A new privacy-preserving approach for publishing periodical reporting systems data
摘要
Spontaneous reporting systems (SRSs) are widely used to collect adverse drug events, which are released periodically for detection and analysis of adverse drug reactions (ADRs). SRS data need to be anonymized before being released, because it is closely related to the privacy of individuals. Data publishing methods can protect privacy while guaranteeing information utility of released data. Unfortunately, traditional data publishing methods are unsuitable for SRS data due to its special features. Moreover, prior methods for periodical SRS data publishing are vulnerable in practice. These schemes oversimplify an individual’s trajectory, which is the pattern of appearance of individual information across periods. Consequently, an attacker’s background knowledge is limited to only a few trajectories, resulting in significant underestimation. To explore these privacy issues, we analyze and formalize an adversary’s background knowledge, presenting six new privacy attacks aimed at SRS data in this paper. Relationships between these known attacks are analyzed, and we point out that previous SRS data publishing methods are susceptible to the new attacks. To address this very issue, we develop a new periodical SRS data publishing method by slicing and integrating individual information from different periods. Simultaneously, to preserve the utility of released tables, the records with similar quasi-identifier attribute values and trajectories are incorporated into the same group, and the remaining information is transmitted to the next release window. Theoretic analysis shows that our method can provide better protection than previous methods, and information utility can be guaranteed. The experimental results on real datasets also demonstrate that the new method improves privacy protection significantly and can thwart various known attacks. Interestingly, our method also has a little improvement in information utility compared with previous methods. Our method is suitable for the scenario that makes great demands on privacy protection while providing the guaranteed strength of ADR signals.