De-identificatie of anonimisering van persoonlijke gegevens met SDC-technologie
De legitimiteit van datagedreven onderzoek en het succes van data-intensieve toepassingen zoals machine learning en andere AI technieken zijn sterk afhankelijk van de bescherming van de privacy bij het ontwerpen, realiseren, inzetten en onderhouden van deze studies en systemen. Daarom is het belangrijk om enkele maatregelen te nemen zodat het risico op het vrijgeven van gevoelige informatie zoveel mogelijk vermeden wordt. In deze cursus richten we ons op technieken uit statistical disclosure control om de hoeveelheid persoonlijke gegevens in datasets te minimaliseren.
Praktische info:
Inschrijven?
- Inschrijvingen: tot 13 okt. 2022
- Voorwaarden: Basiskennis van kanstheorie en statistiek
- Prijs: PhD of postdoc aan Vlaamse academische instituten: gratis | andere academici/non-profit/sociale sector: €300 | private sector: €800
Duur: 4 sessies van een halve dag (+/- 3 uur), in twee opeenvolgende dagen
Tools: ARX and ARXaaS
Leertrajecten
The theory and practice of Statistical Disclosure Control (SDC) technology for protecting microdata sets against privacy disclosures
Legitimacy of data-driven research and success of data-intensive applications depend on protecting privacy in the design, realisation, deployment and maintenance of these studies and systems. Personal Data Minimization (PDM) is a core principle of privacy protection, whereby the amount of personal data in data sets is adjusted to the level needed for the legitimate data usage in mind (i.e., for the aimed study or system functionality). Mainly, Statistical Disclosure Control (SDC) tools and mechanisms are used for the PDM of micro and tabular data sets. SDC technology aims at mitigating the disclosure of privacy sensitive information to adversaries who have access to the content of such data sets. Applying SDC methods is necessary before storing the data sets, sharing them with scientific community or partner organisations, or opening them to the public. Using a SDC tool, an expert can apply advanced SDC algorithms with proper parameters to a data set (i.e., transform the data set), gain insights into the utility of the original and the transformed data sets, estimate the data disclosure risks of the original and the transformed data sets, and eventually make appropriate trade-offs between the indicators of data utility and data disclosure risks.
The task of applying SDC into practice, however, increasingly becomes difficult due to the growth of data volume, variety, velocity ... and the availability of background information to adversaries. Data growth makes it difficult to detect potential privacy issues hidden in data sets (relating to the intrinsic characteristics of data sets) and background information makes it difficult to assess the potential risks when combining sensitive data sets with other ones (relating to the extrinsic characteristics of data sets).
Objectives
This workshop aims at introducing SDC technology to researchers for protecting microdata sets used for their data-driven studies. Microdata sets are structured tables where rows represent individuals and columns represent the attributes of individuals (like their age and occupation).
Specifically, the workshop will:
- Provide an understanding of privacy from a societal, legal and ethical perspective,
- Give an insight in the principles of SDC technology for protecting microdata sets,
- Provide some hands-on experience with applying SDC methods and tools for protecting microdata sets, and
- Give an insight in the process of applying SDC into practice as well as using other data protection measures complementary to SDC technology.
Practical Information
- prerequisite knowledge: Being familiar with basics of mathematics
- Used tools: ARX and ARXaaS
- Duration: Four half-day sessions (each of about 3 hours), organized in two consecutive days
Schedule
1: Introduction
by Mortaza S. Bargh and Sunil Choenni
On privacy foundations, privacy by design principles, publishing the results of privacy-sensitive data-driven studies
2: SDC for microdata protection
by Mortaza S. Bargh and Afshin Amighi
Introducing the theory of the main SDC methods and having hands on practice with the tool ARX
3: Differential privacy and its application to microdata protection
by Mortaza S. Bargh and Afshin Amighi
- Introducing the theory of the main differential privacy methods and having hands on practice with the tool ARX
4: On the process of applying SDC into practice
by Mortaza S. Bargh and Sunil Choenni
- Describing the complementary measures needed, based on the Data Protection Impact Assessment (DPIA) model
Lesgevers / sprekers
Afshin Amighi
Afshin Amighi received his BSc degree in Software Engineering from Isfahan University of Technology, Isfahan, Iran in 2000. Afterwards, he started working at the Information and Communication Technology Institute (ICTI). In September 2008, he started his MSc studies with specialization in Software Engineering for Distributed Systems at KTH, Stockholm, Sweden. In 2010, he participated in a live streaming P2P project at Tradix AB, Stockholm. In March 2011, he joined the Formal Methods and Tools group at the EEMCS Department of University of Twente, The Netherlands as a PhD candidate. His research was funded by an ERC grant under project VerCors: Verification of Concurrent Data Structures. Since September 2015 he has started his career as a Computer Science lecturer at the Rotterdam University of Applied Sciences (RUAS).
Sunil Choenni
Sunil Choenni is the head of the Statistical Information Management and Policy Analysis department of the Research and Documentation Centre (WODC) of the Dutch Ministry of Justice and Security. Furthermore, he is a Research Professor (Lector in Dutch) in the field of Future Information Technologies at RUAS. His research interests include data warehouses and data mining, databases, e-government, cyber security and human centred design.
Mortaza Shoae Bargh
Mortaza S. Bargh is a Scientific Researcher at the WODC (Wetenschappelijk Onderzoek- en Datacentrum, knowledge centre of the Dutch Ministry of Justice and Security). Until 2023 he was a Research Professor on Privary and Cybersecurity at Rotterdam University of Applied Sciences (RUAS). His current research interests include privacy and security by design for social technical systems, privacy preserving data mining and data publishing, responsible machine learning, access and usage control, usable security, and risk management. At the RUAS, Mortaza aims at transferring the practical and scientific knowledge into the ICT-related education disciplines (like developing/teaching innovative courses and developing/conducting practice-oriented research). Similarly, at the WODC he aims at transferring the state-of-the-art technological developments into the daily practice of the ministry and looking for innovative solutions to bridge between technological and not technological (like legal and ethical) aspects. He obtained his PhD and MSc in Information Theory from Eindhoven University of Technology (in 1995 and 1999, respectively). Between 1999 and 2011 he carried out applied research in the areas of secure pervasive computing and ambient intelligence at former Novay (or Telematica Instituut) in Enschede, The Netherlands.
FLAMES & VAIA Data Science Track
Data speelt steeds vaker een belangrijke rol in onze maatschappij. Het is echter niet vanzelfsprekend om uit grote hoeveelheden data relevante informatie te verkrijgen. Daarom organiseren VAIA en het Flames-netwerk (Flanders Training Network for Methodology and Statistics) een reeks opleidingen waarin deelnemers kennismaken met moderne tools en technieken om inzichten uit data te verwerven. Dit kan gaan over het omgaan met data (big data, data management,...) of het grafisch voorstellen van je data en het gebruik van algoritmen om voorspellingen te maken voor nog ongeziene data (machine-learningtechnieken).
VAIA slaat voor deze Data-Sciencereeks de handen in mekaar met het Flames-netwerk. Elke module kan apart gevolgd worden.
Gerelateerde opleidingen