<  Retour au portail Polytechnique Montréal

Information theoretic-based privacy risk evaluation for data anonymization

Anis Bkakria, Frédéric Cuppens, Nora Boulahia Cuppens et Aimilia Tasidou

Article de revue (2021)

Document en libre accès dans PolyPublie et chez l'éditeur officiel
Affichage préliminaire
Libre accès au plein texte de ce document
Version officielle de l'éditeur
Conditions d'utilisation: Creative Commons: Attribution (CC BY)
Télécharger (1MB)
Afficher le résumé
Cacher le résumé


Aim: Data anonymization aims to enable data publishing without compromising the individuals’ privacy. The re- identification and sensitive information inference risks of a dataset are important factors in the decision-making pro- cess for the techniques and the parameters of the anonymization process. If correctly assessed, measuring the re- identification and inference risks can help optimize the balance between protection and utility of the dataset, as too aggressive anonymization can render the data useless, while publishing data with a high risk of de-anonymization is troublesome. Methods: In this paper, a new information theoretic-based privacy metric (ITPR) for assessing both the re-identification risk and sensitive information inference risk of datasets is proposed. We compare the proposed metric with existing information theoretic metrics and their ability to assess risk for various cases of dataset characteristics. Results: We show that ITPR is the only metric that can effectively quantify both re-identification and sensitive infor- mation inference risks. We provide several experiments to illustrate the effectiveness of ITPR. Conclusion: Unlike existing information theoretic-based privacy metrics, the ITPR metric we propose in this paper is, to the best of our knowledge, the first information theoretic-based privacy metric that allows correctly assessing both re-identification and sensitive information inference risks.

Mots clés

Data anonymization, identification risk, disclosure risk, information theoretic-based privacy metrics

Sujet(s): 2700 Technologie de l'information > 2700 Technologie de l'information
Département: Département de génie informatique et génie logiciel
URL de PolyPublie: https://publications.polymtl.ca/9466/
Titre de la revue: Journal of Surveillance, Security and Safety (vol. 2)
Maison d'édition: OAE Publishing Inc
DOI: 10.20517/jsss.2020.20
URL officielle: https://doi.org/10.20517/jsss.2020.20
Date du dépôt: 07 sept. 2023 12:01
Dernière modification: 25 sept. 2024 15:45
Citer en APA 7: Bkakria, A., Cuppens, F., Boulahia Cuppens, N., & Tasidou, A. (2021). Information theoretic-based privacy risk evaluation for data anonymization. Journal of Surveillance, Security and Safety, 2, 83-102. https://doi.org/10.20517/jsss.2020.20


Total des téléchargements à partir de PolyPublie

Téléchargements par année

Provenance des téléchargements


Actions réservées au personnel

Afficher document Afficher document