课题基金 / 基金详情

A Risk Management Framework for Identifiability in Genomics Research

A Risk Management Framework for Identifiability in Genomics Research
基因组学研究中可识别性的风险管理框架
批准号:
9360125
负责人:
Bradley A. Malin
金额:
$24.96万
依托单位国家:
美国
项目类别:
财政年份:
2012
资助国家:
美国
项目状态:
已结题
起止时间:
2012-09-21 至 2020-07-31

项目摘要

项目成果

Bradley A. Malin的其他基金

相似基金

相关文献

中文摘要
翻译
在过去的十年里,见证了无数的例证,基因组数据可以追溯到 相应的具名个人。这些攻击利用了各种收集,包括美国国立卫生研究院数据库 基因类型和表型(DBGaP)、1000基因组计划和全球联盟的灯塔计划 对于基因组学和健康,并经常在流行媒体上报道。与此同时,进行了研究 在这笔赠款的第一阶段(从2012-2016年)显示,这种重新识别攻击通常是最糟糕的- 情况下,不可泛化的情况。具体地说,据显示,这些攻击往往侧重于 进攻--而不是它的概率,因为在实践中经常起作用的因素很多。通过专注于 有可能,这样的调查可能会让政策制定者认为,去身份识别是一项无用的活动。 然而,我们的研究表明,消除身份识别只是一个更大的威慑战略的一部分,可以 被用来管理风险。通过智能地将去身份识别与其他技术风险缓解相结合 方法(例如,受控访问)和社会结构(例如,数据使用协议和惩罚)、基因组 数据共享解决方案的开发可以为科学家和社会带来适当水平的风险和效用。而当 我们的研究为管理基因组数据共享中的识别风险奠定了基础,重要问题 继续将其转化为实际指导意见。特别是,风险管理模型必须 专门针对共享的数据类型、可用的惩罚类型以及 采用和管理威慑机制。因此,在这个研究项目的第二阶段,我们 建议加强基于风险的重新识别管理框架,以模拟和评估威慑力 由现有存储库调用的方法,如DBGaP(保存较小历史记录的集合 来自已完成研究的数据集),以及新出现的倡议,如“精确医学倡议”。这 该项目将追求三个具体目标,旨在和谐地工作,但同时又足够独立 如果失败,这项研究仍将为基因组数据库提供卓有成效的风险管理指导:1)开发 评估基因组数据共享中不同细节层次的重新识别攻击的博弈论模型 (例如,在关联研究中病例组与对照组的变异比例的汇总);2) 描述和衡量与以下项目的常见重新识别威慑方法相关的成本 基因组数据(例如,IT系统使用的实物调查审查和虚拟审计);以及3)优化 威慑政策的参数化(例如,违反数据使用协议的损害赔偿额或 向攻击者/调查者隐瞒数据的时间量)给定基因组数据的预期价值。 我们将使用大量未识别的基因组和电子医学数据库来评估这些方法 一个大型学术医疗中心正在使用的记录,两个联邦储存库托管的数据集,以及一个网络系统 这提供了9000名参与者的汇总统计数据。
英文摘要
The past decade has witnessed numerous demonstrations that genomic data can be traced back to the corresponding named individuals. These attacks exploit various collections, including the NIH Database of Genotypes and Phenotypes (dbGaP), the 1000 Genomes Project, and the Beacon Project of the Global Alliance for Genomics and Health, and are often reported in the popular media. At the same time, research conducted in the first phase of this grant (from 2012-2016) showed that such re-identification attacks often represent worst- case, non-generalizable scenarios. Specifically, it was shown that these attacks often focus on the possibility of attack - and not its probability given the wide range of factors often at play in practice. By focusing on the possible, such investigations can lead policy makers to believe that de-identification is a useless activity. However, our research showed that de-identification is only one part of a larger strategy of deterrents that can be used to manage risk. By intelligently combining de-identification with other technical risk mitigation approaches (e.g., controlled access) and societal constructs (e.g., data use agreements and penalties), genomic data sharing solutions can be developed with appropriate levels of risk and utility for scientists and society. While our research laid the foundation for managing identification risk in genomic data sharing, significant questions remain regarding its translation into practical guidance. In particular, risk management models must be specialized to the type of data that is shared, the types of penalties (or punishments) available, and the costs of adopting and administering deterrence mechanisms. Thus, in the second phase of this research project, we propose to augment risk-based re-identification management frameworks to model and assess the deterrence approaches invoked by existing repositories, such as dbGaP (which holds a collection of smaller historical datasets from completed studies), as well as emerging initiatives, such as the Precision Medicine Initiative. This project will pursue three specific aims, designed to work in harmony, but at the same time sufficiently independent that if one fails, the research will still yield fruitful risk management guidance for genomic databases: 1) Develop game theoretic models to assess re-identification attacks at different levels of detail in genomic data sharing (e.g., aggregate summaries of the proportion of variants in case vs. control groups in association studies); 2) Characterize and measure the costs associated with common re-identification deterrence approaches for genomic data (e.g., physical investigatory reviews and virtual audits of IT system use); and 3) Optimize the parameterization of a deterrence policy (e.g., the amount of damages for violation of a data use agreement or the amount of time to withhold data from an attacker/investigator) given the expected value of genomic data. We will evaluate these approaches with a large repository of de-identified genomic and electronic medical records in use at a large academic medical center, datasets hosted at two federal repositories, and a web system that presents summary statistics from a cohort of 9000 participants.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
Ethics Core (FABRIC)
  • 批准号:
    10662376
  • 项目类别:
  • 资助金额:
    $121.72万
  • 财政年份:
    2023
  • 负责人:
    Bradley A. Malin
  • 依托单位:
Ethics Core (FABRIC)
A Risk Management Framework for Identifiability in Genomics Research
  • 批准号:
    8695427
  • 项目类别:
  • 资助金额:
    $34.3万
  • 财政年份:
    2012
  • 负责人:
    Bradley A. Malin
  • 依托单位:
A Risk Management Framework for Identifiability in Genomics Research
海外基金