Retention-Replacement Probability Generation for Differential Privacy

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing data protection techniques apply uniform retention probabilities, potentially leading to unnecessary protection processing depending on the source database.

Innovation Solution

A retention-replacement probability generation device that includes a global optimal solution determining unit, a region generating unit, and an in-region optimal solution generating unit, which determines and generates optimal retention-replacement probabilities to achieve suitable perturbation while ensuring ε-differential privacy.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of manufacture

If uniform retention probability is applied to all attribute values, then privacy protection is simplified and easier to implement, but unnecessary protection processing may be applied reducing data utility

Engineering Contradiction:
Improveease of implementationVSAvoiddata utility
Core Design Contradiction:
Ease of manufactureVSLoss of information

Solution Approach 1:

The patent applies different retention probabilities to different attribute values based on their specific characteristics and sensitivity. Instead of using a uniform retention probability for all attribute values, the system calculates and applies customized retention probabilities tailored to each attribute value's privacy risk profile and importance, thereby avoiding unnecessary protection processing while maintaining adequate privacy safeguards.

Inventive Principle:
Principle #3Local quality

2Reliability

If retention-replacement perturbation is applied to protect privacy, then individual data privacy is preserved, but analysis precision may be degraded due to data distortion

Engineering Contradiction:
Improveprivacy protectionVSAvoidanalysis precision
Core Design Contradiction:
ReliabilityVSMeasurement precision

Solution Approach 1:

The patent dynamically adjusts retention probabilities as key parameters to optimize the balance between privacy protection and analysis precision. By calculating retention probabilities based on attribute value characteristics, sensitivity levels, and query workloads, the system adapts the perturbation intensity to minimize data distortion while maintaining privacy guarantees through mathematical bounds on information loss.

Inventive Principle:
Principle #35Parameter changes

3Loss of information

If high retention probability is used to preserve data utility, then analysis precision is improved, but privacy protection effectiveness is reduced

Engineering Contradiction:
Improvedata utilityVSAvoidprivacy risk
Core Design Contradiction:
Loss of informationVSObject-affected harmful factors

Solution Approach 1:

The patent applies differentiated retention probabilities where high-risk attribute values receive higher replacement probabilities (lower retention) and low-risk attribute values receive lower replacement probabilities (higher retention). This localized approach to probability assignment ensures that privacy protection is strengthened where needed while preserving data utility where the risk is minimal, thereby resolving the contradiction between privacy protection and data utility.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS12242627B2Retention-replacement probability generation device, retention-replacement perturbation device, retention-replacement probability generation method, retention-replacement perturbation method, and program
Publication Date: 2025.03.04 NIPPON TELEGRAPH & TELEPHONE CORP
  • US12242627B2 patent drawing
  • US12242627B2 patent drawing
  • US12242627B2 patent drawing

AI summary

Provided is a retention-replacement probability generation device that is capable of generating retention-replacement probability that realizes retention-replacement perturbation of a suitable level. Included are: a global optimal solution determining unit that, outputs a global optimal solution in a case where a global optimal solution exists that is a replacement probability of the attribute values in which the transition matrix P and histogram vector expression v of the attribute values yield ∥Pv−v∥=0; a region generating unit that, in a case where the global optimal solution does not exist, generates a region that is defined by an inequality equivalent to conditions for both replacement probabilities corresponding to i'th and j'th attribute values satisfying ε-differential privacy, and an inequality equivalent to conditions for the replacement probability of one and the retention probability of the other corresponding to the i'th and the j'th attribute values satisfying ε-differential privacy.