Re-identification Attack to Privacy-Preserving Data Analysis with Noisy Sample-Mean
Du Su, Hieu Tri Huynh, Ziao Chen, Yi Lu, Wenmiao Lu
Abstract
In mining sensitive databases, access to sensitive class attributes of individual records is often prohibited by enforcing field-level security, while only aggregate class-specific statistics are allowed to be released. We consider a common privacy-preserving data analytics scenario where only a noisy sample mean of the class of interest can be queried. Such practice is widely found in medical research and business analytics settings. This paper studies the hazard of re-identification of entire class caused by revealing a noisy sample mean of the class. With a novel formulation of the re-identification attack as a generalized positive-unlabeled learning problem, we prove that the risk function of the re-identification problem is closely related to that of learning with complete data. We demonstrate that with a one-sided noisy sample mean, an effective re-identification attack can be devised with existing PU learning algorithms. We then propose a novel algorithm, growPU, that exploits the unique property of sample mean and consistently outperforms existing PU learning algorithms on the re-identification task. GrowPU achieves re-identification accuracy of 93.6% on the MNIST dataset and 88.1% on an online behavioral dataset with noiseless sample mean. With noise that guarantees 0.01-differential privacy, growPU achieves 91.9% on the MNIST dataset and 84.6% on the online behavioral dataset.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Cited by top-tier papers1
Ask how each one uses itRelated papers
- In Differential Privacy, There is Truth: on Vote-Histogram Leakage in Ensemble Private LearningJiaqi Wang, Roei Schuster, Ilia Shumailov, David Lie et al.NeurIPS 2022 · 8 citations
- Robust and differentially private mean estimationXiyang Liu, Weihao Kong, Sham M. Kakade, Sewoong OhNeurIPS 2021 · 87 citations
- LDPRecover: Recovering Frequencies from Poisoning Attacks Against Local Differential PrivacyXinyue Sun, Qingqing Ye, Haibo Hu, Jiawei Duan et al.ICDE 2024 · 21 citations
- Encrypted Databases: New Volume Attacks against Range QueriesZichen Gui, Oliver Johnson, Bogdan WarinschiCCS 2019 · 97 citations
- Generate-then-Verify: Reconstructing Data from Limited Published StatisticsTerrance Liu, Eileen Xiao, Adam D. Smith, Pratiksha Thaker et al.S&P 2026
