Tanja Sarcevic

dblp:221/5764 · DBLP profile ↗
← Back
2ranked-venue papers in the field
2as first author
2since 2021 · last 2023
0000-0003-0896-9193ORCID · reported

Domains — venue-derived; a paper can count in several

Big Data, Cloud & Distributed Data Systems · 2 (2 first)
YearPublicationVenuePosition
2023 Achieving Privacy and Tracing Unauthorised Usage: Anonymisation-based Fingerprinting of Private Data
abstract
Since many types of data nowadays contain personally identifiable information about individuals, it is important to apply privacy protection techniques to mitigate disclosure risks. One approach is k-anonymity, where hiding the identity within a group of k similar entities reduces the risk of re-identification. Another risk when distributing data is the loss of control over their further re-distribution and sharing. This risk is frequently addressed by fingerprinting, a method that allows to identify the recipient of a specific copy of the data, by embedding a generally invisible mark.In this paper, we specifically implement and adapt an intrinsic fingerprint scheme that makes use of k-anonymity and the fact that multiple, differently perturbed versions of a dataset can be found that all fulfil a certain k-anonymity, and share a rather similar level of data precision. Thus, these different datasets can be seen each as a fingerprinted version of the original.One research question we address in this paper is the evaluation of the most common generalisation algorithms according to their generalisation strategy and their influence on data utility and the number of resulting release candidates, i.e. fingerprints and execution time. In addition, we investigate the properties and robustness of these fingerprints against intentional (adversarial) manipulation through attack simulations. We further provide recommendations and guidelines on how fingerprinting can be best achieved based on the results of our evaluation.
Tanja Sarcevic, Rudolf Mayer, Philipp Adler
IEEE Big Data1
2022 Adaptive Attacks and Targeted Fingerprinting of Relational Data
abstract
Fingerprinting is a method of embedding a traceable mark into digital data to (i) verify the owner and (ii) identify the recipient of a released copy of a data set. This is crucial when releasing data to third parties, especially if it involves a fee, or if the data is of sensitive nature and further sharing and leaks should be discouraged and deterred from. A fingerprint is required to (i) be robust against modifications t o t he d ata to achieve successful ownership protection, while (ii) affecting the quality and utility of the data as little as possible.So far, literature mostly assumes attackers with rather limited capabilities who perform random modification t o t he dataset. With a certain task in mind to perform on the data, the attacker can however perform an adaptive and targeted attack that maximises its chances of removing or invalidating the fingerprint, while reducing the data utility the least. In the same line, the data owner can optimise the robustness of the scheme by anticipating a specific f ocus o f t he a ttacker a nd f ocusing t he fingerprint embedding on the most valuable parts of the data. In this paper, we, therefore, provide an in-depth discussion on threat models, targeted attacks and adaptive defences. We further demonstrate the impact of targeted attacks on classical and, in comparison, adaptive fingerprinting i n a n e mpirical manner.
Tanja Sarcevic, Rudolf Mayer, Andreas Rauber
IEEE Big Data1