{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,8,20]],"date-time":"2026-08-20T14:48:28Z","timestamp":1787237308017,"version":"3.56.0"},"reference-count":40,"publisher":"Association for Computing Machinery (ACM)","issue":"11","content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Proc. VLDB Endow."],"published-print":{"date-parts":[[2019,7]]},"abstract":"<jats:p>Differential privacy is considered a de facto standard for private data analysis. However, the definition and much of the supporting literature applies to flat tables. While there exist variants of the definition and specialized algorithms for specific types of relational data (e.g. graphs), there isn't a general privacy definition for multi-relational schemas with constraints, and no system that permits accurate differentially private answering of SQL queries while imposing a fixed privacy budget across all queries posed by the analyst.<\/jats:p>\n                  <jats:p>This work presents PrivateSQL, a first-of-its-kind end-to-end differentially private relational database system. PrivateSQL allows an analyst to query data stored in a standard database management system using a rich class of SQL counting queries. PrivateSQL adopts a novel generalization of differential privacy to multi-relational data that takes into account constraints in the schema like foreign keys, and allows the data owner to flexibly specify entities in the schema that need privacy. PrivateSQL ensures a fixed privacy loss across all the queries posed by the analyst by answering queries on private synopses generated from several views over the base relation that are tuned to have low error on a representative query workload. We experimentally evaluate PrivateSQL on a real-world dataset and a workload of more than 3, 600 queries. We show that for 50% of the queries PrivateSQL offers at least 1, 000x better error rates than solutions adapted from prior work.<\/jats:p>","DOI":"10.14778\/3342263.3342274","type":"journal-article","created":{"date-parts":[[2019,9,18]],"date-time":"2019-09-18T14:36:11Z","timestamp":1568817371000},"page":"1371-1384","source":"Crossref","is-referenced-by-count":100,"title":["PrivateSQL"],"prefix":"10.14778","volume":"12","author":[{"given":"Ios","family":"Kotsogiannis","sequence":"first","affiliation":[{"name":"Duke University"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Yuchao","family":"Tao","sequence":"additional","affiliation":[{"name":"Duke University"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Xi","family":"He","sequence":"additional","affiliation":[{"name":"University of Waterloo"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Maryam","family":"Fanaeepour","sequence":"additional","affiliation":[{"name":"Duke University"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Ashwin","family":"Machanavajjhala","sequence":"additional","affiliation":[{"name":"Duke University"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Michael","family":"Hay","sequence":"additional","affiliation":[{"name":"Colgate University"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Gerome","family":"Miklau","sequence":"additional","affiliation":[{"name":"University of Massachusetts"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2019,7]]},"reference":[{"key":"e_1_2_1_1_1","unstructured":"2010 census summary file 1. https:\/\/www.census.gov\/prod\/cen2010\/doc\/sf1.pdf.  2010 census summary file 1. https:\/\/www.census.gov\/prod\/cen2010\/doc\/sf1.pdf."},{"key":"e_1_2_1_2_1","unstructured":"Census scientific advisory committee fall meeting. https:\/\/www.census.gov\/about\/cac\/sac\/meetings\/2018-12-meeting.html.  Census scientific advisory committee fall meeting. https:\/\/www.census.gov\/about\/cac\/sac\/meetings\/2018-12-meeting.html."},{"key":"e_1_2_1_3_1","unstructured":"Tpc benchmark h. https:\/\/http:\/\/www.tpc.org\/tpch\/.  Tpc benchmark h. https:\/\/http:\/\/www.tpc.org\/tpch\/."},{"key":"e_1_2_1_4_1","doi-asserted-by":"publisher","DOI":"10.1145\/2465351.2465355"},{"key":"e_1_2_1_5_1","first-page":"1","volume-title":"ICALP","author":"Arapinis M.","year":"2016","unstructured":"M. Arapinis , D. Figueira , and M. Gaboardi . Sensitivity of counting queries . In ICALP , pages 120: 1 -- 120 :13, 2016 . M. Arapinis, D. Figueira, and M. Gaboardi. Sensitivity of counting queries. In ICALP, pages 120:1--120:13, 2016."},{"key":"e_1_2_1_6_1","doi-asserted-by":"publisher","DOI":"10.1145\/6012.15399"},{"key":"e_1_2_1_7_1","doi-asserted-by":"publisher","DOI":"10.1145\/1265530.1265569"},{"key":"e_1_2_1_8_1","doi-asserted-by":"publisher","DOI":"10.1145\/3132747.3132769"},{"key":"e_1_2_1_9_1","doi-asserted-by":"publisher","DOI":"10.1145\/2463676.2465304"},{"key":"e_1_2_1_10_1","doi-asserted-by":"publisher","DOI":"10.1145\/2882903.2926745"},{"key":"e_1_2_1_11_1","volume-title":"Learning with privacy at scale","author":"Differential Privacy Team A.","year":"2017","unstructured":"A. Differential Privacy Team . Learning with privacy at scale , 2017 . A. Differential Privacy Team. Learning with privacy at scale, 2017."},{"key":"e_1_2_1_12_1","doi-asserted-by":"publisher","DOI":"10.1145\/3269206.3271736"},{"key":"e_1_2_1_13_1","doi-asserted-by":"publisher","DOI":"10.1145\/773153.773173"},{"key":"e_1_2_1_14_1","doi-asserted-by":"publisher","DOI":"10.1145\/1806689.1806787"},{"key":"e_1_2_1_15_1","doi-asserted-by":"publisher","DOI":"10.1561\/0400000042"},{"key":"e_1_2_1_16_1","doi-asserted-by":"publisher","DOI":"10.1145\/2660267.2660348"},{"key":"e_1_2_1_17_1","doi-asserted-by":"crossref","DOI":"10.7551\/mitpress\/7432.001.0001","volume-title":"Introduction to Statistical Relational Learning (Adaptive Computation and Machine Learning)","author":"Getoor L.","year":"2007","unstructured":"L. Getoor and B. Taskar . Introduction to Statistical Relational Learning (Adaptive Computation and Machine Learning) . The MIT Press , 2007 . L. Getoor and B. Taskar. Introduction to Statistical Relational Learning (Adaptive Computation and Machine Learning). The MIT Press, 2007."},{"key":"e_1_2_1_18_1","doi-asserted-by":"publisher","DOI":"10.1007\/s007780100054"},{"key":"e_1_2_1_19_1","doi-asserted-by":"publisher","DOI":"10.1145\/3035918.3035940"},{"key":"e_1_2_1_20_1","first-page":"2339","volume-title":"Advances in Neural Information Processing Systems 25","author":"Hardt M.","year":"2012","unstructured":"M. Hardt , K. Ligett , and F. Mcsherry . A simple and practical algorithm for differentially private data release. In F. Pereira, C. Burges, L. Bottou, and K. Weinberger, editors , Advances in Neural Information Processing Systems 25 , pages 2339 -- 2347 . Curran Associates, Inc. , 2012 . M. Hardt, K. Ligett, and F. Mcsherry. A simple and practical algorithm for differentially private data release. In F. Pereira, C. Burges, L. Bottou, and K. Weinberger, editors, Advances in Neural Information Processing Systems 25, pages 2339--2347. Curran Associates, Inc., 2012."},{"key":"e_1_2_1_21_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICDM.2009.11"},{"key":"e_1_2_1_22_1","doi-asserted-by":"publisher","DOI":"10.1145\/2882903.2882931"},{"key":"e_1_2_1_23_1","doi-asserted-by":"publisher","DOI":"10.1145\/2588555.2588581"},{"key":"e_1_2_1_24_1","doi-asserted-by":"publisher","DOI":"10.1145\/3187009.3177733"},{"key":"e_1_2_1_25_1","doi-asserted-by":"publisher","DOI":"10.1145\/2611523"},{"key":"e_1_2_1_26_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-36594-2_26"},{"key":"e_1_2_1_27_1","doi-asserted-by":"publisher","DOI":"10.14778\/2732269.2732271"},{"key":"e_1_2_1_28_1","doi-asserted-by":"publisher","DOI":"10.1007\/s00778-015-0398-x"},{"key":"e_1_2_1_29_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICDE.2014.6816689"},{"key":"e_1_2_1_30_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICDE.2008.4497436"},{"key":"e_1_2_1_31_1","doi-asserted-by":"publisher","DOI":"10.14778\/3231751.3231769"},{"key":"e_1_2_1_32_1","doi-asserted-by":"publisher","DOI":"10.1145\/1559845.1559850"},{"key":"e_1_2_1_33_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-03356-8_8"},{"key":"e_1_2_1_34_1","doi-asserted-by":"publisher","DOI":"10.14778\/2556549.2556576"},{"key":"e_1_2_1_35_1","doi-asserted-by":"publisher","DOI":"10.1145\/2588555.2588575"},{"key":"e_1_2_1_36_1","unstructured":"W. Sexton J. M. Abowd I. M. Schmutte and L. Vilhuber. Synthetic population housing and person records for the united states.  W. Sexton J. M. Abowd I. M. Schmutte and L. Vilhuber. Synthetic population housing and person records for the united states."},{"key":"e_1_2_1_37_1","doi-asserted-by":"publisher","DOI":"10.1109\/TKDE.2010.247"},{"key":"e_1_2_1_38_1","doi-asserted-by":"publisher","DOI":"10.1145\/3183713.3196921"},{"key":"e_1_2_1_39_1","doi-asserted-by":"publisher","DOI":"10.1145\/2588555.2588573"},{"key":"e_1_2_1_40_1","doi-asserted-by":"publisher","DOI":"10.1137\/1.9781611973440.68"}],"container-title":["Proceedings of the VLDB Endowment"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.14778\/3342263.3342274","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2022,12,28]],"date-time":"2022-12-28T04:56:52Z","timestamp":1672203412000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.14778\/3342263.3342274"}},"subtitle":["a differentially private SQL query engine"],"short-title":[],"issued":{"date-parts":[[2019,7]]},"references-count":40,"journal-issue":{"issue":"11","published-print":{"date-parts":[[2019,7]]}},"alternative-id":["10.14778\/3342263.3342274"],"URL":"https:\/\/doi.org\/10.14778\/3342263.3342274","relation":{},"ISSN":["2150-8097"],"issn-type":[{"value":"2150-8097","type":"print"}],"subject":[],"published":{"date-parts":[[2019,7]]}}}