Achieving k-anonymity privacy protection using generalization and suppression

Achieving k-anonymity privacy protection using generalization and suppression
复制标题

DOI:
10.1142/s021848850200165x
复制
发表时间:
2002-10-01
影响因子:
1.5
通讯作者:
Sweeney, L
Sweeney, L
中科院分区:
计算机科学4区
文献类型:
--
作者:
Sweeney, L

文献摘要

被引文献

相似文献

通常,数据持有者(例如医院或银行)需要以无法确定数据主体的个人身份的方式共享特定于个人的记录。实现此目的的一种方法是让已发布的记录遵守 k-匿名性,这意味着每个已发布的记录在该版本中至少有 (k-l) 个其他记录,这些记录的值与出现在外部数据中的字段不明确。因此,k-匿名性通过保证每个发布的记录将与至少 k 个个人相关来提供隐私保护,即使这些记录直接链接到外部信息。本文正式介绍了结合泛化和抑制来实现 k-匿名性。泛化涉及用不太具体但语义一致的值替换(或重新编码)值。抑制涉及根本不释放值。优选最小泛化算法(MinGen)是本文提出的理论算法,它结合了这些技术以提供具有最小失真的k-匿名保护。将现实世界的算法 Datafly 和 mu-Argus 与 MinGen 进行比较。 Datafly 和 mu-Argus 都使用启发式方法进行近似,因此它们并不总是能产生最佳结果。结果表明,Datafly 可能会过度扭曲数据,而 mu-Argus 也可能无法提供足够的保护。
Often a data holder, such as a hospital or bank, needs to share person-specific records in such a way that the identities of the individuals who are the subjects of the data cannot be determimed. One way to achieve this is to have the released records adhere to k-anonymity, which means each released record has at least (k-l) other records in the release whose values are indistinct over those fields that appear in external data. So, k-anonymity provides privacy protection by guaranteeing that each released record will relate to at least k individuals even if the records are directly linked to external information. This paper provides a formal presentation of combining generalization and suppression to achieve k-anonymity. Generalization involves replacing (or recoding) a value with a less specific but semantically consistent value. Suppression involves not releasing a value at all. The Preferred Minimal Generalization Algorithm (MinGen), which is a theoretical algorithm presented herein, combines these techniques to provide k-anonymity protection with minimal distortion. The real-world algorithms Datafly and mu-Argus are compared to MinGen. Both Datafly and mu-Argus use heuristics to make approximations, and so, they do not always yield optimal results. It is shown that Datafly can over distort data and mu-Argus can additionally fail to provide adequate protection.