Privacy Inference Attacking And Prevention On Multiple Relative K-Anonymized Microdata Sets

Yalong Dong,Zude Li,Xiaojun Ye
DOI: https://doi.org/10.1007/978-3-540-78849-2_28
2008-01-01
Abstract:In k-anonymity modeling process, it is widely assumed that a relational table of microdata is published with a single sensitive attribute. This assumption is too simple and unreasonable. We observe that multiple sensitive attributes in one or more tables may incur privacy inference violations that are not visible tinder the single sensitive attribute assumption. In this paper, a new (k, l)-anonymity model is introduced beyond the existed e-diversity mechanism, which is an improved microdata publication model that can effectively prevent these multiple-attributed privacy violations. The (k, e)-anonymity process consists of two phases: k-anonymization on identifying attributes and e-diversity on sensitive attributes. The related (k, l)-anonymity algorithms are proposed and the data generalization metric is provided for minimizing the anonymization cost. A running example illustrates this technique in detail, which also convinces its effectiveness.
What problem does this paper attempt to address?