Andrei Kazlouski

dblp:286/5792 · DBLP profile ↗
← Back
2ranked-venue papers
1as first author
2since 2021 · last 2022
0000-0002-2880-1403ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 2 · 1 first-author · 2 since 2021
YearPublicationVenuePosition
2022 What your Fitbit Says about You: De-anonymizing Users in Lifelogging Datasets
abstract
Recently, there has been a significant surge of lifelogging experiments, where the activity of few participants\nis monitored for a number of days through fitness trackers. Data from such experiments can be aggregated\nin datasets and released to the research community. To protect the privacy of the participants, fitness datasets\nare typically anonymized by removing personal identifiers such as names, e-mail addresses, etc. However,\nalthough seemingly correct, such straightforward approaches are not sufficient. In this paper we demonstrate\nhow an adversary can still de-anonymize individuals in lifelogging datasets. We show that users’ privacy can\nbe compromised by two approaches: (i) through the inference of physical parameters such as gender, height,\nand weight; and/or (ii) via the daily routine of participants. Both methods rely solely on fitness data such as\nsteps, burned calories, and covered distance to obtain insights on the users in the dataset. We train several\ninference models, and leverage them to de-anonymize users in public lifelogging datasets. Between our two\napproaches we achieve 93.5% re-identification rate of participants. Furthermore, we reach 100% success rate\nfor people with highly distinct physical attributes (e.g., very tall, overweight, etc.).
Andrei Kazlouski, Thomas Marchioro, Evangelos P. Markatos
SECRYPT1
2021 User Identification from Time Series of Fitness Data
abstract
We explore the threat posed by disclosure of personal fitness information collected by wearable devices. In\nparticular, we study a scenario where an attacker has a list of aggregated records produced by a group of users,\nwhich are stored as time series of steps and calories. We introduce a machine learning-based approach to\nidentify one target person in the aggregated data while being in possession of other records from that person.\nWe estimate how accurately an attacker can find the target’s data when aggregated with other users by testing\nour approach on two public datasets. Our results show that personal fitness data possess identifying capabilities\nthat should be accounted when they are shared or disclosed.
Thomas Marchioro, Andrei Kazlouski, Evangelos P. Markatos
SECRYPT2