arXiv:2508.15850cs.CRcs.LG2025-08被引 6

公开心电图数据易被关联攻击识破身份,即使攻击者信息有限。

Linkage Attacks Expose Identity Risks in Public ECG Data Sharing

  • 基于部分已知信息模拟真实攻击,评估心电图隐私风险。
  • 85%准确率可重识别公众数据中个体,误分类率14.2%。
  • 揭示简单匿名化无效,适合医疗数据共享安全研究者。

公开共享的心电图(ECG)数据因具备生物特征属性,存在严重隐私风险,易受关联攻击。与以往假设攻击者拥有理想能力的研究不同,本文在攻击者仅具备部分知识的现实条件下评估隐私风险。利用来自109名参与者、涵盖多种真实数据集的样本,所提方法在公开数据集中实现85%的重识别准确率,最优置信度阈值下整体误分类率为14.2%,其中15.6%的未知个体被误判为已知,12.8%的已知个体被误判为未知。结果表明,即便攻击者信息有限,仍可有效进行身份关联,凸显简单匿名化手段无法防范重识别风险。研究强调亟需采用差分隐私、访问控制和加密计算等隐私保护策略,在保障医疗数据可用性的同时降低身份暴露风险。

原文摘要 · Abstract (English)

The increasing availability of publicly shared electrocardiogram (ECG) data raises critical privacy concerns, as its biometric properties make individuals vulnerable to linkage attacks. Unlike prior studies that assume idealized adversarial capabilities, we evaluate ECG privacy risks under realistic conditions where attackers operate with partial knowledge. Using data from 109 participants across diverse real-world datasets, our approach achieves 85% accuracy in re-identifying individuals in public datasets while maintaining a 14.2% overall misclassification rate at an optimal confidence threshold, with 15.6% of unknown individuals misclassified as known and 12.8% of known individuals misclassified as unknown. These results highlight the inadequacy of simple anonymization techniques in preventing re-identification, demonstrating that even limited adversarial knowledge enables effective identity linkage. Our findings underscore the urgent need for privacy-preserving strategies, such as differential privacy, access control, and encrypted computation, to mitigate re-identification risks while ensuring the utility of shared biosignal data in healthcare applications.

心电图隐私关联攻击差分隐私

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。