匿名数据集隐私保护效果度量机制
网络出版日期: 2024-11-16
基金资助
国家重点研发计划项目(2021YFB3100400)
版权
Measurement the effect of anonymization techniques over databases
Online published: 2024-11-16
Copyright
当前,数据拥有者通常需要将自己收集到的数据交予其他机构进行数据分析或向公众发布。为了防止用户隐私信息的泄露,在发布或共享数据前,往往需要对数据进行匿名处理,达到一定隐私保护程度后才可安全发布。因此衡量发布数据的隐私保护水平是一项重要的研究内容。由于在以往的研究中,缺少足够通用的方案,不能对发布数据的隐私保护水平进行精确度量。因此提出了一种度量发布数据隐私保护程度方法,该方法主要通过条件熵与互信息,度量出数据处理前后的差异值,在此基础上基于互信息和联合熵融合得到具体的隐私保护效果,最终输出一个0~1范围的数值精确表示发布数据的隐私保护水平。将该方法应用到真实的数据集中,在匿名处理数据集使其满足常用的隐私模型后,分别度量不同隐私模型下数据各个属性的隐私保护水平,证明了所提方法的有效性。
臧帅 , 朱友文 . 匿名数据集隐私保护效果度量机制[J]. 网络空间安全科学学报, 2024 , 2(3) : 67 -78 . DOI: 10.20172/j.issn.2097-3136.240306
Nowadays, data owners often need to provide the data they have collected to other organizations for data analysis. To prevent the leakage of users' private information, data is typically anonymized before being published or shared, ensuring a certain level of privacy protection. Therefore, measuring the privacy protection level of published data is an important research topic. In previous studies, there has been a lack of sufficiently general methods to accurately measure the privacy protection level of published data. A method to measure the privacy protection level of published data was proposed. The method primarily uses conditional entropy and mutual information to measure the difference between the data before and after processing. The results are then substituted into a formula to obtain an accurate privacy protection level, ultimately calculating a number between 0 and 1 to precisely indicate the privacy protection level of the data. Finally, this method was applied to real datasets. After anonymizing the datasets to meet commonly used privacy models, the privacy protection level of each attribute was measured under different privacy models, thereby demonstrating the practicality of the method.
Key words: anonymity; privacy; information entropy; conditional entropy; mutual information
表 1 原始数据Table 1 Raw Data |
| 序号 | 邮政编码 | 年龄 | 薪资 | 疾病 |
| 1 | 29 | gastric ulcer | ||
| 2 | 22 | gastritis | ||
| 3 | 27 | stomach cancer | ||
| 4 | 43 | gastritis | ||
| 5 | 52 | flu | ||
| 6 | 47 | bronchitis | ||
| 7 | 30 | bronchitis | ||
| 8 | 36 | pneumonia | ||
| 9 | 32 | stomach cancer |
表 2 匿名数据Table 2 Anonymous Data |
| 序号 | 邮政编码 | 年龄 | 薪资 | 疾病 |
| 1 | gastric ulcer | |||
| 2 | gastritis | |||
| 3 | stomach cancer | |||
| 4 | gastritis | |||
| 5 | flu | |||
| 6 | bronchitis | |||
| 7 | bronchitis | |||
| 8 | pneumonia | |||
| 9 | stomach cancer |
表 3 数据集的信息Table 3 Information on the dataset |
| 序号 | 类型 | 属性 | 不同值数量 | 符号 |
| 1 | 索引 | 识别符 | ||
| 2 | 年龄 | 准识别符 | 74 | |
| 3 | 工作类型 | 准识别符 | 8 | |
| 4 | 教育程度 | 敏感属性 | 16 | |
| 5 | 母国国籍 | 敏感属性 | 41 | |
| 6 | 职业 | 准识别符 | 14 | |
| 7 | 种族 | 准识别符 | 5 | |
| 8 | 性别 | 准识别符 | 2 | |
| 9 | 薪资 | 准识别符 | 2 | |
| 10 | 婚姻状况 | 准识别符 | 7 | |
| 11 | – | 不敏感属性 | – |
| 1 |
FUNG B CM, WANG K, CHEN R, et al. Privacy-preserving data publishing: A survey of recent developments[J]. ACM Computing Surveys (Csur), 2010, 42 (4): 1- 53.
|
| 2 |
KANWAL T, ANJUM A, MALIK S U R, et al. A robust privacy preserving approach for electronic health records using multiple dataset with multiple sensitive attributes[J]. Computers & Security, 2021, 105, 102224.
|
| 3 |
SWEENEY L. Statement before the privacy and integrity advisory committee of the department of homeland security[J]. Dept. Homeland Security,2005.
|
| 4 |
BERTINO E,LIN D,JIANG W. A survey of quantification of privacy preserving data mining algorithms[J]. Privacy-Preserving Data Mining:Models and Algorithms,2008:183-205.
|
| 5 |
CHEN B C,LEFEVRE K,RAMASKRISHNAN R. Privacy skyline:Privacy with multidimensional adversarial knowledge[R]. University of Wisconsin-Madison Department of Computer Sciences,2007.
|
| 6 |
SWEENEY L. K-anonymity: A model for protecting privacy[J]. International Journal of Uncertainty, Fuzziness and Knowledge-based Systems, 2002, 10 (5): 557- 570.
|
| 7 |
ZHOU KY, YANG YX, QIAO Y, et al. Mixstyle neural networks for domain generalization and adaptation[J]. International Journal of Computer Vision, 2024, 132(3): 822-836.
|
| 8 |
LI N,LI T,Venkatasubramanian S. T-closeness:Privacy beyond k-anonymity and l-diversity[C]//2007 IEEE 23rd international conference on data engineering. IEEE,2006:106-115.
|
| 9 |
MACHANAVAJJHALA A, KIFER D, GEHRKE J, et al. l-diversity: Privacy beyond k-anonymity[J]. Acm Transactions on Knowledge Discovery From Data (tkdd), 2007, 1 (1): 3- es.
|
| 10 |
EVFIMIEVSKI A,GEHRKE J,SRIKANT R. Limiting privacy breaches in privacy preserving data mining[C]//Proceedings of the twenty-second ACM SIGMOD-SIGACT-SIGART symposium on Principles of database systems,2003:211-222.
|
| 11 |
ZHANG Y, ZHU Y, Zhou Y, et al. Frequency estimation mechanisms under ϵδ-utility-optimized local differential privacy[J]. IEEE Transactions on Emerging Topics in Computing, 2023, 12(1): 316-327.
|
| 12 |
GHINITA G,KALNIS P,SKIADOPOULOS S. PRIVE:Anonymous location-based queries in distributed mobile systems[C]//Proceedings of the 16th international conference on World Wide Web,2007:371-380.
|
| 13 |
DWORK C. Differential privacy[C]//International Colloquium on Automata,Languages,and Programming. Berlin,Heidelberg:Springer Berlin Heidelberg,2006:1-12.
|
| 14 |
GRUTESER M,GRUNWALD D. Anonymous usage of location-based services through spatial and temporal cloaking[C]//Proceedings of the 1st International Conference on Mobile Systems,Applications and Services,2003:31-42.
|
| 15 |
ZHU YW,SONG QM,LUO YL. Differentially private top-k flows estimation mechanism in network traffic,IEEE Transactions on Network Science and Engineering,2024,11(3) 2462-2472
|
| 16 |
ISSA I, KAMATH S, WAGNER A B. An operational measure of information leakage[C]//2016 Annual Conference on Information Science and Systems (CISS). IEEE, 2016: 234-239.
|
| 17 |
SONDECK L P, LAURENT M, FREY V. Discrimination rate: an attribute-centric metric to measure privacy[J]. Annals of Telecommunications, 2017, 72, 755- 766.
|
| 18 |
SADHYA D, CHAKRABORT B. Quantifying the effects of anonymization techniques over micro-databases[J]. IEEE Transactions on Emerging Topics in Computing, 2022, 10 (4): 1979- 1992.
|
| 19 |
LI N,LI T,VENKATASUBRAMANIAN S. T-closeness:Privacy beyond k-anonymity and l-diversity. [C]// 2007 IEEE 23rd International Conference on Data Engineering,IEEE,2007:106–115.
|
| 20 |
ZHU YW, CAO YR , XUE Q, et al. Heavy hitter identification over large-domain set-valued data with local differential privacy[J]. IEEE Transactions on Information Forensics and Security, 2024, 19: 414-426.
|
| 21 |
SAMARATI P, SWEENEY L .Protecting privacy when disclosing information:k- anonymity and its enforcement through generalization and suppression. Technical repor[J]. SRI International,1998.
|
| 22 |
DWORK C,MCSHERRY F,NISSIM K,et al. Calibrating noise to sensitivity in private data analysis[C]//Theory of Cryptography:Third Theory of Cryptography Conference,2006:265-284.
|
| 23 |
MCSHERRY F T K. Mechanism design via differential privacy//Proceeding soft the 48th Annual IEEE Symposium on Foundations of Computer Science[J]. IEEE Computer Society, 2007, 94, 103.
|
| 24 |
SANKAR L, RAJAGOPALAR S R, POOR H V. Utility-privacy tradeoffs in databases: An information-theoretic approach[J]. IEEE Transactions on Information Forensics and Security, 2013, 8 (6): 838- 852.
|
| 25 |
KOLMOGOROV A. On the Shannon theory of information transmission in the case of continuous signals[J]. IRE Transactions on Information Theory, 2016, 2 (4): 102- 108.
|
| 26 |
MOHIT R R V, KATOCH S, VANJARE A, et al. Classification of complex UCI datasets using machine learning algorithms using hadoop[J]. International Journal of Computer Science and Software Engineering, 2015, 4 (7): 190- 198.
|
| 27 |
PRASSER F,KOHLMAYER F. Putting statistical disclosure control into practice:The ARX data anonymization tool[J]. Medical Data Privacy Handbook,2015:111-148.
|
| 28 |
DI VIMERCATI S D C, FORESTI S, LIVRAGA G, et al. K-anonymity: From theory to applications[J]. Transcation on Data Privacy, 2023, 16 (1): 25- 49.
|
/
| 〈 |
|
〉 |