PAIS 2015
Transparency and disclosure risk in data privacy Vicen¸ c Torra1 March, 2015
1 School of Informatics, University of Sk¨
- vde, Sweden
Transparency and disclosure risk in data privacy c Torra 1 Vicen - - PowerPoint PPT Presentation
PAIS 2015 Transparency and disclosure risk in data privacy c Torra 1 Vicen March, 2015 1 School of Informatics, University of Sk ovde, Sweden Outline Outline Outline Quantitative measures of risk: record linkage Transparency principle:
1 School of Informatics, University of Sk¨
Outline Outline
Vicen¸ c Torra; Transparency data privacy PAIS 2015 1 / 61
Outline
PAIS 2015 2 / 61
Introduction > Masking methods Outline
PAIS 2015 3 / 61
Introduction > Masking methods Outline
Vicen¸ c Torra; Transparency data privacy PAIS 2015 4 / 61
Introduction > Masking methods Outline
Vicen¸ c Torra; Transparency data privacy PAIS 2015 5 / 61
Introduction > Masking methods Outline
Vicen¸ c Torra; Transparency data privacy PAIS 2015 6 / 61
Introduction > Microaggregation Outline
Vicen¸ c Torra; Transparency data privacy PAIS 2015 7 / 61
Introduction > Microaggregation Outline
v1 v2 v3 v4 v′
1
v′
2
v′
3
v′
4
1 1 1 1 1.66667 2 1.33333 1.66667 2 2 1 2 1.66667 2 1.33333 1.66667 2 3 1 6 1.66667 2 2.33333 5.66667 2 9 1 10 3 7.33333 1.66667 9.66667 3 6 2 2 3 7.33333 1.33333 1.66667 4 1 2 9 4.33333 5 1.66667 9.66667 4 6 2 10 4.33333 5 1.66667 9.66667 4 7 3 2 3 7.33333 2.33333 5.66667 5 8 3 9 4.33333 5 2.33333 5.66667 6 8 4 7 7.66667 8.66667 6 5 8 1 7 2 8.66667 2.66667 6 5 8 9 7 6 7.66667 8.66667 6 5 9 3 8 1 8.66667 2.66667 8.66667 1.33333 9 4 8 2 8.66667 2.66667 8.66667 1.33333 9 9 10 1 7.66667 8.66667 8.66667 1.33333
Vicen¸ c Torra; Transparency data privacy PAIS 2015 8 / 61
Introduction > Disclosure risk Outline
Vicen¸ c Torra; Transparency data privacy PAIS 2015 9 / 61
Introduction > Disclosure risk Outline
Vicen¸ c Torra; Transparency data privacy PAIS 2015 10 / 61
Introduction > Disclosure risk Outline
Vicen¸ c Torra; Transparency data privacy PAIS 2015 11 / 61
Introduction > Disclosure risk Outline
Vicen¸ c Torra; Transparency data privacy PAIS 2015 11 / 61
Introduction > Disclosure risk Outline
Vicen¸ c Torra; Transparency data privacy PAIS 2015 11 / 61
Introduction > Disclosure risk Outline
c = Xc.
nc = ρ(Xnc).
Vicen¸ c Torra; Transparency data privacy PAIS 2015 12 / 61
Introduction > Disclosure risk Outline
Vicen¸ c Torra; Transparency data privacy PAIS 2015 13 / 61
Introduction > Disclosure risk Outline
Vicen¸ c Torra; Transparency data privacy PAIS 2015 14 / 61
Introduction > Disclosure risk Outline
Vicen¸ c Torra; Transparency data privacy PAIS 2015 14 / 61
Introduction > Disclosure risk Outline
Vicen¸ c Torra; Transparency data privacy PAIS 2015 14 / 61
Introduction > Disclosure risk Outline
Vicen¸ c Torra; Transparency data privacy PAIS 2015 14 / 61
Introduction > Disclosure risk Outline
Vicen¸ c Torra; Transparency data privacy PAIS 2015 15 / 61
Introduction > Disclosure risk Outline
Vicen¸ c Torra; Transparency data privacy PAIS 2015 15 / 61
Introduction > Disclosure risk Outline
Vicen¸ c Torra; Transparency data privacy PAIS 2015 15 / 61
Introduction > Disclosure risk Outline
Vicen¸ c Torra; Transparency data privacy PAIS 2015 15 / 61
Introduction > Disclosure risk Outline
Vicen¸ c Torra; Transparency data privacy PAIS 2015 16 / 61
Introduction > Disclosure risk Outline
Vicen¸ c Torra; Transparency data privacy PAIS 2015 16 / 61
Introduction > Disclosure risk Outline
Vicen¸ c Torra; Transparency data privacy PAIS 2015 16 / 61
Introduction > Disclosure risk Outline
Vicen¸ c Torra; Transparency data privacy PAIS 2015 16 / 61
Introduction > Disclosure risk Outline
Vicen¸ c Torra; Transparency data privacy PAIS 2015 16 / 61
Introduction > Disclosure risk Outline
Vicen¸ c Torra; Transparency data privacy PAIS 2015 17 / 61
Introduction > Disclosure risk Outline
Vicen¸ c Torra; Transparency data privacy PAIS 2015 17 / 61
Transparency Outline
Vicen¸ c Torra; Transparency data privacy PAIS 2015 18 / 61
Transparency > Definition Outline
Vicen¸ c Torra; Transparency data privacy PAIS 2015 19 / 61
Transparency > Definition Outline
Vicen¸ c Torra; Transparency data privacy PAIS 2015 20 / 61
Transparency > Definition Outline
i, X′ j) = Cov(Xi, Xj) for i = j
i,X′ j = Cov(X′ i,X′ j)
i)V ar(X′ j) = Cov(Xi,Xj) (1+k)√ V ar(Xi)V ar(Xj) = 1 1+kρXi,Xj Vicen¸ c Torra; Transparency data privacy PAIS 2015 20 / 61
Transparency > Definition Outline
i, X′ j) = Cov(Xi, Xj) for i = j
i,X′ j = Cov(X′ i,X′ j)
i)V ar(X′ j) = Cov(Xi,Xj) (1+k)√ V ar(Xi)V ar(Xj) = 1 1+kρXi,Xj
Vicen¸ c Torra; Transparency data privacy PAIS 2015 20 / 61
Transparency > Definition Outline
Vicen¸ c Torra; Transparency data privacy PAIS 2015 21 / 61
Transparency > Attacks Outline
Vicen¸ c Torra; Transparency data privacy PAIS 2015 22 / 61
Transparency > Rank swapping and transparency Outline
Vicen¸ c Torra; Transparency data privacy PAIS 2015 23 / 61
Transparency > Rank swapping and transparency Outline
Vicen¸ c Torra; Transparency data privacy PAIS 2015 23 / 61
Transparency > Rank swapping and transparency Outline
Vicen¸ c Torra; Transparency data privacy PAIS 2015 23 / 61
Transparency > Rank swapping and transparency Outline
Vicen¸ c Torra; Transparency data privacy PAIS 2015 23 / 61
Transparency > Rank swapping and transparency Outline
Vicen¸ c Torra; Transparency data privacy PAIS 2015 24 / 61
Transparency > Rank swapping and transparency Outline
Vicen¸ c Torra; Transparency data privacy PAIS 2015 24 / 61
Transparency > Rank swapping and transparency Outline
Vicen¸ c Torra; Transparency data privacy PAIS 2015 24 / 61
Transparency > Rank swapping and transparency Outline
Vicen¸ c Torra; Transparency data privacy PAIS 2015 24 / 61
Transparency > Rank swapping and transparency Outline
Vicen¸ c Torra; Transparency data privacy PAIS 2015 25 / 61
Transparency > Rank swapping and transparency Outline
ℓ ∈ Bj(a)
Vicen¸ c Torra; Transparency data privacy PAIS 2015 25 / 61
Transparency > Rank swapping and transparency Outline
ℓ ∈ Bj(a)
ℓ ∈ ∩1≤j≤cBj(xi).
Vicen¸ c Torra; Transparency data privacy PAIS 2015 25 / 61
Transparency > Rank swapping and transparency Outline
ℓ ∈ Bj(a)
ℓ ∈ ∩1≤j≤cBj(xi).
Vicen¸ c Torra; Transparency data privacy PAIS 2015 25 / 61
Transparency > Rank swapping and transparency Outline
ℓ ∈ ∩1≤j≤cBj(xi).
Vicen¸ c Torra; Transparency data privacy PAIS 2015 26 / 61
Transparency > Rank swapping and transparency Outline
1
2
3
4
Vicen¸ c Torra; Transparency data privacy PAIS 2015 27 / 61
Transparency > Rank swapping and transparency Outline
1
2
3
4
Vicen¸ c Torra; Transparency data privacy PAIS 2015 28 / 61
Transparency > Rank swapping and transparency Outline
Vicen¸ c Torra; Transparency data privacy PAIS 2015 29 / 61
Transparency > Rank swapping and transparency Outline
Vicen¸ c Torra; Transparency data privacy PAIS 2015 30 / 61
Transparency > Rank swapping and transparency Outline
Vicen¸ c Torra; Transparency data privacy PAIS 2015 31 / 61
Transparency > Rank swapping and transparency Outline
Vicen¸ c Torra; Transparency data privacy PAIS 2015 32 / 61
Transparency > Avoiding Attacks RS Outline
Vicen¸ c Torra; Transparency data privacy PAIS 2015 33 / 61
Transparency > Avoiding Attacks RS Outline
Vicen¸ c Torra; Transparency data privacy PAIS 2015 34 / 61
Transparency > Avoiding Attacks RS Outline
Vicen¸ c Torra; Transparency data privacy PAIS 2015 34 / 61
Transparency > Avoiding Attacks RS Outline
Vicen¸ c Torra; Transparency data privacy PAIS 2015 35 / 61
Transparency > Attacks Outline
Vicen¸ c Torra; Transparency data privacy PAIS 2015 36 / 61
Transparency > Microaggregation Outline
ℓ ∈ Bj(a)
ℓ ∈ ∩1≤j≤cBj(xi).
Vicen¸ c Torra; Transparency data privacy PAIS 2015 37 / 61
Transparency > Avoiding Attacks Microaggregation Outline
Vicen¸ c Torra; Transparency data privacy PAIS 2015 38 / 61
Transparency > Avoiding Attacks Microaggregation Outline
Vicen¸ c Torra; Transparency data privacy PAIS 2015 39 / 61
Disclosure risk > Distances Outline
Vicen¸ c Torra; Transparency data privacy PAIS 2015 40 / 61
Disclosure Risk > Distances Outline
Vicen¸ c Torra; Transparency data privacy PAIS 2015 41 / 61
Disclosure Risk > Distances Outline
n
Vicen¸ c Torra; Transparency data privacy PAIS 2015 42 / 61
Disclosure Risk > Distances Outline
Vicen¸ c Torra; Transparency data privacy PAIS 2015 43 / 61
Disclosure Risk > Distances Outline
Vicen¸ c Torra; Transparency data privacy PAIS 2015 43 / 61
Disclosure Risk > Distances Outline
Vicen¸ c Torra; Transparency data privacy PAIS 2015 44 / 61
Disclosure Risk > Distances Outline
Vicen¸ c Torra; Transparency data privacy PAIS 2015 44 / 61
Disclosure Risk > Distances Outline
Vicen¸ c Torra; Transparency data privacy PAIS 2015 45 / 61
Disclosure Risk > Distances Outline
Vicen¸ c Torra; Transparency data privacy PAIS 2015 46 / 61
Disclosure Risk > Distances Outline
Vicen¸ c Torra; Transparency data privacy PAIS 2015 47 / 61
Disclosure Risk > Distances Outline
Vicen¸ c Torra; Transparency data privacy PAIS 2015 47 / 61
Disclosure Risk > Distances Outline
Vicen¸ c Torra; Transparency data privacy PAIS 2015 48 / 61
Disclosure Risk > Distances Outline
Vicen¸ c Torra; Transparency data privacy PAIS 2015 48 / 61
Disclosure Risk > Distances Outline
Vicen¸ c Torra; Transparency data privacy PAIS 2015 49 / 61
Disclosure Risk > Distances Outline
N
Vicen¸ c Torra; Transparency data privacy PAIS 2015 50 / 61
Disclosure Risk > Distances Outline
N
n
Vicen¸ c Torra; Transparency data privacy PAIS 2015 51 / 61
Disclosure Risk > Distances Outline
Vicen¸ c Torra; Transparency data privacy PAIS 2015 52 / 61
Disclosure Risk > Distances Outline
Vicen¸ c Torra; Transparency data privacy PAIS 2015 53 / 61
Disclosure Risk > Distances Outline
Vicen¸ c Torra; Transparency data privacy PAIS 2015 54 / 61
Disclosure Risk > Distances Outline
Vicen¸ c Torra; Transparency data privacy PAIS 2015 55 / 61
Disclosure Risk > Distances Outline
M4-33 M4-28 M4-82 M5-38 M6-385 M6-853 d2W M 29.83 41.37 24.33 718.43 11.81 17.77 d2W Mm 3.43 6.26 2.26 190.75 4.34 6.72 d2CI 280.24 427.75 242.86 42, 731.22 24.17 87.43 d2CIm 155.07 441.99 294.98 4, 017.16 79.43 829.81 d2SBNC 32.04 2, 793.81 150.66 10, 592.99 13.65 14.11 d2SB 13.67 3, 479.06 139.59 169, 049.55 13.93 13.70
N: number of records; n: number of attributes d2W Mm d2CIm Additional n
i=1 pi = 1
µ(∅) = 0 Constraints pi > 0 µ(V ) = 1 µ(A) ≤ µ(B) when A ⊆ B µ(A) + µ(B) ≥ µ(A ∪ B) + µ(A ∩ B) Total Constr. N(N − 1) + N + 1 + n N(N − 1) + N + 2 + (n
k=2
n
k
k) + n
2
c Torra; Transparency data privacy PAIS 2015 56 / 61
Disclosure Risk > Distances Outline
Vicen¸ c Torra; Transparency data privacy PAIS 2015 57 / 61
Summary Outline
Vicen¸ c Torra; Transparency data privacy PAIS 2015 58 / 61
Disclosure Risk > Distances Outline
Vicen¸ c Torra; Transparency data privacy PAIS 2015 59 / 61
Summary Outline
∗ Special thanks to Jordi Nin, Daniel Abril, Guillermo Navarro-Arribas
Vicen¸ c Torra; Transparency data privacy PAIS 2015 60 / 61
Disclosure Risk > Distances Outline
Record Linkage, Information Fusion, in press.
disclosure risk assessment, Information Fusion 13:4 (2012) 274-284.
Knowledge Engineering, 67 (2008) 399-412.
Knowledge Engineering, 64:1 (2008) 346-364.
Vicen¸ c Torra; Transparency data privacy PAIS 2015 61 / 61