k-anonymity:: A model for protecting privacy

被引:4715
作者
Sweeney, L [1 ]
机构
[1] Carnegie Mellon Univ, Sch Comp Sci, Pittsburgh, PA 15213 USA
关键词
data anonymity; data privacy; re-identification; data fusion; privacy;
D O I
10.1142/S0218488502001648
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Consider a data holder, such as a hospital or a bank, that has a privately held collection of person-specific, field structured data. Suppose the data holder wants to share a version of the data with researchers. How can a data holder release a version of its private data with scientific guarantees that the individuals who are the subjects of the data cannot be re-identified while the data remain practically useful? The solution provided in this paper includes a formal protection model named k-anonymity and a set of accompanying policies for deployment. A release provides k-anonymity protection if the information for each person contained in the release cannot be distinguished from at least k-l individuals whose information also appears in the release. This paper also examines re-identification attacks that can be realized on releases that adhere to k-anonymity unless accompanying policies are respected. The k-anonymity protection model is important because it forms the basis on which the real-world systems known as Datafly, mu-Argus and k-Similar provide guarantees of privacy protection.
引用
收藏
页码:557 / 570
页数:14
相关论文
共 24 条
  • [1] [Anonymous], 1982, CRYPTOGRAPHY DATA SE, DOI DOI 10.5555/539308
  • [2] [Anonymous], 1996, 3 INT SEM STAT CONF
  • [3] *CAMBR VOT LIST DA, 1997, CIT CAMBR
  • [4] DALENIUS T, 1986, J OFF STAT, V2, P329
  • [5] Denning D. E., 1987, Proceedings of the 1987 IEEE Symposium on Security and Privacy (Cat. No.87CH2416-6), P220
  • [6] Denning D. E., 1979, ACM Transactions on Database Systems, V4, P76, DOI 10.1145/320064.320069
  • [7] DUNCAN G, 1991, STAT SCI MAY
  • [8] DUNCAN G, 1991, P 1991 IEEE S RES SE
  • [9] FELLEGI I, 1972, J AM STAT ASSOC, P7
  • [10] GARVEY T, 1991, IEEE COMP SEC FDN WO, V4