The paper aims to give an overview of various approaches to statistical\ndisclosure control based on random noise that are currently being discussed for\nofficial population statistics and censuses. A particular focus is on a\nstringent delineation between different concepts influencing the discussion: we\nseparate clearly between risk measures, noise distributions and output\nmechanisms - putting these concepts into scope and into relation with each\nother.\n After recapitulating differential privacy as a risk measure, the paper also\nremarks on utility and risk aspects of some specific output mechanisms and\nparameter setups, with special attention on static outputs that are rather\ntypical in official population statistics. In particular, it is argued that\nunbounded noise distributions, such as plain Laplace, may jeopardise key unique\ncensus features without a clear need from a risk perspective. On the other\nhand, bounded noise distributions, such as the truncated Laplace or the cell\nkey method, can be set up to keep unique census features while controlling\ndisclosure risks in census-like outputs.\n Finally, the paper analyses some typical attack scenarios to constrain\ngeneric noise parameter ranges that suggest a good risk/utility compromise for\nthe 2021 EU census output scenario. The analysis also shows that strictly\ndifferentially private mechanisms would be severely constrained in this\nscenario.\n
Paper
References (46)
Scroll for more · 34 remaining