Cloud-based collaboration platforms encrypt content but typically leave metadata — who meets whom, how often, and when — observable to the cloud provider and to any adversary who compromises it. We study whether differential privacy (DP) can protect this metadata in a realistic organisational setting, and show empirically that the way noise is composed matters as much as the privacy budget itself. Using a synthetic organisational dataset with a designated “sensitive cluster” of densely-interacting users, we implement and measure two DP release mechanisms: a naive per-cell mechanism that applies independent Laplace noise to every pairwise interaction count, and a corrected mechanism that calibrates noise directly to each released statistic’s own sensitivity. We find that (1) without protection, a simple logistic-regression adversary achieves near-perfect (AUC = 1.00) inference of sensitive cluster membership from raw metadata; (2) commonly-assumed privacy budgets such as ε = 1.0 leave this attack largely intact (AUC = 0.92), and ε ≤ 0.5 is needed to degrade it meaningfully; and (3) correcting the composition of the release mechanism reduces aggregate-query error by roughly three orders of magnitude at every tested ε, while maintaining the same stated privacy budget. A reproducible prototype implementation produces all reported results; no experimental figures in this paper are estimated or illustrative.
Differential Privacy, Cloud Collaboration, Metadata Privacy, Membership Inference, Privacy–Utility Trade-off.
. Correctly-Scoped Differential Privacy for Metadata Protection in Collaborative Cloud Applications: A Measurement Study. Indian Journal of Modern Research and Reviews. 2026; 4(8):256-260
Download PDF