提出可直接使用的匿名数据重识别风险评估方法
Practical and Ready-to-Use Methodology to Assess the re-identification Risk in Anonymized Datasets
- 采用网络安全领域成熟的风险分析方法,兼顾攻击能力与个体影响
- 首次对属性及其值进行暴露程度分级,聚焦真实攻击常靶向的类型
- 适合数据隐私合规团队快速落地使用
为证明数据集已充分匿名,许多隐私政策建议开展重识别风险评估,但未提供具体方法,导致行业缺乏实践指引。本文提出一种实用且可直接应用的重识别风险评估方法,其原创性体现在:(1)首次采用网络安全领域长期使用的风险分析方法(如EBIOS),不仅评估攻击可行性,还考量攻击对个体造成的实际影响;(2)首次对属性及属性值按暴露程度进行分类,因现实攻击通常集中于特定类型属性而非所有信息。该方法为数据匿名化合规提供了可操作的框架。
原文摘要 · Abstract (English)
To prove that a dataset is sufficiently anonymized, many privacy policies suggest that a re-identification risk assessment be performed, but do not provide a precise methodology for doing so, leaving the industry alone with the problem. This paper proposes a practical and ready-to-use methodology for re-identification risk assessment, the originality of which is manifold: (1) it is the first to follow well-known risk analysis methods (e.g. EBIOS) that have been used in the cybersecurity field for years, which consider not only the ability to perform an attack, but also the impact such an attack can have on an individual; (2) it is the first to qualify attributes and values of attributes with e.g. degree of exposure, as known real-world attacks mainly target certain types of attributes and not others.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。