vix.ing · top · new · best · stats · spec

New Directions in Anonymization: Permutation Paradigm, Verifiability by\n Subjects and Intruders, Transparency to Users

2015/01/17 by Domingo-Ferrer, Josep, Krishnamurty Muralidhar, Muralidhar, Krishnamurty
Computer Science · Social Sciences · #47N30 #94-XX #Cryptography and Data Security #Cryptography and Security (cs.CR) #Databases (cs.DB) #FOS: Computer and information sciences #H.2.8 #K.4.1 #Privacy, Security, and Data Protection #Privacy-Preserving Technologies in Data

paper · pdf · doi:10.48550/arxiv.1501.04186

openalex publication_date 2015/01/17 · openalex created_date 2025/10/10 · openalex updated_date 2026/07/28

Abstract

There are currently two approaches to anonymization: "utility first" (use an\nanonymization method with suitable utility features, then empirically evaluate\nthe disclosure risk and, if necessary, reduce the risk by possibly sacrificing\nsome utility) or "privacy first" (enforce a target privacy level via a privacy\nmodel, e.g., k-anonymity or epsilon-differential privacy, without regard to\nutility). To get formal privacy guarantees, the second approach must be\nfollowed, but then data releases with no utility guarantees are obtained. Also,\nin general it is unclear how verifiable is anonymization by the data subject\n(how safely released is the record she has contributed?), what type of intruder\nis being considered (what does he know and want?) and how transparent is\nanonymization towards the data user (what is the user told about methods and\nparameters used?).\n We show that, using a generally applicable reverse mapping transformation,\nany anonymization for microdata can be viewed as a permutation plus (perhaps) a\nsmall amount of noise; permutation is thus shown to be the essential principle\nunderlying any anonymization of microdata, which allows giving simple utility\nand privacy metrics. From this permutation paradigm, a new privacy model\nnaturally follows, which we call (d,v)-permuted privacy. The privacy ensured by\nthis method can be verified by each subject contributing an original record\n(subject-verifiability) and also at the data set level by the data protector.\nWe then proceed to define a maximum-knowledge intruder model, which we argue\nshould be the one considered in anonymization. Finally, we make the case for\nanonymization transparent to the data user, that is, compliant with Kerckhoff's\nassumption (only the randomness used, if any, must stay secret).\n

Related