arXiv:2508.04542cs.LGcs.CR2025-08被引 1

通过分析5000+真实数据泄露案例,构建个人身份信息风险图谱。

Privacy Risk Predictions Based on Fundamental Understanding of Personal Data and an Evolving Threat Landscape

  • 基于5000+真实案例构建身份信息图谱,揭示数据暴露的关联关系。
  • 利用图神经网络预测某条数据泄露后引发其他泄露的概率。
  • 帮助用户和组织识别高风险数据,适合安全防护与隐私管理使用。

缺乏对相对隐私风险的根本理解,使得个人和组织难以有效保护个人信息。本研究分析了超过5000起真实的身份盗用与欺诈案例,识别出被暴露的个人数据类型、暴露频率及其后果。我们构建了一个身份生态系统图(Identity Ecosystem graph),其中节点代表个人身份信息(PII)属性,边表示它们之间的实证披露关系(如某一PII属性因另一属性泄露而暴露)。基于该图结构,我们开发了一种隐私风险预测框架,采用图论与图神经网络来估算当特定PII属性被泄露时,引发其他泄露的可能性。结果表明,该方法能有效回答核心问题:某一身份属性的披露是否可能引致另一属性的披露。相关代码已开源:https://github.com/niu-haoran/Privacy-Risk-Predictions-and-UTCID-Identity-Ecosystem.git。

原文摘要 · Abstract (English)

It is difficult for individuals and organizations to protect personal information without a fundamental understanding of relative privacy risks. By analyzing over 5,000 empirical identity theft and fraud cases, this research identifies which types of personal data are exposed, how frequently such exposures occur, and what the consequences of those exposures are. We construct an Identity Ecosystem graph - a foundational, graph-based model in which nodes represent personally identifiable information (PII) attributes and edges represent empirical disclosure relationships between them (e.g., one PII attribute is exposed due to the exposure of another). Leveraging this graph structure, we develop a privacy risk prediction framework that uses graph theory and graph neural networks to estimate the likelihood of further disclosures when certain PII attributes are compromised. The results show that our approach effectively addresses the core question: Can the disclosure of a given identity attribute possibly lead to the disclosure of another attribute? The code for the privacy risk prediction framework is available at: https://github.com/niu-haoran/Privacy-Risk-Predictions-and-UTCID-Identity-Ecosystem.git.

隐私风险图神经网络数据泄露

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。