USENIX Security2022Top-tier venue
Attacks on Deidentification's Defenses
Aloni Cohen
Abstract
Quasi-identifier-based deidentification techniques (QI-deidentification) are widely used in practice, including -anonymity, -diversity, and -closeness. We present three new attacks on QI-deidentification: two theoretical attacks and one practical attack on a real dataset. In contrast to prior work, our theoretical attacks work even if every attribute is a quasi-identifier. Hence, they apply to -anonymity, -diversity, -closeness, and most other QI-deidentification techniques. First, we introduce a new class of privacy attacks called downcoding attacks, and prove that every QI-deidentification scheme is vulnerable to downcoding attacks if it is minimal and hierarchical. Second, we convert the downcoding attacks into powerful predicate singling-out (PSO) attacks, which were recently proposed as a way to demonstrate that a privacy mechanism fails to legally anonymize under Europe's General Data Protection Regulation. Third, we use LinkedIn.com to reidentify 3 students in a -anonymized dataset published by EdX (and show thousands are potentially vulnerable), undermining EdX's claimed compliance with the Family Educational Rights and Privacy Act. The significance of this work is both scientific and political. Our theoretical attacks demonstrate that QI-deidentification may offer no protection even if every attribute is treated as a quasi-identifier. Our practical attack demonstrates that even deidentification experts acting in accordance with strict privacy regulations fail to prevent real-world reidentification. Together, they rebut a foundational tenet of QI-deidentification and challenge the actual arguments made to justify the continued use of -anonymity and other QI-deidentification techniques.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 6dcc9f7d-7fd7-4a88-be70-d59370ad4379Cited by top-tier papers11
- SoK: Privacy-Preserving Data SynthesisYuzheng Hu, Fan Wu, Qinbin Li, Yunhui Long et al.S&P 2024 · 61 citations
- A Linear Reconstruction Approach for Attribute Inference Attacks against Synthetic DataMeenatchi Sundaram Muthu Selva Annamalai, Andrea Gadotti, Luc RocherUSENIX Security 2024 · 37 citations
- On the Risks of Collecting Multidimensional Data Under Local Differential PrivacyHéber Hwang Arcolezi, Sébastien Gambs, Jean-François Couchot, Catuscia PalamidessiVLDB 2023 · 22 citations
- Large-scale online deanonymization with LLMsSimon Lermen, Daniel Paleka, Joshua Swanson, Michael Aerni et al.USENIX Security 2026 · 20 citations
- SoK: Technical Implementation and Human Impact of Internet Privacy RegulationsEleanor Birrell, Jay Rodolitz, Angel Ding, Jenna Lee et al.S&P 2024 · 11 citations
Related papers
- Privacy-preserving datasets of eye-tracking samples with applications in XRBrendan David-John, Kevin R. B. Butler, Eakta JainIEEE VR 2023 · 35 citations
- Targeted Deanonymization via the Cache Side Channel: Attacks and DefensesMojtaba Zaheri, Yossi Oren, Reza CurtmolaUSENIX Security 2022
- Re-identification Attack to Privacy-Preserving Data Analysis with Noisy Sample-MeanDu Su, Hieu Tri Huynh, Ziao Chen, Yi Lu et al.KDD 2020 · 12 citations
- Differential Privacy and Swapping: Examining De-Identification's Impact on Minority Representation and Privacy Preservation in the U.S. CensusMiranda Christ, Sarah Radway, Steven M. BellovinS&P 2022 · 23 citations
- Exposing Privacy Risks in Anonymizing Clinical Data: Combinatorial Refinement Attacks on k-Anonymity Without Auxiliary InformationSomiya Chhillar, Mary K. Righi, Rebecca E. Sutter, Evgenios M. KornaropoulosCCS 2025
