Casual Users and Rational Choices within Differential Privacy
Narges Ashena, Oana Inel, Badrie L. Persaud, Abraham Bernstein
IEEE Symposium on Security and Privacy 2024 · Day 1 · Continental Ballroom 6
Overview
This presentation, delivered by Narges Ashena, delves into the critical challenge of making Differential Privacy (DP) comprehensible and actionable for everyday users. Differential Privacy is a robust privacy framework designed to allow insights to be gained from datasets while rigorously protecting the privacy of individual data points. A core component of DP is the Epsilon (ε) parameter, which acts as a knob to calibrate the trade-off between privacy protection and the utility (accuracy) of the query results. Setting Epsilon is notoriously difficult, even for experts, and the talk highlights the significant gap between expert recommendations (typically ε < 1) and the wide range of values observed in real-world applications (0.1 to nearly 50).

Key moments
- 0:00 Introduction to Differential Privacy and Epsilon
- 2:00 Exploring user perceptions of DP and Epsilon
- 2:40 Designing interactive visualizations for DP parameters
- 5:30 Study design and participant engagement
- 6:10 User Epsilon choices and visualization effectiveness
- 7:50 Accuracy loss influences user Epsilon choices
- 8:00 Main takeaways and future research directions
Casual Users and Rational Choices within Differential Privacy
Speakers: Narges Ashena, PhD candidate at University of Zurich; Oana Inel; Badrie L. Persaud; Abraham Bernstein
Conference: IEEE S&P
YouTube: https://www.youtube.com/watch?v=VgwHJqYBk28
Overview
This presentation, delivered by Narges Ashena, delves into the critical challenge of making Differential Privacy (DP) comprehensible and actionable for everyday users. Differential Privacy is a robust privacy framework designed to allow insights to be gained from datasets while rigorously protecting the privacy of individual data points. A core component of DP is the Epsilon (ε) parameter, which acts as a knob to calibrate the trade-off between privacy protection and the utility (accuracy) of the query results. Setting Epsilon is notoriously difficult, even for experts, and the talk highlights the significant gap between expert recommendations (typically ε < 1) and the wide range of values observed in real-world applications (0.1 to nearly 50).
The study presented here aimed to bridge this gap by exploring effective methods for communicating DP and Epsilon to casual users – the ultimate data owners and subjects of privacy risks. Through a series of interactive visualizations tailored to a relatable scenario of COVID-19 case reporting in New York City, the researchers investigated users' perceptions and preferences regarding DP and their choices for Epsilon. The findings offer crucial insights into how data owners perceive privacy-accuracy trade-offs and the efficacy of different visualization techniques in guiding them towards more privacy-preserving choices.
This research is highly significant for the practical deployment of Differential Privacy. As DP gains traction across various industries and government initiatives, ensuring that individuals whose data is being protected can understand and influence the privacy settings is paramount. The study underscores the need for intuitive interfaces and effective communication strategies to empower users to make informed, rational choices about their data's privacy, ultimately fostering greater trust and adoption of DP technologies.
Background
▶ Watch: Introduction to Differential Privacy and Epsilon (0:00)
Differential Privacy (DP) has emerged as the gold standard for privacy-preserving data analysis, offering a rigorous mathematical guarantee that the presence or absence of any single individual's data in a dataset does not significantly alter the outcome of a query. This protection is achieved by adding carefully calibrated noise to the query results, making it difficult to infer individual attributes even if an adversary has access to all other information in the dataset. The core of this calibration lies in the Epsilon (ε) parameter.
Epsilon quantifies the level of privacy protection:
- A smaller Epsilon means more noise is added, leading to higher privacy protection but a greater loss of accuracy in the results.
- A larger Epsilon means less noise is added, resulting in lower privacy protection but more accurate results.
This inherent privacy-accuracy trade-off is central to DP, and the selection of an appropriate Epsilon value is critical yet challenging. DP experts generally recommend keeping Epsilon values small, ideally less than 1, with specific suggestions often ranging from 0.1 to 0.01, depending on the sensitivity of the data. For instance, Harvard's differentially private data sharing interface, "Side," recommends values like 0.25. However, real-world applications of DP exhibit a much broader spectrum of Epsilon values, from the recommended 0.1 all the way up to nearly 50. This discrepancy highlights a fundamental disconnect: while experts understand the theoretical implications of Epsilon, the practical implementation often deviates, potentially exposing individuals to greater privacy risks than intended or understood.
The problem this study addresses is the lack of understanding and agency among "casual users" or "data owners" regarding DP and Epsilon. These individuals are the direct subjects of privacy risks, yet they often lack the tools or information to make informed choices about how their data is protected. Prior work in DP has largely focused on algorithmic advancements and theoretical guarantees, with less emphasis on user-facing aspects and the cognitive burden of understanding complex privacy parameters. This study builds on the recognition that for DP to be truly effective and widely adopted, it must be interpretable and controllable by the individuals it aims to protect. The researchers hypothesized that interactive visualizations could serve as an effective means to bridge this knowledge gap, allowing users to directly observe the consequences of different Epsilon settings on both privacy and accuracy.
Key Findings
▶ Watch: Designing interactive visualizations for DP parameters (2:40)
The study yielded several significant findings regarding how casual users perceive and interact with Differential Privacy and the Epsilon parameter:
- General Preference for Smaller Epsilon Values: Approximately 75% of participants selected Epsilon values in the lower half of the provided slider range. This indicates a general inclination towards greater privacy protection when given the option, which is a positive sign for DP adoption.
- Epsilon Choices Above Expert Recommendations: Despite the preference for smaller values, the participants' selected Epsilons were generally above the values recommended by DP experts. For example, many choices were higher than the 0.25 recommended by platforms like Harvard's Side interface, suggesting that while users want privacy, their intuitive understanding of "enough" privacy might differ from expert consensus, or they may struggle to fully grasp the numerical implications.
- Visualizations Improve Epsilon Selection: A substantial majority – 8 out of 9 interactive visualizations – demonstrated an improvement over the baseline (no visualization) in leading participants to select smaller Epsilon values, or values closer to expert recommendations. This strongly supports the efficacy of visual aids in communicating DP concepts.
- Statistically Significant Impact of Specific Visualizations: Out of the nine visualizations, four conditions showed a statistically significant impact compared to the baseline, indicating that certain visual communication strategies are particularly effective in guiding user choices towards more privacy-preserving settings.
- Sensitivity to Accuracy Loss: Participants exhibited a clear sensitivity to the presented level of accuracy loss. When confronted with scenarios where the published data showed low accuracy, they were statistically significantly more likely to opt for bigger Epsilon values. This suggests that users are willing to "give up" some privacy if they perceive the resulting data to be too inaccurate or unusable, highlighting a critical aspect of the privacy-utility trade-off from a user's perspective.
- Plot Type Less Influential: Interestingly, running a similar analysis on the specific plot type (pip plot, line plot, or map plot) did not show a statistically significant impact on the selected Epsilon values by participants. This implies that the way accuracy or privacy loss is framed (e.g., the magnitude of accuracy loss) might be more influential than the specific graphical representation used.
These findings collectively emphasize that while casual users are generally privacy-conscious, their understanding of the nuanced privacy-accuracy trade-off is heavily influenced by how that trade-off is presented. Effective visualizations can guide users towards more privacy-preserving choices, but the perceived utility (accuracy) of the data remains a strong determinant of their final Epsilon selection.
Technical Deep Dive
▶ Watch: Study design and participant engagement (5:30)
The core of this study's technical contribution lies in its methodology for empirically investigating user perceptions of Differential Privacy and Epsilon. The researchers designed a subject study involving 426 participants, focusing on how different interactive visualizations influenced their choices.
At the heart of Differential Privacy is the mathematical guarantee achieved through the addition of random noise. The Epsilon (ε) parameter directly controls the magnitude of this noise: a smaller ε means more noise, hence stronger privacy but less accurate results, and vice versa. Experts typically recommend ε values below 1, ideally around 0.1 or 0.01, to ensure strong privacy guarantees. However, this numerical value is abstract for non-experts.
To make DP and Epsilon tangible, the researchers developed multiple interactive visualizations tailored to a realistic data sharing scenario: reporting COVID-19 positive cases in New York City. This context was chosen for its familiarity and direct relevance to public health data, making the privacy risks more concrete.
The visualizations were designed to illustrate two key aspects of the DP trade-off:
- Privacy Loss Visualization:
- This was primarily represented using a pip plot.
- The pip plot highlighted the probability of inferring an individual's COVID test result correctly from the published counts. This directly quantifies the privacy risk.
- Examples shown in the talk:
- For ε = 0.25, the inference probability was around 12%.
- For ε = 2.5, it increased significantly to about 71%.
- For a very high ε = 4.5, it reached almost 90%.
- This direct mapping of Epsilon to a tangible privacy risk (inference probability) aimed to make the concept more intuitive.
- Accuracy Loss Visualization:
- This was presented using a simple line plot and a heat map.
- The line plot displayed the original, true COVID counts (solid line) against the noisy, DP-protected counts (dotted lines). A shaded area highlighted the error bound introduced by DP for the selected Epsilon.
- A crucial observation here was that "although the noise bound remains constant for each Epsilon value, the error bound can look very different relative to the magnitude of the original counts." For instance, for the same Epsilon, the visual error might appear negligible when counts are scaled up 50 times, potentially misleading users about the true impact.
- The heat map of New York City provided a more contextual visualization. It showed "how DP changes the COVID counts" across different geographical areas as Epsilon values were adjusted. The map on the left remained static as a reference for comparing actual and noisy values, allowing participants to visually grasp the spatial impact of DP.
The researchers systematically combined these visualization components to create nine different conditions, plus one baseline:
- Trade-off Focus: Visualizations either focused on privacy loss, accuracy loss, or a full trade-off view (showing both simultaneously or allowing switching).
- Relative Accuracy Loss Levels: Two distinct levels were presented to participants – scenarios where the accuracy loss appeared low or high. This was crucial for testing the hypothesis that perceived accuracy impacts Epsilon choices.
- Plot Types: The pip plot, line plot, and map plot were used in various combinations.
The baseline condition involved only a slider for Epsilon adjustment with no visual aid, mimicking a common, abstract interface.
The study protocol involved:
- Introduction: Participants received a brief introduction to DP via a short video and explanatory text.
- Scenario: They were presented with the New York COVID-19 data sharing scenario.
- Random Assignment: Each participant was randomly assigned to one of the nine visualization conditions or the baseline.
- Interaction and Selection: Participants interacted with their assigned visualization, adjusting the Epsilon slider and observing the visual feedback, then selected an "appropriate value" for the scenario.
- Additional Data Collection: Researchers also collected data on participants' privacy preference scores and their comfort levels with different entities deploying DP.
This rigorous experimental design allowed the researchers to isolate the impact of different visualization strategies and accuracy presentations on user Epsilon choices, providing empirical evidence for effective DP communication.
Demo / Proof of Concept
▶ Watch: Accuracy loss influences user Epsilon choices (7:50)
While the talk itself didn't feature a live demonstration of the tools in action during the presentation, the core of the research involved participants interacting with a suite of interactive visualizations designed to convey the impact of Differential Privacy and the Epsilon parameter. These visualizations served as the "proof of concept" within the study, demonstrating how abstract DP concepts could be made tangible for casual users.
Participants in the study were able to:
- Adjust Epsilon: A slider allowed them to continuously modify the Epsilon value.
- Observe Privacy Impact: As Epsilon changed, the pip plot dynamically updated, showing the corresponding probability of inferring an individual's COVID test result. For example, moving the slider from a small Epsilon like 0.25 (12% inference probability) to a larger Epsilon like 4.5 (90% inference probability) would immediately illustrate the drastic reduction in privacy protection.
- Observe Accuracy Impact: Simultaneously, the line plot would update, showing the original counts versus the new noisy counts and the changing error bounds. Similarly, the heat map of New York City would visually transform, showing how the reported COVID counts across different boroughs were altered by the DP noise for the selected Epsilon. This provided an intuitive, geographical representation of accuracy loss.
The interactive nature of these tools allowed participants to directly experiment with the privacy-accuracy trade-off. They could see, for instance, that a very small Epsilon (high privacy) might make the COVID case counts appear highly erratic on the map, potentially reducing the utility of the data for public health analysis. Conversely, a very large Epsilon (low privacy) might show counts very close to the actual values, but at a significant individual privacy risk. This direct, cause-and-effect feedback loop was crucial for helping users form a more concrete understanding of DP beyond abstract definitions. The study's findings, particularly the improvement over the baseline, underscore the effectiveness of these interactive visualization "demos" in guiding user choices.
Defensive Implications
▶ Watch: Main takeaways and future research directions (8:00)
The findings of this study carry significant implications for both individuals whose data is subject to Differential Privacy and organizations deploying DP technologies.
For data owners and casual users:
- Empowerment through Understanding: The study reinforces the idea that understanding the implications of privacy parameters like Epsilon is crucial. Users should not blindly trust default settings but demand transparency and intuitive tools to make informed decisions about their privacy.
- Awareness of Accuracy Trade-offs: Users need to be aware that prioritizing high accuracy, especially when presented with scenarios of seemingly "low" accuracy data, can lead to inadvertently compromising their privacy. They should critically evaluate whether the marginal gain in accuracy is worth the corresponding reduction in privacy protection.
For organizations and data stewards deploying Differential Privacy:
- Prioritize User-Centric Design: Simply stating an Epsilon value is insufficient. Organizations must invest in user-centric interfaces that effectively communicate the privacy-accuracy trade-off. The study shows that interactive, visual explanations are far more effective than abstract numerical sliders or text descriptions alone.
- Focus on Privacy-Oriented Visualizations: The finding that privacy-focused visualizations are effective in leading users towards smaller Epsilons suggests that interfaces should prominently feature how Epsilon impacts individual privacy risk (e.g., inference probability) rather than just data utility.
- Contextualize Accuracy Loss Carefully: While users are sensitive to accuracy loss, the way it's presented matters. The observation that participants opted for larger Epsilons when presented with low accuracy scenarios is a critical warning. Organizations should avoid framing accuracy loss in a way that disproportionately scares users into sacrificing privacy. Instead, they should contextualize the utility of the noisy data for its intended purpose, even with higher noise. For instance, explaining that "this data is still useful for population trends, even if individual counts are less precise" could be more helpful than just showing a large error bar.
- Avoid Misleading Visual Scales: The point about error bounds looking different relative to the magnitude of original counts is important. Visualizations should be carefully designed to avoid understating the impact of noise when original counts are very high, as this could lead users to select higher Epsilon values than appropriate.
- Beyond Expert Recommendations: While expert recommendations for Epsilon are a good starting point, organizations should recognize that user perceptions and preferences can differ. A participatory design approach, where users are involved in setting or at least understanding Epsilon, could lead to more trusted and sustainable DP deployments.
- Continuous Research and Improvement: The need for exploring additional data sharing scenarios and visualizing more advanced DP concepts highlights that this is an ongoing challenge. Organizations should contribute to or leverage research in human-computer interaction for privacy to continually improve their DP interfaces.
In essence, the defensive implication is that for Differential Privacy to achieve its full potential and be widely accepted, it must move beyond being a purely technical construct to become a transparent, user-understandable, and user-controllable mechanism. This shift will build trust and ensure that DP genuinely protects individuals while delivering valuable insights.
Key Takeaways
- Privacy-focused visualizations are highly effective: Presenting the impact of Epsilon on individual privacy (e.g., inference probability) significantly helps users choose smaller, more privacy-preserving Epsilon values, aligning closer with expert recommendations.
- Users are sensitive to perceived accuracy loss: Participants are willing to sacrifice privacy for accuracy, particularly when presented with data that appears to have low utility due to noise. This highlights a critical tension in user decision-making.
- **The way trade-offs are presented matters more than plot type:** While visualizations generally improve Epsilon selection, the specific graphical representation (pip plot, line plot, map) had less impact than how accuracy loss was framed or the overall focus of the visualization.
- Expert recommendations are often exceeded by user choices: Despite a general desire for privacy, users often select Epsilon values higher than those recommended by DP experts, suggesting a gap in understanding the numerical implications of privacy guarantees.
- User education and intuitive interfaces are crucial: For Differential Privacy to be successfully adopted in real-world applications, it is essential to develop better, more intuitive ways to communicate its complex concepts and trade-offs to casual users.
- Further research is needed for diverse scenarios: The study suggests exploring different data sharing scenarios and advanced DP mechanisms to gain a more comprehensive understanding of user choices and perceptions.
About the Speaker(s)
The primary speaker for this presentation was Narges Ashena, who is a PhD candidate at the University of Zurich. She presented this work as part of her doctoral research.
The study was conducted as a joint effort with her colleagues, Oana Inel and Badrie L. Persaud, and her supervisor, Abraham Bernstein. While Narges Ashena delivered the talk, the research represents a collaborative endeavor from the University of Zurich, focusing on the intersection of human-computer interaction and privacy-preserving technologies like Differential Privacy.
Reviews
Dr. Zero (Offensive Security Researcher) — STRONG ACCEPT
This empirical study tackles a critical problem for Differential Privacy: making Epsilon understandable to casual users. The research rigorously demonstrates how interactive visualizations can guide users towards more privacy-preserving choices, despite their inherent sensitivity to perceived data accuracy.
Heather Calloway (CISO) — STRONG ACCEPT
This presentation offers critical insights for organizations deploying Differential Privacy, revealing how user interface design directly impacts the effectiveness of privacy guarantees. It’s a clear call to action for privacy engineering and product teams to prioritize user-centric communication of privacy-accuracy trade-offs, providing actionable guidance to build trust and ensure DP truly protects individuals as intended.
→ Top-rated talks at IEEE Symposium on Security and Privacy 2024