Privacy Specifications that do not Compose: Empirical and Formal Auditing of Sequentially Published Energy Data
This paper demonstrates that sequentially published energy data often fails to uphold privacy promises over time, as repeated annual releases allow for the inference of sensitive marginal group information through simple subtraction, necessitating a shift from auditing isolated files to evaluating the entire sequence using new metrics like "specification half-life."
Original paper licensed under CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/). This is an AI-generated explanation of the paper below. It is not written or endorsed by the authors. For technical accuracy, refer to the original paper. Read full disclaimer
Imagine a library that publishes a yearly report on how much electricity every neighborhood uses. To protect people's privacy, the library has a strict rule: "We will never write down numbers for a neighborhood unless at least five houses are in it." This is like saying, "We won't name a specific person; we'll only talk about a small group."
For years, the library has followed this rule perfectly. Every single year's report, looked at on its own, is safe. No one can tell who lives in which house just by reading that year's book.
The Problem: The "Math Magic" Trick
This paper argues that while each individual book is safe, the whole series of books is not. The authors discovered a "math magic" trick that anyone can use to break the privacy promise.
Here is the analogy:
Imagine you have two photos of a crowd taken one year apart.
- Photo A (Year 1): Shows a crowd of 100 people.
- Photo B (Year 2): Shows a crowd of 98 people.
If you look at Photo A alone, you see a big group. If you look at Photo B alone, you see a big group. Both are safe.
But, if you take Photo B and subtract Photo A from it (mathematically), you are left with a picture of exactly 2 people who left the crowd.
The paper found that energy publishers are doing exactly this. By taking the current year's data and subtracting last year's data, they accidentally reveal small groups of people (sometimes just 1 or 2 households) that the "five-house" rule was supposed to hide.
The "Half-Life" of Privacy
The authors came up with a new way to measure how long a privacy rule actually lasts. They call it the "Specification Half-Life."
Think of a privacy promise like a battery.
- When the library publishes the first year's report, the battery is 100% full. The promise is strong.
- After the second year, the battery drops a bit because the math trick becomes possible.
- After the third year, the battery is half-dead. The promise that "we protect everyone" is no longer true for most neighborhoods.
In the UK data they studied, the privacy promise "died" (became useless) after just three years. In the US data they compared it to, the promise lasted longer because the numbers were more stable, but it still wore down over time.
The "Formal" Detective Work
The authors didn't just guess this was happening; they used two types of detective work:
- The Empirical Detective (The Math): They actually did the subtraction on real data. They found that in 93% of the small areas they checked, they could spot a change of just 1 to 4 houses between years. This proved the "math magic" trick works in the real world.
- The Formal Detective (The Logic): They translated the library's written rules into a computer language (like a logic puzzle). They asked the computer: "Does your written rule actually stop this subtraction trick?" The computer said "No." It pointed out that the library's rule only checked one year at a time and forgot to check what happens when you stack the years together.
The Main Takeaway
The paper's big message is simple: Privacy rules don't work if you only check them one by one.
If you publish data every year, you have to check the entire stack of years, not just the new one. The authors suggest that publishers need a new rule: "Before we publish this year's data, we must check if subtracting it from last year's data reveals any small, secret groups."
They also found that for some datasets (like the UK's small neighborhoods), the numbers change so fast that the privacy rule breaks very quickly. For others (like big power companies), the numbers are stable, so the rule lasts longer. But in all cases, the "single-year" rule is a lie when you look at the whole series.
In short: You can't just lock the door for today and forget about yesterday. If you keep publishing the same kind of data, the "locks" eventually wear out, and the math can pick the lock.
Drowning in papers in your field?
Get daily digests of the most novel papers matching your research keywords — with technical summaries, in your language.