4.8 Article

Interaction data are identifiable even across long periods of time

Journal

NATURE COMMUNICATIONS
Volume 13, Issue 1, Pages -

Publisher

NATURE PORTFOLIO
DOI: 10.1038/s41467-021-27714-6

Keywords

-

Funding

  1. Imperial College London's Department of Computing
  2. Oxford-Man Institute of Quantitative Finance

Ask authors/readers for more resources

In this study, a behavioral profiling attack model is proposed to re-identify individuals in anonymous datasets based on the stability of their interaction networks over time. The results show that the learned profiles are stable and can identify individuals even after a certain period of time.
Large amounts of interaction data are collected by messaging apps, mobile phone carriers, and social media. Cretu et al. propose a behavioral profiling attack model and show that the stability of people's interaction networks over time can allow individuals to be re-identified in interaction datasets. Fine-grained records of people's interactions, both offline and online, are collected at large scale. These data contain sensitive information about whom we meet, talk to, and when. We demonstrate here how people's interaction behavior is stable over long periods of time and can be used to identify individuals in anonymous datasets. Our attack learns the profile of an individual using geometric deep learning and triplet loss optimization. In a mobile phone metadata dataset of more than 40k people, it correctly identifies 52% of individuals based on their 2-hop interaction graph. We further show that the profiles learned by our method are stable over time and that 24% of people are still identifiable after 20 weeks. Our results suggest that people with well-balanced interaction graphs are more identifiable. Applying our attack to Bluetooth close-proximity networks, we show that even 1-hop interaction graphs are enough to identify people more than 26% of the time. Our results provide strong evidence that disconnected and even re-pseudonymized interaction data can be linked together making them personal data under the European Union's General Data Protection Regulation.

Authors

I am an author on this paper
Click your name to claim this paper and add it to your profile.

Reviews

Primary Rating

4.8
Not enough ratings

Secondary Ratings

Novelty
-
Significance
-
Scientific rigor
-
Rate this paper

Recommended

No Data Available
No Data Available