On the measurement of privacy as an attacker's estimation error

被引:30
作者
Rebollo-Monedero, David [1 ]
Parra-Arnau, Javier [1 ]
Diaz, Claudia [2 ]
Forne, Jordi [1 ]
机构
[1] Univ Politecn Cataluna, Dept Telemat Engn, ES-08034 Barcelona, Catalonia, Spain
[2] Katholieke Univ Leuven, ESAT SCD IBBT COSIC, B-3001 Louvain, Belgium
关键词
Privacy; Criteria; Metrics; Estimation; Bayes decision theory; Statistical disclosure control; Anonymous communication systems; Location-based services; K-ANONYMITY; FORMALIZATION;
D O I
10.1007/s10207-012-0182-5
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
A wide variety of privacy metrics have been proposed in the literature to evaluate the level of protection offered by privacy-enhancing technologies. Most of these metrics are specific to concrete systems and adversarial models and are difficult to generalize or translate to other contexts. Furthermore, a better understanding of the relationships between the different privacy metrics is needed to enable more grounded and systematic approach to measuring privacy, as well as to assist system designers in selecting the most appropriate metric for a given application. In this work, we propose a theoretical framework for privacy-preserving systems, endowed with a general definition of privacy in terms of the estimation error incurred by an attacker who aims to disclose the private information that the system is designed to conceal. We show that our framework permits interpreting and comparing a number of well-known metrics under a common perspective. The arguments behind these interpretations are based on fundamental results related to the theories of information, probability, and Bayes decision.
引用
收藏
页码:129 / 149
页数:21
相关论文
共 42 条
[1]   A SANDWICH PROOF OF THE SHANNON-MCMILLAN-BREIMAN THEOREM [J].
ALGOET, PH ;
COVER, TM .
ANNALS OF PROBABILITY, 1988, 16 (02) :899-909
[2]  
[Anonymous], 2006, 22 INT C DAT ENG WOR, DOI DOI 10.1109/ICDEW.2006.116
[3]  
[Anonymous], ACM Transactions on Information and System Security (TISSEC), DOI DOI 10.1145/290163.290168
[4]  
[Anonymous], 2002, Proc. of Privacy Enhancing Technologies (PET)
[5]  
[Anonymous], 1991, ELEMENTS INFORM THEO, DOI [DOI 10.1002/0471200611, 10.1002/0471200611]
[6]  
[Anonymous], 2001, Pattern Classification
[7]  
Bagai R, 2011, LECT NOTES COMPUT SC, V6794, P117, DOI 10.1007/978-3-642-22263-4_7
[8]  
Berger J.O., 1985, Statistical decision theory and Bayesian analysis, V2nd
[9]  
Berthold O., 2000, P DESIGNING PRIVACY, V2009, P30
[10]   UNTRACEABLE ELECTRONIC MAIL, RETURN ADDRESSES, AND DIGITAL PSEUDONYMS [J].
CHAUM, DL .
COMMUNICATIONS OF THE ACM, 1981, 24 (02) :84-88