USENIX Security2025Top-tier venue
How Researchers De-Identify Data in Practice
Wentao Guo, Paige Pepitone, Adam J. Aviv, Michelle L. Mazurek
Abstract
Human-subjects researchers are increasingly expected to deidentify and publish data about research participants. However, de-identification is difficult, lacking objective solutions for how to balance privacy and utility, and requiring significant time and expertise. To understand researchers' approaches, we interviewed 18 practitioners who have deidentified data for publication and 6 curators who review data submissions for repositories and funding organizations. We find that researchers account for the kinds of risks described by k-anonymity, but they address them through manual and social processes and not through systematic assessments of risk across a dataset. This allows for nuance but may leave published data vulnerable to re-identification. We explore why researchers take this approach and highlight three main barriers to more rigorous de-identification: threats seem unrealistic, stronger standards are not incentivized or supported, and tools do not meet researchers' needs. We conclude with takeaways for repositories, funding agencies, and privacy experts.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Builds on20
- SoK: Privacy-Preserving Data SynthesisYuzheng Hu, Fan Wu, Qinbin Li, Yunhui Long et al.S&P 2024 · 61 citations
- Bounded and Unbiased Composite Differential PrivacyKai Zhang, Yanjun Zhang, Ruoxi Sun, Pei-Wei Tsai et al.S&P 2024 · 54 citations
- When the Weakest Link is Strong: Secure Collaboration in the Case of the Panama PapersSusan E. McGregor, Elizabeth Anne Watkins, Mahdi Nasrullah Al-Ameen, Kelly Caine et al.USENIX Security 2017 · 52 citations
- SoK: Differential Privacy as a Causal PropertyMichael Carl Tschantz, Shayak Sen, Anupam DattaS&P 2020 · 49 citations
- Don't Look at the Data! How Differential Privacy Reconfigures the Practices of Data ScienceJayshree Sarathy, Sophia Song, Audrey Haque, Tania Schlatter et al.CHI 2023 · 24 citations
Related papers
- A Qualitative Analysis of Practical De-Identification GuidesWentao Guo, Aditya Kishore, Adam J. Aviv, Michelle L. MazurekCCS 2024 · 1 citation
- Out of Sight, Out of Mind? Exploring Data Protection Practices for Personal Data in Usable Security & Privacy StudiesFlorin Martius, Luisa Jansen, Lukas Struck, Arthi Arumugam et al.CHI 2025 · 7 citations
- Diagnosing Bias in the Gender Representation of HCI Research Participants: How it Happens and Where We AreAnna Offenwanger, Alan John Milligan, Minsuk Chang, Julia Bullard et al.CHI 2021 · 51 citations
- It Shouldn't Be This Difficult: Researcher Perspectives on Diversity and Inclusion in Usable Privacy and Security ResearchPriyasha Chatterjee, Smirity Kaushik, Karola Marky, Yixin ZouCHI 2026 · 1 citation
- Assessing Anonymity Techniques Employed in German Court Decisions: A De-Anonymization ExperimentDominic Deuber, Michael Keuchen, Nicolas ChristinUSENIX Security 2023
