3 ms·
Sure. But to see it, we'll have to expand the example a little. Suppose you release the average salary for people that got an associates degree from the communi
by dbatten 6y ago
Sure. But to see it, we'll have to expand the example a little. Suppose you release the average salary for people that got an associates degree from the community college system - just a single number. Then you release that number broken down by campus. Then you release it for all campuses together, but broken down by subject area. Then you do it broken down by all campuses AND all subject areas. Then by all campuses, subject areas, and industry of employment. Etc. Ad nauseum.
Now suppose you had one person who got an associate's in art from campus X. You hide that value. But you now need to go searching across multiple dimensions to find "buddy cells" to suppress. You need to make sure that you suppress the value of associate's in art, but from a different campus. And you need to suppress the value of associate's from the same campus, but in a different subject. Otherwise, somebody can algebra-out the originally suppressed value. The more dimensions you have, the more you have to search across to hide data.
But here's where the optimization goal comes in - you don't like hiding data. You want to release as much data as possible. So you want to find a way to release the maximum amount of data while still protecting individual privacy.
The greedy approach is to go through every suppressed cell and make sure that it has a "buddy" cell across every possible dimension of aggregation. If it does NOT have a buddy cell, then select the cell in that dimension based on the smallest number of people, and suppress that one as well. But now you have to make sure that THAT cell is protected and can't be algebra'd-out, so you have to cycle through again. You keep doing this, always selecting the smallest possible buddy cells, until you have at least 2 cells suppressed across any dimension that can be aggregated.
Of course, if you really want to release as much data as possible, you can treat it as a binary integer programming problem where your goal is to minimize the sum of the N of data underlying suppressed cells and your decision variables are whether or not to suppress a given cell...
I hope that helps?
- troelsSteegin 6y agoThat was great, thank you for the detailed follow up.