USENIX Security '22 - Attacks on Deidentification's Defenses

USENIX Security '22 - Attacks on Deidentification's Defenses Aloni Cohen, University of Chicago Distinguished Paper Award Winner Quasi-identifier-based deidentification techniques (QI-deidentification) are widely used in practice, including k-anonymity, l-diversity, and t-closeness. We present three new attacks on QI-deidentification: two theoretical attacks and one practical attack on a real dataset. In contrast to prior work, our theoretical attacks work even if every attribute is a quasi-identifier. Hence, they apply to k-anonymity, l-diversity, t-closeness, and most other QI-deidentification techniques.First, we introduce a new class of privacy attacks called downcoding attacks, and prove that every QI-deidentification scheme is vulnerable to downcoding attacks if it is minimal and hierarchical. Second, we convert the downcoding attacks into powerful predicate singling-out (PSO) attacks, which were recently proposed as a way to demonstrate that a privacy mechanism fails to legally anonymize under Europe's General Data Protection Regulation. Third, we use LinkedIn.com to reidentify 3 students in a k-anonymized dataset published by EdX (and show thousands are potentially vulnerable), undermining EdX's claimed compliance with the Family Educational Rights and Privacy Act.The significance of this work is both scientific and political. Our theoretical attacks demonstrate that QI-deidentification may offer no protection even if every attribute is treated as a quasi-identifier. Our practical attack demonstrates that even deidentification experts acting in accordance with strict privacy regulations fail to prevent real-world reidentification. Together, they rebut a foundational tenet of QI-deidentification and challenge the actual arguments made to justify the continued use of k-anonymity and other QI-deidentification techniques. View the full USENIX Security '22 program at https://www.usenix.org/conference/use...

USENIX Security '22 - Birds of a Feather Flock Together: How Set Bias Helps to Deanonymize You
▶︎

USENIX Security '22 - Birds of a Feather Flock Together: How Set Bias Helps to Deanonymize You

Personal VPNs: Encryption Myths and Data Security Explained
▶︎

Personal VPNs: Encryption Myths and Data Security Explained

How to Hide in Plain Sight: Next-Level Digital Privacy | Ivan Banov at BSidesCache 2025
▶︎

How to Hide in Plain Sight: Next-Level Digital Privacy | Ivan Banov at BSidesCache 2025

The Anonymisation Problem - Computerphile
▶︎

The Anonymisation Problem - Computerphile

Passkeys Explained: Are They Actually Better Than Passwords?
▶︎

Passkeys Explained: Are They Actually Better Than Passwords?

S13 E17: Trump’s Reflecting Pool, Redistricting & Soaps: 6/28/26: Last Week Tonight with John Oliver
▶︎

S13 E17: Trump’s Reflecting Pool, Redistricting & Soaps: 6/28/26: Last Week Tonight with John Oliver

The Professor Who Taught People How To Think (1962)
▶︎

The Professor Who Taught People How To Think (1962)

The Big Short (2015): The Jenga Scene – Explaining the Financial Collapse
▶︎

The Big Short (2015): The Jenga Scene – Explaining the Financial Collapse

I Investigated The World's Skinniest vs Fattest City
▶︎

I Investigated The World's Skinniest vs Fattest City

The French Do Not Care About Work
▶︎

The French Do Not Care About Work

Cybersecurity Expert Answers Hacking History Questions | Tech Support | WIRED
▶︎

Cybersecurity Expert Answers Hacking History Questions | Tech Support | WIRED

LAWYER: If Cops Ask "Where Are You Coming From?" - Say These Words
▶︎

LAWYER: If Cops Ask "Where Are You Coming From?" - Say These Words

Is the AfD a threat to Germany? Mehdi Hasan & Maximilian Krah | Head to Head
▶︎

Is the AfD a threat to Germany? Mehdi Hasan & Maximilian Krah | Head to Head

Understand AI in 14 minutes – with Anthropic's Chloe Lubinski [ARC 2026]
▶︎

Understand AI in 14 minutes – with Anthropic's Chloe Lubinski [ARC 2026]

She’s 12. She Sings Aretha Franklin… Until Simon TELLS Her to Do It Acapella! 😳
▶︎

She’s 12. She Sings Aretha Franklin… Until Simon TELLS Her to Do It Acapella! 😳

When Stupid Cops Mess With FBI Agent
▶︎

When Stupid Cops Mess With FBI Agent

How To Think SO CLEARLY People Assume You're A Genius
▶︎

How To Think SO CLEARLY People Assume You're A Genius

Keynote: After the AI Hype – What’s Real, and What’s Next - Richard Campbell - 2026
▶︎

Keynote: After the AI Hype – What’s Real, and What’s Next - Richard Campbell - 2026

Golden Retriever Meets Completely Broken Rescue for the First Time
▶︎

Golden Retriever Meets Completely Broken Rescue for the First Time

JANITOR vs THE BIGGEST GUYS IN THE GYM. They Didn’t Expect THAT
▶︎

JANITOR vs THE BIGGEST GUYS IN THE GYM. They Didn’t Expect THAT