arXiv:2409.10986cs.DBcs.AI2024-09被引 1

通过流程树重构业务流程,可能泄露原始日志中的敏感信息。

Control-flow Reconstruction Attacks on Business Process Models

  • 设计多种回放策略,从流程树还原控制流
  • 在真实数据集上验证,重构结果与原始日志高度相似
  • 首次实证揭示流程模型发布带来的隐私风险,适合关注流程安全的研究者

流程模型可由包含实际业务流程数据的事件日志自动生成。尽管这些模型泛化了特定执行实例的控制流,但通常还附带行为统计信息,如执行频率。一旦模型公开,外部方就可能据此重建原始流程执行的某些细节,从而获取业务流程的机密信息。本文首次基于真实数据对这类重构攻击进行实证研究。我们提出了多种回放策略,从流程树中重构控制流,可能利用频率标注信息。为评估此类攻击的成功率及模型发布带来的风险,我们在多个真实世界数据集上将重构的流程执行结果与原始日志进行对比。

原文摘要 · Abstract (English)

Process models may be automatically generated from event logs that contain as-is data of a business process. While such models generalize over the control-flow of specific, recorded process executions, they are often also annotated with behavioural statistics, such as execution frequencies.Based thereon, once a model is published, certain insights about the original process executions may be reconstructed, so that an external party may extract confidential information about the business process. This work is the first to empirically investigate such reconstruction attempts based on process models. To this end, we propose different play-out strategies that reconstruct the control-flow from process trees, potentially exploiting frequency annotations. To assess the potential success of such reconstruction attacks on process models, and hence the risks imposed by publishing them, we compare the reconstructed process executions with those of the original log for several real-world datasets.

流程挖掘隐私安全重构攻击

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。