3 ms·
>..."not possible to publish medical data in an anonymized fashion that does not infringe privacy rights". 1. Sometimes it is. 2. I already gave substantive r
by throwawayjava 8y ago
>..."not possible to publish medical data in an anonymized fashion that does not infringe privacy rights".
1. Sometimes it is.
2. I already gave substantive reasons why this will commonly occur in environmental medical research -- dense datasets about small populations that capture sensitive information about individuals.
> I do not see how it's takeway from that paper.
Because that's literally the only assumption in the adversarial model other than "access to the published dataset". And correlating with an auxiliary dataset is literally how all actual instantiations of this attack work.
> just sprinkle some private data on it, show it to IRB, they cry out "no, this can't be released, no way!" - and voila, you are safe from review.
1. My proposal doesn't say "IRB happened to say you can't publicly publish this one particular protocol." My proposal says that IRB explicitly judges that no such protocol exists.
2. IRBs are not that arbitrary and are themselves audited.
3. If you're this paranoid about intent, then you can't trust the research anyways. If the research is committing intentional fraud, they could just do it at the data collection step.
The way I see it, either:
A. Even if we can't trust individual scientists, we can more-or-less trust a broad subset of scientists with different and well-aligned motives (as in, a whole group of: the IRB board, the PI, the people reviewing the IRB board) when they say that data can't be shared for privacy reasons; or,
B. We should expect that literally dozens of scientists, all with different motives, will routinely and actively collude to commit wide-spread fraud.
If (A), my approach makes sense. If we max out paranoia and go with (B), then I don't know why we should trust the data regardless of whether it's published publicly...