32
DH09 Plausible Adversaries in Re-Identification Risk Assessment Lukasz Kniola Biogen, Maidenhead, UK

Plausible Adversaries Re-Identification Risk AssessmentDisclaimer The scope of this presentation is to present the opinions and suggestions of the author. The interpretations of standards

  • Upload
    others

  • View
    2

  • Download
    0

Embed Size (px)

Citation preview

Page 1: Plausible Adversaries Re-Identification Risk AssessmentDisclaimer The scope of this presentation is to present the opinions and suggestions of the author. The interpretations of standards

DH09

Plausible Adversaries

in

Re-Identification Risk Assessment

Lukasz KniolaBiogen, Maidenhead, UK

Page 2: Plausible Adversaries Re-Identification Risk AssessmentDisclaimer The scope of this presentation is to present the opinions and suggestions of the author. The interpretations of standards

Disclaimer

The scope of this presentation is to present the opinions and suggestions of the author. The interpretations of standards and procedures presented are those of the author and are not necessarily correct. Any views, conclusions and recommendations are those of the author, and they do not represent the positions of their employer.

Page 3: Plausible Adversaries Re-Identification Risk AssessmentDisclaimer The scope of this presentation is to present the opinions and suggestions of the author. The interpretations of standards

Agenda

. Context

. Methodology

. Survey

. Trends and Outlooks

Page 4: Plausible Adversaries Re-Identification Risk AssessmentDisclaimer The scope of this presentation is to present the opinions and suggestions of the author. The interpretations of standards

Adversaries

Possible Plausible

Page 5: Plausible Adversaries Re-Identification Risk AssessmentDisclaimer The scope of this presentation is to present the opinions and suggestions of the author. The interpretations of standards

Context Of Data Release

Public Release

Internal Secondary Research (Data Re-use)

External Secondary Research

Page 6: Plausible Adversaries Re-Identification Risk AssessmentDisclaimer The scope of this presentation is to present the opinions and suggestions of the author. The interpretations of standards

Direct Relation No Relation

Classification (1/2)

Family

Acquaintances

Doctors

Employers

Academic Research

Regulatory Bodies

Other Sponsors

Hackers (Demostration

Attacks)

Lawyers

InsuranceCompanies

JournalistsPatients

Themselves

Page 7: Plausible Adversaries Re-Identification Risk AssessmentDisclaimer The scope of this presentation is to present the opinions and suggestions of the author. The interpretations of standards

Classification (2/2)

Adversary’s Background Knowledge

Likely / Unlikely

Target of Re-id:Specific / Random

Adversary KnowsTarget is in Data Set?

Definitely / Doubtfully

Page 8: Plausible Adversaries Re-Identification Risk AssessmentDisclaimer The scope of this presentation is to present the opinions and suggestions of the author. The interpretations of standards

Prosecutor Journalist Marketer

Page 9: Plausible Adversaries Re-Identification Risk AssessmentDisclaimer The scope of this presentation is to present the opinions and suggestions of the author. The interpretations of standards

Prosecutor

Page 10: Plausible Adversaries Re-Identification Risk AssessmentDisclaimer The scope of this presentation is to present the opinions and suggestions of the author. The interpretations of standards

Prosecutor

Matching Person To Record

Page 11: Plausible Adversaries Re-Identification Risk AssessmentDisclaimer The scope of this presentation is to present the opinions and suggestions of the author. The interpretations of standards

Journalist

Page 12: Plausible Adversaries Re-Identification Risk AssessmentDisclaimer The scope of this presentation is to present the opinions and suggestions of the author. The interpretations of standards

Journalist

Person To Record?

Matching Record To Person

Page 13: Plausible Adversaries Re-Identification Risk AssessmentDisclaimer The scope of this presentation is to present the opinions and suggestions of the author. The interpretations of standards

Prosecutor Journalist Marketer≥ ≥

Page 14: Plausible Adversaries Re-Identification Risk AssessmentDisclaimer The scope of this presentation is to present the opinions and suggestions of the author. The interpretations of standards

Maximum and AveraGE risk

0.50

Page 15: Plausible Adversaries Re-Identification Risk AssessmentDisclaimer The scope of this presentation is to present the opinions and suggestions of the author. The interpretations of standards

UniQueness in the data set

Page 16: Plausible Adversaries Re-Identification Risk AssessmentDisclaimer The scope of this presentation is to present the opinions and suggestions of the author. The interpretations of standards

Harm ≠ Risk

Identity Disclosure

VS

Attribute Disclosure

Intent To Harm &

Potential Harm

Page 17: Plausible Adversaries Re-Identification Risk AssessmentDisclaimer The scope of this presentation is to present the opinions and suggestions of the author. The interpretations of standards

Survey 23 Responders

6 Questions12 Adversary categories

Testing perceived:MotivationMeans/ToolsBackground knowledgeIntent to harm

Likelyhood of knowing:Target in the data setFull list of trial participants

Page 18: Plausible Adversaries Re-Identification Risk AssessmentDisclaimer The scope of this presentation is to present the opinions and suggestions of the author. The interpretations of standards
Page 19: Plausible Adversaries Re-Identification Risk AssessmentDisclaimer The scope of this presentation is to present the opinions and suggestions of the author. The interpretations of standards
Page 20: Plausible Adversaries Re-Identification Risk AssessmentDisclaimer The scope of this presentation is to present the opinions and suggestions of the author. The interpretations of standards
Page 21: Plausible Adversaries Re-Identification Risk AssessmentDisclaimer The scope of this presentation is to present the opinions and suggestions of the author. The interpretations of standards
Page 22: Plausible Adversaries Re-Identification Risk AssessmentDisclaimer The scope of this presentation is to present the opinions and suggestions of the author. The interpretations of standards
Page 23: Plausible Adversaries Re-Identification Risk AssessmentDisclaimer The scope of this presentation is to present the opinions and suggestions of the author. The interpretations of standards
Page 24: Plausible Adversaries Re-Identification Risk AssessmentDisclaimer The scope of this presentation is to present the opinions and suggestions of the author. The interpretations of standards
Page 25: Plausible Adversaries Re-Identification Risk AssessmentDisclaimer The scope of this presentation is to present the opinions and suggestions of the author. The interpretations of standards

Survey

Page 26: Plausible Adversaries Re-Identification Risk AssessmentDisclaimer The scope of this presentation is to present the opinions and suggestions of the author. The interpretations of standards
Page 27: Plausible Adversaries Re-Identification Risk AssessmentDisclaimer The scope of this presentation is to present the opinions and suggestions of the author. The interpretations of standards
Page 28: Plausible Adversaries Re-Identification Risk AssessmentDisclaimer The scope of this presentation is to present the opinions and suggestions of the author. The interpretations of standards

Journalist RiskMaximum

Prosecutor RiskAverage

Prosecutor RiskAverage

Journalist RiskMaximum

Survey - Conclusions

Page 29: Plausible Adversaries Re-Identification Risk AssessmentDisclaimer The scope of this presentation is to present the opinions and suggestions of the author. The interpretations of standards

EMA Policy 0070Guidance

Demonstration Attack

Participants of Public Interest

Embarrass Data Controller or Process

Acquaintance Recognition

Vulnerable Patients & Sensitive Info

Maximum Risk Across All Records

Page 30: Plausible Adversaries Re-Identification Risk AssessmentDisclaimer The scope of this presentation is to present the opinions and suggestions of the author. The interpretations of standards

Easier to Defend

Easier to Apply

More Conservative

Lower Data Utility

Prosecutor

EMA Policy 0070Trends

Page 31: Plausible Adversaries Re-Identification Risk AssessmentDisclaimer The scope of this presentation is to present the opinions and suggestions of the author. The interpretations of standards

Greater Detail Retention

Higher Data Utility

Requires:

Better Guidelines

Define „Similar Studies”

More Evidence

Journalist

EMA Policy 0070Outlook

Page 32: Plausible Adversaries Re-Identification Risk AssessmentDisclaimer The scope of this presentation is to present the opinions and suggestions of the author. The interpretations of standards

Thank You

Questions?

[email protected]