A game theoretic framework for analyzing re-identification risk.

A game theoretic framework for analyzing re-identification risk.
复制标题

DOI:
10.1371/journal.pone.0120592
复制
发表时间:
2015
期刊:
影响因子:
3.7
通讯作者:
Malin BA
Malin BA
中科院分区:
综合性期刊3区
文献类型:
--
作者:
Wan Z;Vorobeychik Y;Xia W;Clayton EW;Kantarcioglu M;Ganta R;Heatherly R;Malin BA

文献摘要

参考文献

相似文献

鉴于大数据库可以提供对个人数据的潜在洞察力,许多组织的目标是通过共享去识别数据来共享数据,同时保护隐私,但由于各种演示表明这些数据可以重新识别,因此感到担忧。然而,这些调查的重点是如何实施攻击,而不是攻击实现的可能性。本文介绍了一个博弈论框架,该框架使出版商能够平衡重新识别风险与共享数据的价值,并利用一个自然假设,即接收者只有在潜在收益大于成本时才会尝试重新识别。我们将该框架应用于一个真实的案例研究,其中数据对出版商的价值是来自国家赞助商的实际赠款资金金额,而收件人的重新识别收益是因违反联邦隐私规则而支付给监管机构的罚款。有三个值得注意的发现:1)可以实现零风险,因为接收者永远不会从重新识别中获益,同时共享几乎与允许少量风险的最佳解决方案一样多的数据; 2)零风险解决方案能够共享比美国健康保险便携性和责任法案(HIPAA)的常用去识别政策更多的数据;以及3)敏感性分析表明这些发现对于玩家损失和收益的数量级变化是稳健的。结合起来,这些研究结果提供了支持,这样的框架可以使务实的政策决定去识别数据共享。
Given the potential wealth of insights in personal data the big databases can provide, many organizations aim to share data while protecting privacy by sharing de-identified data, but are concerned because various demonstrations show such data can be re-identified. Yet these investigations focus on how attacks can be perpetrated, not the likelihood they will be realized. This paper introduces a game theoretic framework that enables a publisher to balance re-identification risk with the value of sharing data, leveraging a natural assumption that a recipient only attempts re-identification if its potential gains outweigh the costs. We apply the framework to a real case study, where the value of the data to the publisher is the actual grant funding dollar amounts from a national sponsor and the re-identification gain of the recipient is the fine paid to a regulator for violation of federal privacy rules. There are three notable findings: 1) it is possible to achieve zero risk, in that the recipient never gains from re-identification, while sharing almost as much data as the optimal solution that allows for a small amount of risk; 2) the zero-risk solution enables sharing much more data than a commonly invoked de-identification policy of the U.S. Health Insurance Portability and Accountability Act (HIPAA); and 3) a sensitivity analysis demonstrates these findings are robust to order-of-magnitude changes in player losses and gains. In combination, these findings provide support that such a framework can enable pragmatic policy decisions about de-identified data sharing.
DOI: 10.1073/pnas.1006155107
发表时间: 2010-12-28
影响因子: 11.1
作者:
Crandall, David J.;Backstrom, Lars;Kleinberg, Jon
通讯作者: Kleinberg, Jon
DOI: 10.1126/science.1229566
发表时间: 2013-01-18
期刊: SCIENCE
影响因子: 56.9
作者:
Gymrek, Melissa;McGuire, Amy L.;Erlich, Yaniv
通讯作者: Erlich, Yaniv
DOI: 10.1038/srep01376
发表时间: 2013
期刊: SCIENTIFIC REPORTS
影响因子: 4.6
作者:
de Montjoye, Yves-Alexandre;Hidalgo, Cesar A.;Verleysen, Michel;Blondel, Vincent D.
通讯作者: Blondel, Vincent D.
DOI: 10.1371/journal.pone.0028071
发表时间: 2011
期刊: PloS one
影响因子: 3.7
作者:
El Emam K;Jonker E;Arbuckle L;Malin B
通讯作者: Malin B
DOI: 10.1136/jamia.2009.000026
发表时间: 2010-03-01
影响因子: 6.4
作者:
Benitez, Kathleen;Malin, Bradley
通讯作者: Malin, Bradley