
Banning "noise infusion" from US Census products will be a disaster, privacy researcher warns
The US Department of Commerce has barred "noise infusion" from statistical products published by the Census Bureau and the Bureau of Economic Analysis, removing the basis of differential privacy.
The United States Department of Commerce has issued an order declaring that "noise infusion" will be banned from all statistical products published by the Census Bureau and the Bureau of Economic Analysis. The measure, analysed in a blog post by privacy researcher Damien Desfontaines, removes the main technique behind differential privacy — the method the Bureau adopted for the 2020 Census.
The disclosure-avoidance toolbox
Statistical products are numbers published from a secret dataset, and they must not reveal the confidential records underneath. Statisticians call the field disclosure avoidance, and Desfontaines lists the standard techniques: suppression (dropping counts below a threshold), coarsening (making attributes less precise), sampling, swapping attributes between records, contribution bounding, and noise addition — adding a random number to a statistic to hide its true value.
Combining contribution bounding with carefully calibrated noise produces differential privacy, which the post calls the gold standard of privacy protection among scientists.
Why the Census adopted noise
From 1990 to 2010 the Census Bureau relied mainly on swapping. It later found the technique unsafe and that individual records could be reconstructed from published statistics — a problem, since federal law requires those records to stay confidential. Differential privacy was chosen for the 2020 Census because, among the options that mitigated the attack, it preserved the most utility; its parameters were set for usefulness at an acceptable level of privacy, not for rock-solid guarantees.
The 2020 numbers were less accurate than in 2010, and the inaccuracies became impossible to ignore. Demographers and social scientists had to work with noisier data, and the Bureau's communication of the change drew heavy criticism. Reconstruction, the post notes, was an open secret used by political operatives in gerrymandering, which likely explains the political attention on a niche technical debate.
What the order does
The order targets differential privacy but also appears to affect other techniques that involve randomness: the text states that coarsening should always be preferred, with suppression as a "last resort". It adds that it "shall not be interpreted to conflict with any constitutional, statutory, regulatory, or other legal provision", so confidentiality obligations still stand.
Desfontaines argues the consequences will be dire for utility or for privacy, and possibly both: future releases will either be far less useful than past ones or unsafe. Other widely used methods also rely on noise — the Cell Key method, swapping, sampling and even imputation. Coarsening and suppression, by contrast, only work when statistics are already very coarse; on complex products they either destroy utility, especially for minority populations, or leave the data vulnerable.
The post notes that attacks on statistical releases amount to solving a system of equations, and that uncertainty is what makes them hard.
SiTech — AI-powered web development
We build fast, modern websites and bring AI into real business workflows. Have a project or a question? We'd love to help.