[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-detail-81584-en":3,"doc-seo-81584-105":30,"detail-sidebar-cat-0-en-105":91},{"code":4,"msg":5,"data":6},0,"success",{"doc_id":7,"user_id":8,"nickname":9,"user_avatar":10,"doc_module":4,"category_id":11,"category_name":12,"doc_title":13,"doc_description":14,"doc_content":15,"file_id":16,"file_url":17,"file_type":18,"file_size":19,"view_count":20,"is_deleted":4,"is_public":21,"is_downloadable":21,"audit_status":21,"page_count":22,"language":23,"language_code":24,"site_id":25,"html_lang":24,"table_of_contents":26,"faqs":27,"seo_title":13,"seo_description":14,"update_tm":28,"read_time":29},81584,962075006959,"Anda","https://ap-avatar.wpscdn.com/avatar/e0002397efbe92a78e?_k=1776741047341049297",8,"Research & Report","Adaptive Privacy of Sequential Data Releases Under Collusion","The paper studies the privacy–utility trade-off for sequential data releases when multiple parties may collude. It argues that one-time privacy mechanisms do not transfer directly to repeated releases, and that distinct real-world parties may request data over time with potential data sharing between receivers. The work formulates a new adaptive privacy-utility problem using expected distortion or mutual information for utility and mutual information for privacy, then designs a Blahut–Arimoto-style algorithm and validates it with experiments on real data.","Adaptive Privacy of Sequential Data Releases Under Collusion  \nSophie Taylor, Praneeth Kumar Vippathalla, and Justin P. Coon  \narXiv :2601 .2 1859v2 [ cs .IT] 10 Jul 2026  \nAbstract—The fundamental trade-off between privacy and utility remains an active area of research. Our contribution is motivated by two observations. First, privacy mechanisms developed for one-time data release cannot straightforwardly be extended to sequential releases. Second, practical databases are likely to be useful to multiple distinct parties. Furthermore, we can not rule out the possibility of data sharing between parties. With utility in mind, we formulate a new privacy-utility trade-off problem to adaptively tackle sequential data requests made by different, potentially colluding entities. We consider both expected distortion and mutual information as measures to quantify utility, and use mutual information to measure privacy. We assume an attack model whereby illicit data sharing, which we call collusion, can occur between data receivers. We develop an adaptive algorithm for data releases that makes use of a Blahut–Arimoto-style algorithm. We show that the resulting data releases are optimal when expected distortion quantifies utility, and locally optimal when mutual information quantifies utility. Numerical experiments on real data demonstrate that the proposed adaptive algorithm can exploit previously released information to reduce cumulative leakage under collusion without sacrificing much, if any utility. Finally, we discuss how our findings may extend to applications in machine learning.  \nI. INTRODUCTION  \nIn data privacy literature, a common goal is to maximise the utility of a data release, whilst maintaining a certain level of privacy. In its simplest form, the problem considersa single party that has made one request for data. They are sent a version of their request that has undergone some transformation via a privacy mechanism. Should this party make a second data request, the naive approach of using the same privacy mechanism poses clear issues. Assuming the mechanism was designed subject to a privacy budget, we can expect that applying it twice will not meet the same budget. In fact, in the worst case, the two data releases may combine synergistically, revealing far more information than the sum of their individual contributions.1 A malicious actor could design their data requests to exploit this fact. To address this, many authors have considered adaptive privacy schemes, which take into account previous data releases.  \nIt is also conceivable that multiple distinct parties maybe interested in a dataset. For example, a medical dataset might prove useful to several research groups, each pursuing  \nThe authors are with the Department of Engineering Science, University of Oxford, Parks Road, Oxford, OX1 3PJ, UK,(email: sophie.taylor2@balliol. [ox.ac.uk](ox.ac.uk); [praneeth.vippathalla@eng.ox.ac.uk](praneeth.vippathalla@eng.ox.ac.uk); [justin.coon@eng.ox.ac.uk](justin.coon@eng.ox.ac.uk)).  \nThis research was funded in part by the Engineering and Physical Sciences Research Council under grant number EP/W524311/1, and the U. S. Army Research Laboratory and the U. S. Army Research Office under grant number W911NF-22-1-0070 . For the purpose of Open Access, the authors have applied a CC BY public copyright license to any Author Accepted Manuscript (AAM) version arising from this submission.  \n1To see this, consider the general possibility that I(X, Y ; Z) > I (X; Z)+ I (Y ; Z) for random variables X, Y, Z.  \nFig. 1. Problem setup for a multi-party adaptive scheme  \ndifferent objectives. The data handler may wish to exploit the full research potential of the dataset rather than limiting access to one group. Likewise, social media companies sell or license users’ data to multiple third parties for advertising and analytics purposes. In both cases, data handlers are unlikely to communicate with all parties simultaneously and will instead r","cbCaitGjSOVTP9Ae","https://ap.wps.com/l/cbCaitGjSOVTP9Ae","pdf",2016653,2,1,13,"English","en",105,"# Introduction\n## Privacy–utility challenge in repeated releases\n## Multi-party sequential requests and collusion threat\n## Problem setup and online adaptive model","[{\"question\":\"Why can’t one-time privacy mechanisms be directly reused for sequential data releases?\",\"answer\":\"Applying the same mechanism multiple times may violate the original privacy budget assumptions. Combined releases can also reveal more information jointly than the sum of their individual contributions.\"},{\"question\":\"How does the paper model collusion among adversarial data receivers?\",\"answer\":\"It assumes illicit data sharing can occur between receivers, so a malicious actor may combine information obtained from different parties’ released data up to the most recent release.\"},{\"question\":\"What privacy and utility measures does the proposed adaptive approach use?\",\"answer\":\"Utility is quantified using expected distortion or mutual information, while privacy is measured using mutual information. This choice guides how the adaptive release algorithm is optimized.\"}]",1784174514,33,{"code":4,"msg":31,"data":32},"ok",{"site_id":25,"language":24,"slug":33,"title":13,"keywords":34,"description":14,"schema_data":35,"social_meta":86,"head_meta":88,"extra_data":90,"updated_unix":28},"adaptive-privacy-of-sequential-data-releases-under-collusion","",{"@graph":36,"@context":85},[37,53,68],{"@type":38,"itemListElement":39},"BreadcrumbList",[40,44,47,50],{"item":41,"name":42,"@type":43,"position":21},"https://docshare.wps.com","Home","ListItem",{"item":45,"name":46,"@type":43,"position":20},"https://docshare.wps.com/document/","Document",{"item":48,"name":12,"@type":43,"position":49},"https://docshare.wps.com/document/research-report/",3,{"item":51,"name":13,"@type":43,"position":52},"https://docshare.wps.com/document/adaptive-privacy-of-sequential-data-releases-under-collusion/81584/",4,{"url":51,"name":13,"@type":54,"author":55,"headline":13,"publisher":57,"fileFormat":60,"inLanguage":24,"description":14,"dateModified":61,"datePublished":62,"encodingFormat":60,"isAccessibleForFree":63,"interactionStatistic":64},"DigitalDocument",{"name":9,"@type":56},"Person",{"url":41,"name":58,"@type":59},"DocShare","Organization","application/pdf","2026-07-25","2026-07-16",true,{"@type":65,"interactionType":66,"userInteractionCount":20},"InteractionCounter",{"@type":67},"ViewAction",{"@type":69,"mainEntity":70},"FAQPage",[71,77,81],{"name":72,"@type":73,"acceptedAnswer":74},"Why can’t one-time privacy mechanisms be directly reused for sequential data releases?","Question",{"text":75,"@type":76},"Applying the same mechanism multiple times may violate the original privacy budget assumptions. Combined releases can also reveal more information jointly than the sum of their individual contributions.","Answer",{"name":78,"@type":73,"acceptedAnswer":79},"How does the paper model collusion among adversarial data receivers?",{"text":80,"@type":76},"It assumes illicit data sharing can occur between receivers, so a malicious actor may combine information obtained from different parties’ released data up to the most recent release.",{"name":82,"@type":73,"acceptedAnswer":83},"What privacy and utility measures does the proposed adaptive approach use?",{"text":84,"@type":76},"Utility is quantified using expected distortion or mutual information, while privacy is measured using mutual information. This choice guides how the adaptive release algorithm is optimized.","https://schema.org",{"og:url":51,"og:type":87,"og:title":13,"og:site_name":58,"og:description":14},"article",{"robots":89,"canonical":51},"index,follow",{"doc_id":7,"site_id":25},{"code":4,"msg":5,"data":92},[93,97,101,105,110,115,120,123,128,131,135],{"id":21,"doc_module":4,"doc_module_name":46,"category_name":94,"show_sort_weight":95,"slug":96},"Story & Novel",90,"story-novel",{"id":20,"doc_module":4,"doc_module_name":46,"category_name":98,"show_sort_weight":99,"slug":100},"Literature",80,"literature",{"id":52,"doc_module":4,"doc_module_name":46,"category_name":102,"show_sort_weight":103,"slug":104},"Exam",70,"exam",{"id":106,"doc_module":4,"doc_module_name":46,"category_name":107,"show_sort_weight":108,"slug":109},5,"Comic",60,"comic",{"id":111,"doc_module":4,"doc_module_name":46,"category_name":112,"show_sort_weight":113,"slug":114},6,"Technology",50,"technology",{"id":116,"doc_module":4,"doc_module_name":46,"category_name":117,"show_sort_weight":118,"slug":119},7,"Healthcare",40,"healthcare",{"id":11,"doc_module":4,"doc_module_name":46,"category_name":12,"show_sort_weight":121,"slug":122},30,"research-report",{"id":124,"doc_module":4,"doc_module_name":46,"category_name":125,"show_sort_weight":126,"slug":127},9,"Religion & Spirituality",20,"religion-spirituality",{"id":126,"doc_module":4,"doc_module_name":46,"category_name":129,"show_sort_weight":126,"slug":130},"World Cup","world-cup",{"id":132,"doc_module":4,"doc_module_name":46,"category_name":133,"show_sort_weight":132,"slug":134},10,"Lifestyle","lifestyle",{"id":136,"doc_module":4,"doc_module_name":46,"category_name":137,"show_sort_weight":106,"slug":138},19,"General","general"]