Database Reconstruction Is Not So Easy and Is Different from Reidentification

Journal of Official Statistics, Forthcoming

14 Pages Posted: 26 Jan 2023

See all articles by Krish Muralidhar

Krish Muralidhar

University of Oklahoma

Josep Domingo-Ferrer

Rovira i Virgili University; Universitat Rovira i Virgili

Date Written: January 24, 2023

Abstract

In recent years, it has been claimed that releasing accurate statistical information on a database is likely to allow its complete reconstruction. Differential privacy has been suggested as the appropriate methodology to prevent these attacks. These claims have recently been taken very seriously by the U.S. Census Bureau and led them to adopt differential privacy for releasing U.S. Census data. This in turn has caused consternation among users of the Census data due to the lack of accuracy of the protected outputs. It has also brought legal action against the U.S. Department of Commerce. In this paper, we trace the origins of the claim that releasing information on a database automatically makes it vulnerable to being exposed by reconstruction attacks and we show that this claim is, in fact, incorrect. We also show that reconstruction can be averted by properly using traditional statistical disclosure control (SDC) techniques. We further show that the geographic level at which exact counts are released is even more relevant to protection than the actual SDC method employed. Finally, we caution against confusing reconstruction and re-identification: using the quality of reconstruction as a metric of re-identification results in exaggerated re-identification risk figures.

Keywords: Database Privacy, Database Reconstruction, Statistical Disclosure Control, Differential Privacy

Suggested Citation

Muralidhar, Krish and Domingo-Ferrer, Josep, Database Reconstruction Is Not So Easy and Is Different from Reidentification (January 24, 2023). Journal of Official Statistics, Forthcoming, Available at SSRN: https://ssrn.com/abstract=4336757 or http://dx.doi.org/10.2139/ssrn.4336757

Krish Muralidhar (Contact Author)

University of Oklahoma ( email )

307 W Brooks
Norman, OK 73019
United States

Josep Domingo-Ferrer

Rovira i Virgili University ( email )

Campus Sescelades, Carretera de Valls s/n
43006 Tarragona, Tarragona 43007
Spain

Universitat Rovira i Virgili ( email )

Tarragona
Spain
43007 (Fax)

Do you have a job opening that you would like to promote on SSRN?

Paper statistics

Downloads
186
Abstract Views
845
Rank
334,550
PlumX Metrics