Don't Be a Tattle-Tale: Preventing Leakages through Data Dependencies on Access Control Protected Data
Primal Pappachan, Shufan Zhang, Xi He, Sharad Mehrotra
Abstract
We study the problem of answering queries when (part of) the data may be sensitive and should not be leaked to the querier. Simply restricting the computation to non-sensitive part of the data may leak sensitive data through inference based on data dependencies. While inference control from data dependencies during query processing has been studied in the literature, existing solution either detect and deny queries causing leakage, or use a weak security model that only protects against exact reconstruction of the sensitive data. In this paper, we adopt a stronger security model based on full deniability that prevents any information about sensitive data to be inferred from query answers. We identify conditions under which full deniability can be achieved and develop an efficient algorithm that minimally hides non-sensitive cells during query processing to achieve full deniability. We experimentally show that our approach is practical and scales to increasing proportion of sensitive data, as well as, to increasing database size.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers2
- DProvDB: Differentially Private Query Processing with Multi-Analyst ProvenanceShufan Zhang, Xi HeSIGMOD 2024 · 10 citations
- Disclosure-Compliant Query AnsweringRudi Poepsel Lemaitre, Kaustubh Beedkar, Volker MarklSIGMOD 2025 · 1 citation
Builds on2
- One-sided Differential PrivacyIos Kotsogiannis, Stelios Doudalis, Samuel Haney, Ashwin Machanavajjhala et al.ICDE 2020 · 36 citations
- Sieve: A Middleware Approach to Scalable Access Control for Database Management SystemsPrimal Pappachan, Roberto Yus, Sharad Mehrotra, Johann-Christoph FreytagVLDB 2020
Related papers
- DP4SQL: Differentially Private SQL with Flexible Privacy PoliciesAndrew Cascio, KinChin Tong, Daniel Kifer, Zeyu Ding et al.CCS 2026
- Plaintext Recovery Against Post-Filtering Access ControlZachary Espiritu, David CashUSENIX Security 2026
- Forward and Backward Private Conjunctive Searchable Symmetric EncryptionSikhar Patranabis, Debdeep MukhopadhyayNDSS 2021
- Discovering Denial Constraints in Dynamic DatasetsEduardo H. M. Pena, Fábio Porto, Felix NaumannICDE 2024 · 2 citations
- Privacy Preserving Strong Simulation Queries on Large GraphsLyu Xu, Jiaxin Jiang, Byron Choi, Jianliang Xu et al.ICDE 2021 · 18 citations
