Don't Look at the Data! How Differential Privacy Reconfigures the Practices of Data Science

AI Ethics, Fairness & AccountabilityAlgorithmic Transparency & AuditabilityPrivacy by Design & User ControlData Scientists & AnalystsAI/ML Researchers & EngineersPrivacy Policy Makers

Document Title

Don’t Look at the Data! How Differential Privacy Reconfigures the Practices of Data Science

Document Information

  • Subject Area: Conflict and integration between differential privacy and data science practices
  • Keywords: Differential privacy, data science, privacy protection, data availability, data analysis tools, data workflow, data ethics, data governance

Research Background and Issues

  • Identified Problems or Challenges:

    • The contradiction between privacy protection and openness requirements in data sharing.
    • The gap between the theory and practice of differential privacy (DP).
    • The impact of differential privacy on every stage of the data science workflow, and the obstacles faced by non-experts in using DP tools.
  • Significance:

    • Data managers in academia, government, and industry face dual pressures of releasing data while protecting privacy. Differential privacy is considered a potential solution to this dilemma, but its practical application still presents significant challenges.
    • Ensuring privacy protection for sensitive data while promoting open access to data is crucial for enhancing public trust and the reproducibility of scientific research.
  • Research Motivation and Related Work:

    • Differential privacy has been deployed on a large scale by organizations such as Google, Apple, and the U.S. Census Bureau, demonstrating its potential while exposing deployment difficulties.
    • Previous research has primarily focused on DP’s mathematical framework and technically prioritized design, with limited discussion on the needs of ordinary data practitioners.

Solution

  • Proposed Methods or Solutions:

    • Conduct user research using the differential privacy data analysis tool prototype “DP Creator” to explore the experiences of data custodians, analysts, and administrators when sharing or analyzing sensitive data.
    • Collect user feedback and analyze the utility and challenges of differential privacy within the data science workflow.
  • Innovations:

    • Integrating differential privacy theory with the practical needs of ordinary data practitioners to provide realistic references for tool design, education, and governance.
    • Differentiating role-specific needs (custodians vs analysts) and thoroughly dissecting the impact of differential privacy on each stage of the workflow.
  • Implementation Steps and Techniques:

    • Design a technical probe: DP Creator for practical data privacy analysis.
    • Recruit 19 non-DP experts, including researchers and data administrators, for interviews, using the tool to release noisy statistical data or explore sensitive databases.
    • Apply reflexive thematic analysis to process interview content.

Research Outcomes

  • Specific Findings:

    • Identified four major challenges in using differential privacy tools:
      1. Understanding the rationale and meaning of parameter settings.
      2. Difficulties in conducting analyses without access to raw data.
      3. Taking on new risks and responsibilities.
      4. Difficulty integrating DP tools into existing data workflows.
    • Analyzed the potential value of DP: particularly suitable for public access to sensitive data but limited in supporting exploratory analysis and reproducibility in scientific research.
    • Proposed solutions, such as incorporating more dataset annotations, expert consultation, contextualized education, and establishing privacy budget governance mechanisms.
  • Advantages Compared to Existing Solutions:

    • Greater emphasis on user experience and real-world data analysis scenarios.
    • Provides specific recommendations for improving the integration of differential privacy and data science, rather than being confined to theoretical discussions.
  • Experimental or Evaluation Results:

    • Users recognized the significant role of differential privacy in public data access but noted its poor performance in exploratory analysis and reproducibility in scientific research contexts.
    • The tool interface requires improvements in parameter explanation and user guidance, as DP Creator failed to fully align with existing data analysis workflows.
  • Limitations and Future Directions:

    • Limitations: Small sample size, only studied the DP Creator tool; did not test other differential privacy tools.
    • Future Research Directions:
      1. Enhance user education and training, developing more contextualized resources.
      2. Improve tool design, optimizing user experience and data context presentation features.
      3. Explore the impact of changes in data ethics and analysis models on scientific research.
      4. Deepen understanding of how privacy regulations influence the implementation and parameter settings of differential privacy.

The summary of the document highlights significant challenges posed by differential privacy to existing data science practices, with substantial potential for future improvements in tool design, educational resource development, and privacy governance frameworks.

Quick Actions

Share

Share this page

ios_share

https://hci.top/en/papers/chi/95932/2023

AdRecommended

Learn AI Coding at CodeNow

open_in_newOpen DOI Link
DOI: https://doi.org/10.1145/3544548.3580791
At a Glance

Paper Snapshot

fact_check
dataset
Source
CHI
calendar_month
Year
2023
emoji_events
Award
No award tagged
group
Authors
5 authors
sell
Subtopics
AI Ethics, Fairness & Accountability, Algorithmic Transparency & Auditability, Privacy by Design & User Control
work
Professions
Data Scientists & Analysts, AI/ML Researchers & Engineers, Privacy Policy Makers
article
Content Status
Full text indexed
hub
Related Papers
6 related papers