using a differential privacy technique, the respective amounts of noise to the initial set of linear measurements to generate the noise-modified set of linear measurements.
5 . The system of claim 1 , wherein the data management system is further configured to receive the set of noise-modified linear measurements and the one or more values as part of a request to make the data set available for privacy-preserving KDE generation.
6 . A method, comprising:
generating a privacy-preserving kernel density estimation (KDE) value for a feature in a data set, wherein the KDE value does not violate a privacy restriction enforced with respect to the data set and is less than a deviation value from a true KDE value for the feature in the data set, comprising:
identifying a set of noise-modified linear measurements generated from a feature space that represents a plurality of items in the data set using one or more values as parameters for one or more variables of a linear measurement function, wherein respective amounts of noise are added to an initial set of linear measurements determined from the feature space for the plurality of items to generate the set of noise-modified linear measurements that satisfy the privacy restriction for the plurality of items in the data set, and wherein the one or more values were randomly selected;
respectively multiplying a result of a corresponding estimation function paired with the linear measurement function and applied to the feature in the data set with individual ones of the set of noise-modified linear measurements, wherein the one or more values are used as estimation function variables to generate the result; and
providing the privacy-preserving KDE value for the feature in the data set determined based on product values generated by the respective multiplication of the corresponding estimation function with the individual ones of the set of noise-modified linear measurements.
7 . The method of claim 6 , wherein the generating the privacy-preserving KDE value for the feature in the data set is performed as part of generating respective privacy-preserving KDE values for a plurality of different features in the data set, and wherein the method further comprises:
generating a plurality of synthetic items to include in a synthetic data set, wherein the plurality of synthetic items are sampled from the plurality of privacy-preserving KDE values generated for the plurality of different features in the data set; and
storing the synthetic data set including the plurality of synthetic items.
8 . The method of claim 7 , further comprising receiving a request to generate the synthetic data set, wherein the request specifies storing the synthetic data set as a training data set in a data store accessible to a machine learning system.
9 . The method of claim 6 , further comprising receiving a request to generate the privacy-preserving KDE value for the feature in the data set and providing the privacy-preserving KDE value in response to the request.
10 . The method of claim 6 , further comprising:
receiving a search request for data sets according to one or more search criteria;
providing a result of the search request according to the one or more search criteria including the data set; and
receiving a selection of the data set for generating the privacy-preserving KDE value for the feature in the data set.
11 . The method of claim 6 , further comprising providing to a remote computing system, a privacy-preserving KDE client application, wherein the privacy-preserving KDE client application is configured to:
randomly select the one or more values as the parameters for the one or more variables for the linear measurement function;
apply the linear measurement function using the selected one or more values as to the data set to generate an initial set of linear measurements; and
apply, using a differential privacy technique, the respective amounts of noise to the initial set of linear measurements to generate the noise-modified set of linear measurements.
12 . The method of claim 11 , wherein the privacy-preserving KDE client application is configured to send the set of noise-modified linear measurements and the one or more values to a location requested using an interface of the privacy-preserving KDE client application.
13 . The method of claim 6 , wherein the linear measurement function and the corresponding estimation function of the KDE are based on different portions of a Random Fourier Features technique.
14 . The method of claim 6 , further comprising receiving the set of noise-modified linear measurements and the one or more values as part of a request to make the data set available for privacy-preserving KDE generation.
15 . One or more non-transitory, computer-readable storage media, storing program instructions that when executed on or across one or more computing devices cause the one or more computing devices to implement:
identifying a feature in a data set for generating a privacy-preserving kernel density estimation (KDE) value for the feature in the data set, wherein the KDE value does not violate a privacy restriction enforced with respect to the data set and is less than a deviation value from a true KDE value for the feature in the data set; and
generating the privacy-preserving KDE value for the feature in the data set, wherein, in generating the privacy-preserving KDE value, the program instructions cause the one or more computing devices to implement:
identifying a set of noise-modified linear measurements generated from a feature space that represents a plurality of items in the data set using one or more values as parameters for one or more variables of a linear measurement function, wherein respective amounts of noise are added to an initial set of linear measurements determined from the feature space for the plurality of items to generate the set of noise-modified linear measurements that satisfy the privacy restriction for the plurality of items in the data set, and wherein the one or more values were randomly selected;
respectively multiplying a result of a corresponding estimation function paired with the linear measurement function and applied to the feature in the data set with individual ones of the set of noise-modified linear measurements, wherein the one or more values are used as estimation function variables to generate the result; and
providing the privacy-preserving KDE value for the feature in the data set determined based on product values generated by the respective multiplication of the corresponding estimation function with the individual ones of the set of noise-modified linear measurements.
16 . The one or more non-transitory, computer-readable storage media of claim 15 , wherein the identifying the feature in the data set and the generating the privacy-preserving KDE value for the feature in the data set are performed as part of generating respective privacy-preserving KDE values for a plurality of different features, and wherein the one or more non-transitory, computer-readable storage media store further program instructions that when executed on or across the one or more computing devices, cause the one or more computing devices to further implement:
generating a plurality of synthetic items to include in a synthetic data set, wherein the plurality of synthetic items are sampled from the plurality of privacy-preserving KDE values generated for the plurality of different features; and
storing the synthetic data set including the plurality of synthetic items.
17 . The one or more non-transitory, computer-readable storage media of claim 15 , storing further program instructions that when executed on or across the one or more computing devices, cause the one or more computing devices to further implement receiving a request to generate the privacy-preserving KDE value for the feature in the data set and providing the privacy-preserving KDE value in response to the request.
18 . The one or more non-transitory, computer-readable storage media of claim 15 , wherein a distribution for the privacy-preserving KDE value is a Gaussian distribution.
19 . The one or more non-transitory, computer-readable storage media of claim 15 , wherein the linear measurement function and the corresponding estimation function of the KDE value are based on different portions of a Fast Gauss Transform technique.
20 . The one or more non-transitory, computer-readable storage media of claim 14 , storing further program instructions that when executed on or across the one or more computing devices, cause the one or more computing devices to further implement sending a request for the set of noise-modified linear measurements and the one or more values to a data management service, wherein the set of noise-modified linear measurements and the one or more values are received from data management service as a response to the request.