4 ms·
There is a (famous) quote from Cynthia Dwork, who is most likely the key researcher behind differential privacy: "De-identified data isn’t". You can either re-
by TrailMixRaisin 5y ago
There is a (famous) quote from Cynthia Dwork, who is most likely the key researcher behind differential privacy: "De-identified data isn’t".
You can either re-identify the people behind the data or you alter it that strong that it becomes useless for meaningful applications.
- nradov 5y agoDe-identified data can still be quite useful for some types of research. If you strip away every field of personally identifiable information except, let's say, sex and birth year, there's no way to do meaningful re-identification.
- rscho 5y agoThis is wrong. Rare diagnoses are the simplest case of reidentification, but there are many many other opportunities. There's a whole field of research about that.
- specialist 5y agoDitto time and sequence (order). For example, online movie reviews were deanon simply by correlating viewing history with order reviews were posted.
- tmearnest 5y agoDates and times are generally deidentified by choosing a random initial date and changing subsequent timestamps to the random initial plus the duration between visits. The sequence and delays could potentially be used to identify patients, but this would be a lot harder than having absolute timestamps.
- specialist 5y agoTotally. I recently had a crazy notion for losslessly scrambling the sequence as well. Mostly for protecting voter privacy (order in which ballots are cast). One of the major blockers to fully digital voting. I haven't found any hits using terms like "cryptographic timestamps." Surely I can't be the first.
- seoaeu 5y agoVoter privacy for digital voting doesn't solve much. It doesn't seem to be possible to both cryptographically prove to a voter that their vote was counted correctly (integrity) while simultaneously preventing them from being at risk of coercion to share who they voted for (privacy).
- specialist 5y agoTotally. I remain 100% opposed. "Cryptographic timestamps" would only solve one of the many blockers. Sadly, others will continue to push their harebrained ideas. One thing I learned as an activist is that offense beats defense. Meaning it's easier to promote a correct solution than oppose all the bad solutions. So if a digital equivalent of the Australian Ballot system (private voting, public counting) exists, I better find it.
- TrailMixRaisin 5y agoI am sorry, but your answer is nearly the exact textbook example how wrong most people are with their intuition. In 2000 Latanya Sweeney showed that 87% of Americans can be identified by Sex, Birthday and Zip-Code. As other commenters point out, the connection to external databases is extremely powerful and dangerous to privacy. There are other concept in research to still use this data in research like differential privacy or using KI to synthesize data according to training data provided. But so far all concepts that tried to alter and then publish a datasets directly for research failed miserably.
- giovannibonetti 5y agoThe parent comment mentioned birth year, not birthday
- ghaff 5y agoIn fairness, the parent did just say Birth Year and Sex while Latanya Sweeney used the identifiers you list which give quite a bit more information. I agree with your basic point though that data that appears to be anonymized can frequently be de-anonymized--at least to some degree of statistical certainty to a degree that most would find surprising.
- prepend 5y agoBirthday is super different than year of birth. And zip code is really precise. GP said sex and year of birth that are usually perfectly fine for deidentification assuming some basic k-anonymity and l-diversity protections. It’s frustrating when people bring up examples of reidentification out of data that were not properly reidentified in the first place. Hopefully no one competent would think that having unique records based on sex, dob, and zip code are makes data deidentified. This is usually the case of someone not actually deidentified. The bigger risk, I think, is when you have some threshold of at least 10 records sharing sex, year of birth and still iding individuals.
- jfrunyon 5y agoSure, sex and year of birth alone are fine. Why do you assume they won't be able to use the medical data to further de-anonymize it? "Male, 1993, records are from a hospital in Central Texas so he lives there, who has posted on social media about conditions x, y and z" would probably turn up... me.
- alasdair_ 5y agoAll information is potentially personally identifiable. For example, perhaps you take data on favorite movies and strip away every bit of PII except sex and birth year (as you stated). Now let’s say I take the stripped data and target some facebook ads to people of a specific sex and birth year and have the ad be for people who love a certain obscure movie, doubling down on a second obscure movie and so on. Eventually I could have a reasonable chance of determining which other movies a unique individual may like based on the stripped data. Obviously irrelevant for movies, but more relevant for prescription drug uses, sexual preferences etc. The point is that with enough outside data available, even data stripped of PII can be de-anonimized.
- specialist 5y ago> "De-identified data isn’t" People don't yet have intuition about this. I still don't even know how to articulate it. Here's a stab: "With enough data collected, you can uniquely identify people by ruling out everyone else." Mid 2000s, Seisent was helping law enforcement solve cold cases using big data. In layperson's terms, they'd narrow the list of suspects by ruling out everyone who has a solid alibi. At the time, that was achieved by building profiles of everyone, living and dead, simply by compiling 1600 publicly available datasets. Like court records and mortgages and whatnot. Today you'd include location tracking, social media, all financial tracking, etc. It's remarkable that any crime goes unsolved. Like the back log of rape test kits, it's only because no one cares enough to bother to look.
- pokot0 5y agoJust playing akinator once will help giving an intuition about this.
- MaxBarraclough 5y agoWeb version of Akinator. [0] Pretty neat. Pity about the site's high CPU usage. [0] https://en.akinator.com/ https://en.akinator.com/
- Banana699 5y agoI thought of John Kennedy the first time, took the game about 55 questions to get to it, it didn't until it knew that he was a US president, was assassinated (as far as I know only Lincoln and Kennedy meet those two criteria together) AND that he lived in the 20th century, so it couldn't even rule out Lincoln. Next game I thought of Cameron Diaz, the game simply gave up after the 25th question or so. It's a pretty neat idea overall, reminds me of those link-following competitions using Wikipedia where you have to start from a topic and get to another completely unrelated topic solely by recursively chasing links. They both exploit the interconnected nature of our culture, a question (or an article) about a recent TV show providing a clue (or a link) about a pretty unrelated historical character. The game desperately needs some notion of statistical proximity though, it kept asking whether the character was an actor even after knowing he is a president, it doesn't do _any_ kind of deduction on what it already knows, just mad slash-and-dash till it gets the identifying info.
- miej 5y agore-identification is basically the same as browser fingerprinting. with enough vaguely stochastic variables, you can uniquely identify pretty much anyone