Expanding the attack surface: robust profiling attacks threaten the privacy of sparse behavioral data
File(s)sciadv.abl6464.pdf (1.26 MB)
Published version
Author(s)
Tournier, Arnaud
de Montjoye, Yves-Alexandre
Type
Journal Article
Abstract
Behavioral data, collected from our daily interactions with technology, have driven scientific advances. Yet, the collection and sharing of this data raise legitimate privacy concerns, as individuals can often be re-identified. Current identification attacks however
require auxiliary information to roughly match the information available in the dataset,
limiting their applicability. We here propose an entropy-based profiling model to learn
time-persistent profiles. Using auxiliary information about a single target collected over
a non-overlapping time period, we show that individuals are correctly identified 79% of
the time in a large location dataset of 0.5M individuals, and 65.2% for a grocery shopping
dataset of 85, 000 individuals. We further show that accuracy only slowly decreases over
time and that the model is robust to state-of-the-art noise addition. Our results show
that much more auxiliary information than previously believed can be used to identify
individuals, challenging de-identification practices and what currently constitutes legally
anonymous data.
require auxiliary information to roughly match the information available in the dataset,
limiting their applicability. We here propose an entropy-based profiling model to learn
time-persistent profiles. Using auxiliary information about a single target collected over
a non-overlapping time period, we show that individuals are correctly identified 79% of
the time in a large location dataset of 0.5M individuals, and 65.2% for a grocery shopping
dataset of 85, 000 individuals. We further show that accuracy only slowly decreases over
time and that the model is robust to state-of-the-art noise addition. Our results show
that much more auxiliary information than previously believed can be used to identify
individuals, challenging de-identification practices and what currently constitutes legally
anonymous data.
Date Issued
2022-08-19
Date Acceptance
2022-06-03
Citation
Science Advances, 2022, 33 (33), pp.1-11
ISSN
2375-2548
Publisher
American Association for the Advancement of Science
Start Page
1
End Page
11
Journal / Book Title
Science Advances
Volume
33
Issue
33
Copyright Statement
© 2022
The Authors, some
rights reserved;
exclusive licensee
American Association
for the Advancement
of Science. No claim to
original U.S.Government
Works. Distributed
under a Creative
Commons Attribution
License 4.0 (CC BY).
The Authors, some
rights reserved;
exclusive licensee
American Association
for the Advancement
of Science. No claim to
original U.S.Government
Works. Distributed
under a Creative
Commons Attribution
License 4.0 (CC BY).
License URL
Identifier
https://www.science.org/doi/full/10.1126/sciadv.abl6464
Publication Status
Published
Date Publish Online
2022-08-19