Aleksandra B. Slavkovic

dblp:34/6946 · DBLP profile ↗
← Back
26ranked-venue papers
1as first author
5since 2021 · last 2026
0000-0003-0497-1771ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 11 · 2 since 2021Artificial intelligence and machine learning · 6 · 3 since 2021Human-computer interaction and ubiquitous computing · 4Applied, interdisciplinary, general and emerging computing · 3Databases, data management, data science and information retrieval · 1Theory of computation · 1 · 1 first-author
YearPublicationVenuePosition
2026 Statistics-Friendly Confidentiality Protection for Establishment Data, with Applications to the QCEW
abstract
Confidentiality for business data is an understudied area of disclosure avoidance, where legacy methods struggle to provide acceptable results. Standard formal privacy techniques for person-level data, like differential privacy, are designed to protect against membership inference and hence do not provide suitable confidentiality/utility trade-offs due to the highly skewed nature of business data and because extreme outlier records are often important contributors to query answers. Prior proposals, therefore, took a personalized differential privacy approach that allowed privacy parameters to degrade for the outlying records – larger establishments get weaker membership inference guarantees. However, providing guarantees to some entities that are strictly weaker than guarantees for others is problematic from a policy standpoint. In this paper, we propose a novel confidentiality framework for business data with a focus on interpretability for policy makers. Instead of protecting against membership inference, which is often not a concern in business data, we protect against attribute inferences that are too precise. In our framework, data curators specify a neighbor function that is used to define uncertainty interval bands around an establishment’s attribute values and the privacy parameters govern the strength of indistinguishability between values within the same uncertainty interval. We propose two query-answering mechanisms under this framework and evaluate them on: (1) a confidential Quarterly Census of Employment and Wages (QCEW) dataset produced by the U.S. Bureau of Labor Statistics (this was done through a cooperative agreement), and (2) a substitute dataset that we created from public sources (and will publicly release).
Kaitlyn Webb, Prottay Protivash, John Durrell, Aleksandra B. Slavkovic, Daniel Kifer, Daniell Toth
Proc. Priv. Enhancing Technol.4
2025 Gaussian Differentially Private Human Faces Under a Face Radial Curve Representation
abstract
In this paper we consider the problem of releasing a Gaussian Differentially Private (GDP) 3D human face. The human face is a complex structure with many features and inherently tied to one's identity. Protecting this data, in a formally private way, is important yet challenging given the dimensionality of the problem. We extend approximate DP techniques for functional data to the GDP framework. We further propose a novel representation, face radial curves, of a 3D face as a set of functions and then utilize our proposed GDP functional data mechanism. To preserve the shape of the face while injecting noise we rely on tools from shape analysis for our novel representation of the face. We show that our method preserves the shape of the average face and injects less noise than traditional methods for the same privacy budget. Our mechanism consists of two primary components, the first is generally applicable to function value summaries (as are commonly found in nonparametric statistics or functional data analysis) while the second is general to disk-like surfaces and hence more applicable than just to human faces.
Carlos Soto 0002, Matthew Reimherr, Aleksandra B. Slavkovic, Mark Shriver
ICLR3
2024 Differentially Private Quantile Regression
Tran Tran, Matthew Reimherr, Aleksandra B. Slavkovic
PSD3
2022 Shape And Structure Preserving Differential Privacy
abstract
It is common for data structures such as images and shapes of 2D objects to be represented as points on a manifold. The utility of a mechanism to produce sanitized differentially private estimates from such data is intimately linked to how compatible it is with the underlying structure and geometry of the space. In particular, as recently shown, utility of the Laplace mechanism on a positively curved manifold, such as Kendall’s 2D shape space, is significantly influenced by the curvature. Focusing on the problem of sanitizing the Fr\'echet mean of a sample of points on a manifold, we exploit the characterization of the mean as the minimizer of an objective function comprised of the sum of squared distances and develop a K-norm gradient mechanism on Riemannian manifolds that favors values that produce gradients close to the the zero of the objective function. For the case of positively curved manifolds, we describe how using the gradient of the squared distance function offers better control over sensitivity than the Laplace mechanism, and demonstrate this numerically on a dataset of shapes of corpus callosa. Further illustrations of the mechanism’s utility on a sphere and the manifold of symmetric positive definite matrices are also presented.
Carlos Soto 0002, Karthik Bharath, Matthew Reimherr, Aleksandra B. Slavkovic
NeurIPS4
2021 Exact Privacy Guarantees for Markov Chain Implementations of the Exponential Mechanism with Artificial Atoms
abstract
Implementations of the exponential mechanism in differential privacy often require sampling from intractable distributions. When approximate procedures like Markov chain Monte Carlo (MCMC) are used, the end result incurs costs to both privacy and accuracy. Existing work has examined these effects asymptotically, but implementable finite sample results are needed in practice so that users can specify privacy budgets in advance and implement samplers with exact privacy guarantees. In this paper, we use tools from ergodic theory and perfect simulation to design exact finite runtime sampling algorithms for the exponential mechanism by introducing an intermediate modified target distribution using artificial atoms. We propose an additional modification of this sampling algorithm that maintains its $\epsilon$-DP guarantee and has improved runtime at the cost of some utility. We then compare these methods in scenarios where we can explicitly calculate a $\delta$ cost (as in $(\epsilon, \delta)$-DP) incurred when using standard MCMC techniques. Much as there is a well known trade-off between privacy and utility, we demonstrate that there is also a trade-off between privacy guarantees and runtime.
Jeremy Seeman, Matthew Reimherr, Aleksandra B. Slavkovic
NeurIPS3
2020 Private Posterior Inference Consistent with Public Information: A Case Study in Small Area Estimation from Synthetic Census Data
Jeremy Seeman, Aleksandra B. Slavkovic, Matthew Reimherr
PSD2
2019 Redesigning PopMedNetTM for distributed regression analysis with vertically partitioned data
Qoua L. Her, Yuji Samizo, Thomas Kent, Aleksandra B. Slavkovic, Mia Gallagher, Darren Toh
AMIA4
2019 Benefits and Pitfalls of the Exponential Mechanism with Applications to Hilbert Spaces and Functional PCA
abstract
The exponential mechanism is a fundamental tool of Differential Privacy (DP) due to its strong privacy guarantees and flexibility. We study its extension to settings with summaries based on infinite dimensional outputs such as with functional data analysis, shape analysis, and nonparametric statistics. We show that the mechanism must be designed with respect to a specific base measure over the output space, such as a Gaussian process. We provide a positive result that establishes a Central Limit Theorem for the exponential mechanism quite broadly. We also provide a negative result, showing that the magnitude of noise introduced for privacy is asymptotically non-negligible relative to the statistical estimation error. We develop an $\ep$-DP mechanism for functional principal component analysis, applicable in separable Hilbert spaces, and demonstrate its performance via simulations and applications to two datasets.
Jordan Awan, Ana Kenney, Matthew Reimherr, Aleksandra B. Slavkovic
ICML4
2019 Formal Privacy for Functional Data with Gaussian Perturbations
abstract
Motivated by the rapid rise in statistical tools in Functional Data Analysis, we consider the Gaussian mechanism for achieving differential privacy (DP) with parameter estimates taking values in a, potentially infinite-dimensional, separable Banach space. Using classic results from probability theory, we show how densities over function spaces can be utilized to achieve the desired DP bounds. This extends prior results of Hall et al (2013) to a much broader class of statistical estimates and summaries, including “path level" summaries, nonlinear functionals, and full function releases. By focusing on Banach spaces, we provide a deeper picture of the challenges for privacy with complex data, especially the role regularization plays in balancing utility and privacy. Using an application to penalized smoothing, we highlight this balance in the context of mean function estimation. Simulations and an application to {diffusion tensor imaging} are briefly presented, with extensive additions included in a supplement.
Ardalan Mirshani, Matthew Reimherr, Aleksandra B. Slavkovic
ICML3
2018 Differentially Private Uniformly Most Powerful Tests for Binomial Data
abstract
We derive uniformly most powerful (UMP) tests for simple and one-sided hypotheses for a population proportion within the framework of Differential Privacy (DP), optimizing finite sample performance. We show that in general, DP hypothesis tests can be written in terms of linear constraints, and for exchangeable data can always be expressed as a function of the empirical distribution. Using this structure, we prove a ‘Neyman-Pearson lemma’ for binomial data under DP, where the DP-UMP only depends on the sample sum. Our tests can also be stated as a post-processing of a random variable, whose distribution we coin “Truncated-Uniform-Laplace” (Tulap), a generalization of the Staircase and discrete Laplace distributions. Furthermore, we obtain exact p-values, which are easily computed in terms of the Tulap random variable. We show that our results also apply to distribution-free hypothesis tests for continuous data. Our simulation results demonstrate that our tests have exact type I error, and are more powerful than current techniques.
Jordan Awan, Aleksandra B. Slavkovic
NeurIPS2
2018 Synthetic Data via Quantile Regression for Heavy-Tailed and Heteroskedastic Data
Michelle Pistner, Aleksandra B. Slavkovic, Lars Vilhuber
PSD2
2018 pMSE Mechanism: Differentially Private Synthetic Data with Maximal Distributional Similarity
Joshua Snoke, Aleksandra B. Slavkovic
PSD2
2016 Accurate Estimation of Structural Equation Models with Remote Partitioned Data
Joshua Snoke, Timothy R. Brick, Aleksandra B. Slavkovic
PSD3
2014 Differentially Private Exponential Random Graphs
Vishesh Karwa, Aleksandra B. Slavkovic, Pavel N. Krivitsky
Privacy in Statistical Databases2
2014 Scalable privacy-preserving data sharing methodology for genome-wide association studies
Fei Yu 0005, Stephen E. Fienberg, Aleksandra B. Slavkovic, Caroline Uhler
J. Biomed. Informatics3
2014 Ten Simple Rules for the Care and Feeding of Scientific Data
abstract
Author(s): Goodman, Alyssa; Pepe, Alberto; Blocker, Alexander W; Borgman, Christine L; Cranmer, Kyle; Crosas, Merce; Di Stefano, Rosanne; Gil, Yolanda; Groth, Paul; Hedstrom, Margaret; Hogg, David W; Kashyap, Vinay; Mahabal, Ashish; Siemiginowska, Aneta; Slavkovic, Aleksandra | Editor(s): Bourne, Philip E
Alyssa Goodman, Alberto Pepe, Alexander W. Blocker, Christine L. Borgman, Kyle Cranmer, Mercè Crosas, Rosanne Di Stefano, Yolanda Gil, Paul Groth, Margaret L. Hedstrom, David W. Hogg, Vinay L. Kashyap, Ashish Mahabal, Aneta Siemiginowska, Aleksandra B. Slavkovic
PLoS Comput. Biol.15
2012 Differentially Private Graphical Degree Sequences and Synthetic Graphs
Vishesh Karwa, Aleksandra B. Slavkovic
Privacy in Statistical Databases2
2012 Logistic Regression with Variables Subject to Post Randomization Method
Yong Ming Jeffrey Woo, Aleksandra B. Slavkovic
Privacy in Statistical Databases2
2011 Supporting common ground and awareness in emergency management planning: A design research project
abstract
We present a design research project on knowledge sharing and activity awareness in distributed emergency management planning. In three experiments we studied groups using three different prototypes, respectively: a paper-prototype in a collocated work setting, a first software prototype in a distributed setting, and a second, enhanced software prototype in a distributed setting. In this series of studies we tried to better understand the processes of knowledge sharing and activity awareness in complex cooperative work by developing and investigating new tools that can support these processes. We explicate the design rationale behind each prototype and report the results of each experiment investigating it. We discuss how the results from each prototyping phase brought us closer to defining properties of a system that facilitate the sharing and awareness of both content and process knowledge. Our designs enhanced aspects of distributed group performance, in some respects beyond that of comparable face-to-face groups.
Gregorio Convertino, Helena M. Mentis, Aleksandra B. Slavkovic, Mary Beth Rosson, John M. Carroll 0001
ACM Trans. Comput. Hum. Interact.3
2009 Supporting content and process common ground in computer-supported teamwork
abstract
We build on our prior work with computer-supported teams performing a complex decision-making task on maps, where the distinction between content and process common ground is proposed. In this paper we describe a distributed geo-collaboration software prototype. The system design rationale was gleaned from fieldwork, literature on team cognition, and an earlier lab study introducing a reference task with face-to-face teams. We report on a controlled experiment that evaluates this design rationale. Distinct sets of measures show that that the prototype supported both content and process common ground, offsetting the costs imposed by the distributed setting. We interpret the results in relation to prior work on common ground and draw implications for moving beyond current models of sharing and coordination.
Gregorio Convertino, Helena M. Mentis, Mary Beth Rosson, Aleksandra B. Slavkovic, John M. Carroll 0001
CHI4
2008 Articulating common ground in cooperative work: content and process
abstract
We study the development of common ground in an emergency management planning task. Twelve three-person multi-role teams performed the task with a paper prototype in a controlled setting; each team completed three versions of the task. We use converging measures to document the development of common ground in the teams and present an in-depth analysis of the characteristics of the common ground development process. Our findings indicate that in complex collaborative work, process common ground increases, thus diminishing the need for acts like information querying or strategy discussions about how to organize the collaborative activities. However, content common ground is created and tested throughout the three runs; in fact dialogue acts used to clarify this content increase over time. Discussion of the implications of these findings for the theory of common ground and the design of collaborative systems follows.
Gregorio Convertino, Helena M. Mentis, Mary Beth Rosson, John M. Carroll 0001, Aleksandra B. Slavkovic, Craig H. Ganoe
CHI5
2008 Cell Bounds in Two-Way Contingency Tables Based on Conditional Frequencies
Byran J. Smucker, Aleksandra B. Slavkovic
Privacy in Statistical Databases2
2006 "Secure" Log-Linear and Logistic Regression Analysis of Distributed Databases
Stephen E. Fienberg, William J. Fulp, Aleksandra B. Slavkovic, Tracey A. Wrobel
Privacy in Statistical Databases3
2006 The space of compatible full conditionals is a unimodular toric variety
Aleksandra B. Slavkovic, Seth Sullivant
J. Symb. Comput.1
2005 Preserving the Confidentiality of Categorical Statistical Data Bases When Releasing Information for Association Rules
Stephen E. Fienberg, Aleksandra B. Slavkovic
Data Min. Knowl. Discov.2
2000 Using a large projection screen as an alternative to head-mounted displays for virtual environments
abstract
Head-mounted displays for virtual environments facilitate an immersive experience that seems more real than an experience provided by a desk-top monitor [18]; however, the cost of head-mounted displays can prohibit their use. An empirical study was conducted investigating differences in spatial knowledge learned for a virtual environment presented in three viewing conditions: head-mounted display, large projection screen, and desk-top monitor. Participants in each condition were asked to reproduce their cognitive map of a virtual environment, which had been developed during individual exploration of the environment along a predetermined course. Error scores were calculated, indicating the degree to which each participant's map differed from the actual layout of the virtual environment. No statistically significant difference was found between the head-mounted display and large projection screen conditions. An implication of this result is that a large projection screen may be an effective, inexpensive substitute for a head-mounted display.
Emilee Rader, Dennis Cosgrove, Aleksandra B. Slavkovic, Jennifer Ann Rode, Thom Verratti, Greg Chiselko
CHI3