{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,1]],"date-time":"2026-07-01T07:54:11Z","timestamp":1782892451285,"version":"3.54.5"},"reference-count":56,"publisher":"Association for Computing Machinery (ACM)","issue":"1","license":[{"start":{"date-parts":[[2014,1,1]],"date-time":"2014-01-01T00:00:00Z","timestamp":1388534400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"DOI":"10.13039\/100000001","name":"National Science Foundation","doi-asserted-by":"publisher","award":["1054389 and 1253327"],"award-info":[{"award-number":["1054389 and 1253327"]}],"id":[{"id":"10.13039\/100000001","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/100006785","name":"Google","doi-asserted-by":"publisher","id":[{"id":"10.13039\/100006785","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["ACM Trans. Database Syst."],"published-print":{"date-parts":[[2014,1]]},"abstract":"<jats:p>In this article, we introduce a new and general privacy framework called Pufferfish. The Pufferfish framework can be used to create new privacy definitions that are customized to the needs of a given application. The goal of Pufferfish is to allow experts in an application domain, who frequently do not have expertise in privacy, to develop rigorous privacy definitions for their data sharing needs. In addition to this, the Pufferfish framework can also be used to study existing privacy definitions.<\/jats:p>\n          <jats:p>We illustrate the benefits with several applications of this privacy framework: we use it to analyze differential privacy and formalize a connection to attackers who believe that the data records are independent; we use it to create a privacy definition called hedging privacy, which can be used to rule out attackers whose prior beliefs are inconsistent with the data; we use the framework to define and study the notion of composition in a broader context than before; we show how to apply the framework to protect unbounded continuous attributes and aggregate information; and we show how to use the framework to rigorously account for prior data releases.<\/jats:p>","DOI":"10.1145\/2514689","type":"journal-article","created":{"date-parts":[[2014,2,4]],"date-time":"2014-02-04T14:16:21Z","timestamp":1391523381000},"page":"1-36","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":214,"title":["Pufferfish"],"prefix":"10.1145","volume":"39","author":[{"given":"Daniel","family":"Kifer","sequence":"first","affiliation":[{"name":"Penn State University, University Park, PA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Ashwin","family":"Machanavajjhala","sequence":"additional","affiliation":[{"name":"Duke University, Durham, NC"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2014,1,6]]},"reference":[{"key":"e_1_2_2_1_1","doi-asserted-by":"publisher","DOI":"10.1145\/76894.76895"},{"key":"e_1_2_2_2_1","doi-asserted-by":"publisher","DOI":"10.1145\/1150402.1150460"},{"key":"e_1_2_2_3_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-25385-0_12"},{"key":"e_1_2_2_4_1","doi-asserted-by":"publisher","DOI":"10.1145\/1374376.1374464"},{"key":"e_1_2_2_5_1","doi-asserted-by":"publisher","DOI":"10.1198\/000313004X1189"},{"key":"e_1_2_2_6_1","volume-title":"Proceedings of the 37th International Colloguium on Automata, Languages and Programming (ICALP). Lecture Notes in Computer Science","volume":"6199","author":"Chan H.","unstructured":"H. Chan , E. Shi , and D. Song . 2010. Private and continual release of statistics . In Proceedings of the 37th International Colloguium on Automata, Languages and Programming (ICALP). Lecture Notes in Computer Science , vol. 6199 , Springer-Verlag, Berlin, 405--417. H. Chan, E. Shi, and D. Song. 2010. Private and continual release of statistics. In Proceedings of the 37th International Colloguium on Automata, Languages and Programming (ICALP). Lecture Notes in Computer Science, vol. 6199, Springer-Verlag, Berlin, 405--417."},{"key":"e_1_2_2_7_1","doi-asserted-by":"publisher","DOI":"10.1007\/11818175_12"},{"key":"e_1_2_2_8_1","doi-asserted-by":"publisher","DOI":"10.1561\/1900000008"},{"key":"e_1_2_2_9_1","doi-asserted-by":"publisher","DOI":"10.5555\/371090.371092"},{"key":"e_1_2_2_10_1","volume-title":"Proceedings of the NSF Workshop on Next Generation Data Mining.","author":"Clifton C.","unstructured":"C. Clifton , M. Kantarcioglu , and J. Vaidya . 2002. Defining privacy for data mining . In Proceedings of the NSF Workshop on Next Generation Data Mining. C. Clifton, M. Kantarcioglu, and J. Vaidya. 2002. Defining privacy for data mining. In Proceedings of the NSF Workshop on Next Generation Data Mining."},{"key":"e_1_2_2_11_1","volume-title":"Proceedings of the ACM SIGMOD Workshop on Data Mining and Knowledge Discovery. ACM","author":"Clifton Chris","year":"1996","unstructured":"Chris Clifton and Don Marks . 1996 . Security and privacy implications of data mining . In Proceedings of the ACM SIGMOD Workshop on Data Mining and Knowledge Discovery. ACM , New York, NY. Chris Clifton and Don Marks. 1996. Security and privacy implications of data mining. In Proceedings of the ACM SIGMOD Workshop on Data Mining and Knowledge Discovery. ACM, New York, NY."},{"key":"e_1_2_2_12_1","doi-asserted-by":"publisher","DOI":"10.1145\/1774088.1774216"},{"key":"e_1_2_2_13_1","doi-asserted-by":"publisher","DOI":"10.1145\/773153.773173"},{"key":"e_1_2_2_14_1","doi-asserted-by":"publisher","DOI":"10.1145\/1645953.1646160"},{"key":"e_1_2_2_15_1","doi-asserted-by":"publisher","DOI":"10.1007\/11787006_1"},{"key":"e_1_2_2_16_1","series-title":"Lecture Notes in Computer Science","volume-title":"Proceedings of the 5th International Conference on Theory and Applications of Mode Computation (TAMC)","author":"Dwork Cynthia","unstructured":"Cynthia Dwork . 2008. Differential privacy: A survey of results . In Proceedings of the 5th International Conference on Theory and Applications of Mode Computation (TAMC) . Lecture Notes in Computer Science , vol. 4978 , Springer-Verlag , Berlin , 1--9. Cynthia Dwork. 2008. Differential privacy: A survey of results. In Proceedings of the 5th International Conference on Theory and Applications of Mode Computation (TAMC). Lecture Notes in Computer Science, vol. 4978, Springer-Verlag, Berlin, 1--9."},{"key":"e_1_2_2_17_1","doi-asserted-by":"publisher","DOI":"10.1007\/11761679_29"},{"key":"e_1_2_2_18_1","doi-asserted-by":"publisher","DOI":"10.1007\/11681878_14"},{"key":"e_1_2_2_19_1","doi-asserted-by":"publisher","DOI":"10.1145\/1250790.1250804"},{"key":"e_1_2_2_20_1","doi-asserted-by":"publisher","DOI":"10.29012\/jpc.v2i1.585"},{"key":"e_1_2_2_21_1","doi-asserted-by":"publisher","DOI":"10.1145\/1806689.1806787"},{"key":"e_1_2_2_22_1","volume-title":"Proceedings of the 1st Symposium on Innovations in Computer Science (ICS).","author":"Dwork C.","unstructured":"C. Dwork , M. Naor , T. Pitassi , G. N. Rothblum , and S. Yekhanin . 2010b. Pan-private streaming algorithms . In Proceedings of the 1st Symposium on Innovations in Computer Science (ICS). C. Dwork, M. Naor, T. Pitassi, G. N. Rothblum, and S. Yekhanin. 2010b. Pan-private streaming algorithms. In Proceedings of the 1st Symposium on Innovations in Computer Science (ICS)."},{"key":"e_1_2_2_23_1","volume-title":"Confidentiality and disclosure limitation methodology: Challenges for national statistics and statistical research. Tech. rep. 668","author":"Fienberg Stephen E.","unstructured":"Stephen E. Fienberg . 1997. Confidentiality and disclosure limitation methodology: Challenges for national statistics and statistical research. Tech. rep. 668 , Carnegie Mellon University . Stephen E. Fienberg. 1997. Confidentiality and disclosure limitation methodology: Challenges for national statistics and statistical research. Tech. rep. 668, Carnegie Mellon University."},{"key":"e_1_2_2_24_1","doi-asserted-by":"publisher","DOI":"10.1145\/1749603.1749605"},{"key":"e_1_2_2_25_1","doi-asserted-by":"publisher","DOI":"10.1145\/1401890.1401926"},{"key":"e_1_2_2_26_1","series-title":"Lecture Notes in Computer Science","volume-title":"Proceedings of the 32nd Annual Cryptology Conference on Advances in Cryptology (CRYPTO)","author":"Gehrke Johannes","unstructured":"Johannes Gehrke , Michael Hay , Edward Lui , and Rafael Pass . 2012. Crowd-blending privacy . In Proceedings of the 32nd Annual Cryptology Conference on Advances in Cryptology (CRYPTO) . Lecture Notes in Computer Science , vol. 7417 , Springer-Verlag , Berlin , 479--496. Johannes Gehrke, Michael Hay, Edward Lui, and Rafael Pass. 2012. Crowd-blending privacy. In Proceedings of the 32nd Annual Cryptology Conference on Advances in Cryptology (CRYPTO). Lecture Notes in Computer Science, vol. 7417, Springer-Verlag, Berlin, 479--496."},{"key":"e_1_2_2_27_1","series-title":"Lecture Notes in Computer Science","volume-title":"Proceedings of the 8th Theory of Cryptology Conference (TCC)","author":"Gehrke Johannes","unstructured":"Johannes Gehrke , Edward Lui , and Rafael Pass . 2011. Towards privacy for social networks: A zero-knowledge based definition of privacy . In Proceedings of the 8th Theory of Cryptology Conference (TCC) . Lecture Notes in Computer Science , vol. 6597 , Springer-Verlag , Berlin , 432--449. Johannes Gehrke, Edward Lui, and Rafael Pass. 2011. Towards privacy for social networks: A zero-knowledge based definition of privacy. In Proceedings of the 8th Theory of Cryptology Conference (TCC). Lecture Notes in Computer Science, vol. 6597, Springer-Verlag, Berlin, 432--449."},{"key":"e_1_2_2_28_1","doi-asserted-by":"publisher","DOI":"10.1145\/1536414.1536464"},{"key":"e_1_2_2_29_1","first-page":"2","article-title":"Random differential privacy","volume":"4","author":"Hall Robert","year":"2012","unstructured":"Robert Hall , Larry Wasserman , and Alessandro Rinaldo . 2012 . Random differential privacy . J. Privacy Confidentiality 4 , 2 . Robert Hall, Larry Wasserman, and Alessandro Rinaldo. 2012. Random differential privacy. J. Privacy Confidentiality 4, 2.","journal-title":"J. Privacy Confidentiality"},{"key":"e_1_2_2_30_1","doi-asserted-by":"publisher","DOI":"10.1371\/journal.pgen.1000167"},{"key":"e_1_2_2_31_1","unstructured":"Shiva Prasad Kasiviswanathan and Adam Smith. 2008. A note on differential privacy: Defining resistance to arbitrary side information. http:\/\/arxiv.org\/abs\/0803.3946.  Shiva Prasad Kasiviswanathan and Adam Smith. 2008. A note on differential privacy: Defining resistance to arbitrary side information. http:\/\/arxiv.org\/abs\/0803.3946."},{"key":"e_1_2_2_32_1","doi-asserted-by":"publisher","DOI":"10.1145\/1559845.1559861"},{"key":"e_1_2_2_33_1","doi-asserted-by":"publisher","DOI":"10.1145\/1807085.1807106"},{"key":"e_1_2_2_34_1","doi-asserted-by":"publisher","DOI":"10.29012\/jpc.v4i1.610"},{"key":"e_1_2_2_35_1","doi-asserted-by":"publisher","DOI":"10.1145\/1989323.1989345"},{"key":"e_1_2_2_36_1","doi-asserted-by":"publisher","DOI":"10.1145\/2213556.2213571"},{"key":"e_1_2_2_37_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICDE.2006.101"},{"key":"e_1_2_2_38_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICDE.2008.4497436"},{"key":"e_1_2_2_39_1","doi-asserted-by":"publisher","DOI":"10.14778\/1988776.1988780"},{"key":"e_1_2_2_40_1","doi-asserted-by":"publisher","DOI":"10.1145\/1559845.1559850"},{"key":"e_1_2_2_41_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-03356-8_8"},{"key":"e_1_2_2_42_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.datak.2007.06.012"},{"key":"e_1_2_2_43_1","volume-title":"Proceedings of the 17th Australasian Database Conference (ADC).49--58","author":"Natwichai Juggapong","unstructured":"Juggapong Natwichai , Xue Li , and Maria E. Orlowska . 2006. A reconstruction-based algorithm for classification rules hiding . In Proceedings of the 17th Australasian Database Conference (ADC).49--58 Juggapong Natwichai, Xue Li, and Maria E. Orlowska. 2006. A reconstruction-based algorithm for classification rules hiding. In Proceedings of the 17th Australasian Database Conference (ADC).49--58"},{"key":"e_1_2_2_44_1","doi-asserted-by":"publisher","DOI":"10.1145\/1250790.1250803"},{"key":"e_1_2_2_45_1","volume-title":"Proceedings of the 7th International Database Engineering and Applications Symposium. 54--63","author":"Stanley R.","unstructured":"Stanley R. M. Oliveira and Osmar R. Zaiane. 2003. Algorithms for balancing privacy and knowledge discovery in association rule mining . In Proceedings of the 7th International Database Engineering and Applications Symposium. 54--63 . Stanley R. M. Oliveira and Osmar R. Zaiane. 2003. Algorithms for balancing privacy and knowledge discovery in association rule mining. In Proceedings of the 7th International Database Engineering and Applications Symposium. 54--63."},{"key":"e_1_2_2_46_1","unstructured":"PREDICT. 2005. PREDICT (Protected Repository for the Defense of Infrastructure against Cyber Threats). https:\/\/www.predict.org.  PREDICT. 2005. PREDICT (Protected Repository for the Defense of Infrastructure against Cyber Threats). https:\/\/www.predict.org."},{"key":"e_1_2_2_47_1","doi-asserted-by":"publisher","DOI":"10.1145\/1559795.1559812"},{"key":"e_1_2_2_48_1","doi-asserted-by":"publisher","DOI":"10.1109\/69.971193"},{"key":"e_1_2_2_49_1","doi-asserted-by":"publisher","DOI":"10.1038\/ng.436"},{"key":"e_1_2_2_50_1","doi-asserted-by":"publisher","DOI":"10.1145\/974121.974131"},{"key":"e_1_2_2_51_1","doi-asserted-by":"publisher","DOI":"10.1109\/TKDE.2004.1269668"},{"key":"e_1_2_2_52_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.datak.2007.12.005"},{"key":"e_1_2_2_53_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICDM.2005.142"},{"key":"e_1_2_2_54_1","volume-title":"Proceedings of the 32nd International Conference on VLDB (VLDB). 139--150","author":"Xiao Xiaokui","year":"2006","unstructured":"Xiaokui Xiao and Yufei Tao . 2006 . Anatomy: Simple and effective privacy preservation . In Proceedings of the 32nd International Conference on VLDB (VLDB). 139--150 . Xiaokui Xiao and Yufei Tao. 2006. Anatomy: Simple and effective privacy preservation. In Proceedings of the 32nd International Conference on VLDB (VLDB). 139--150."},{"key":"e_1_2_2_55_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICDE.2007.367857"},{"key":"e_1_2_2_56_1","doi-asserted-by":"publisher","DOI":"10.5555\/1700967.1701079"}],"container-title":["ACM Transactions on Database Systems"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/2514689","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/2514689","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,18]],"date-time":"2025-06-18T08:39:18Z","timestamp":1750235958000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/2514689"}},"subtitle":["A framework for mathematical privacy definitions"],"short-title":[],"issued":{"date-parts":[[2014,1]]},"references-count":56,"journal-issue":{"issue":"1","published-print":{"date-parts":[[2014,1]]}},"alternative-id":["10.1145\/2514689"],"URL":"https:\/\/doi.org\/10.1145\/2514689","relation":{},"ISSN":["0362-5915","1557-4644"],"issn-type":[{"value":"0362-5915","type":"print"},{"value":"1557-4644","type":"electronic"}],"subject":[],"published":{"date-parts":[[2014,1]]},"assertion":[{"value":"2012-10-01","order":0,"name":"received","label":"Received","group":{"name":"publication_history","label":"Publication History"}},{"value":"2013-08-01","order":1,"name":"accepted","label":"Accepted","group":{"name":"publication_history","label":"Publication History"}},{"value":"2014-01-06","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}