conference-paper

A study of the privacy perspective on principal component analysis via a realistic attack model

Research footprint

At a glance

الاستشهادات
2
المراجع
7
Comments
0
Paper overview

Abstract

Anonymization methods based on principal component analysis (PCA), one of dimensionality reduction methods, have been well studied. These combine PCA with noise addition. Some of these methods theoretically guarantee privacy but decrease utility because of noise addition. Chen et al. proposed a PCA-based privacy-enhancing method adding noise to com-pressed data and assumed an attack model for privacy evaluation where an attacker can obtain the transformation matrix used to transform the original data matrix into the compressed data matrix. However, it is not always possible for an attacker to obtain the transformation matrix in practice. To the best of our knowledge, there is no study about privacy of the regular PCA. In this study, we propose an attack model for PCA that restricts the information that the attacker can obtain, and under this model, we perform an attack on plain PCA, which doesn't add noise. We conducted experiments to see how our model affects privacy. We evaluated privacy using Re-identification Attack, in which an attacker tries to link records in compressed data to corresponding records in original data. We found that the accuracy of the attack was significantly lower than when using the usual model while keeping the utility high. These results suggest that PCA can sufficiently protect privacy when a realistic attacker is assumed in the proposed model.

Record transparency

Publication details

DOI
10.1109/cis58238.2022.00085
OpenAlex
W4362709149
Document type
conference-paper
Language
EN
Last metadata update
المجتمع

Comments

تسجيل الدخول للانضمام إلى النقاش.

  1. لا توجد تعليقات بعد. ابدأ النقاش.