메뉴 건너뛰기




Volumn 5, Issue , 2011, Pages 1-29

Data confidentiality: A review of methods for statistical disclosure limitation and methods for assessing privacy

Author keywords

Confidentiality; Differential privacy; Disclosure limitation; Missing data; Multiple imputation; Privacy; Synthetic data

Indexed keywords


EID: 84857264816     PISSN: None     EISSN: 19357516     Source Type: Journal    
DOI: 10.1214/11-SS074     Document Type: Article
Times cited : (72)

References (98)
  • 2
    • 0024914229 scopus 로고
    • Security-control methods for statistical databases: A comparative study
    • Adam, N.R., Worthmann, J.C., 1989. Security-control methods for statistical databases: a comparative study. ACM Comput. Surv. 21 (4), 515-556.
    • (1989) ACM Comput. Surv , vol.21 , Issue.4 , pp. 515-556
    • Adam, N.R.1    Worthmann, J.C.2
  • 3
    • 0033559186 scopus 로고    scopus 로고
    • Geographically masking health data to preserve confidentiality
    • Armstrong, M., Rushton, G., Zimmerman, D.L., 1999. Geographically masking health data to preserve confidentiality. Statistics in Medicine 18 (5), 497-525.
    • (1999) Statistics In Medicine , vol.18 , Issue.5 , pp. 497-525
    • Armstrong, M.1    Rushton, G.2    Zimmerman, D.L.3
  • 7
    • 33646348083 scopus 로고    scopus 로고
    • A data-swapping technique for generating synthetic samples; a method for disclosure control
    • Carlson, M., Salabasis, M., 2002. A data-swapping technique for generating synthetic samples; a method for disclosure control. Res. Official Statist. (5), 35-64.
    • (2002) Res. Official Statist , Issue.5 , pp. 35-64
    • Carlson, M.1    Salabasis, M.2
  • 8
    • 0000082189 scopus 로고
    • Suppression methodology and statistical disclosure control
    • Cox, L.H., 1980. Suppression methodology and statistical disclosure control. Journal of the American Statistical Association 75, 377-385.
    • (1980) Journal of the American Statistical Association , vol.75 , pp. 377-385
    • Cox, L.H.1
  • 10
    • 0001445186 scopus 로고
    • A constructive procedure for unbiased controlled rounding
    • Cox, L.H., 1987. A constructive procedure for unbiased controlled rounding. Journal of the American Statistical Association 82, 520-524.
    • (1987) Journal of the American Statistical Association , vol.82 , pp. 520-524
    • Cox, L.H.1
  • 11
    • 0041020068 scopus 로고
    • Matrix masking methods for disclosure limitation in microdata
    • Cox, L.H., 1994. Matrix masking methods for disclosure limitation in microdata. Survey Methodology 6, 165-169.
    • (1994) Survey Methodology , vol.6 , pp. 165-169
    • Cox, L.H.1
  • 13
    • 0012793677 scopus 로고
    • Towards a methodology for statistical disclosure control
    • Dalenius, T., 1977. Towards a methodology for statistical disclosure control. Statistik Tidskrift 15, 429-444.
    • (1977) Statistik Tidskrift , vol.15 , pp. 429-444
    • Dalenius, T.1
  • 14
    • 0000072558 scopus 로고
    • Finding a needle in a haystack - or identifying anonymous census record
    • Dalenius, T., 1986. Finding a needle in a haystack - or identifying anonymous census record. Journal of Official Statistics 2 (3), 329-336.
    • (1986) Journal of Official Statistics , vol.2 , Issue.3 , pp. 329-336
    • Dalenius, T.1
  • 18
    • 0001317036 scopus 로고
    • Uncertainty, information, and sequential experiments
    • MR0139242
    • DeGroot, M.H., 1962. Uncertainty, information, and sequential experiments. Annals of Mathematical Statistics 33, 404-419. MR0139242
    • (1962) Annals of Mathematical Statistics , vol.33 , pp. 404-419
    • Degroot, M.H.1
  • 25
    • 84972531331 scopus 로고
    • Enhancing access to microdata while protecting confidentiality: Prospects for the future (with discussion)
    • Duncan, G., Pearson, R., 1991. Enhancing access to microdata while protecting confidentiality: prospects for the future (with discussion). Statistical Science 6, 219-232.
    • (1991) Statistical Science , vol.6 , pp. 219-232
    • Duncan, G.1    Pearson, R.2
  • 26
    • 33746335051 scopus 로고    scopus 로고
    • Differential privacy
    • Springer, MR2307219
    • Dwork, C., 2006. Differential privacy. In: ICALP. Springer, pp. 1-12. MR2307219
    • (2006) ICALP , pp. 1-12
    • Dwork, C.1
  • 27
    • 41849095625 scopus 로고    scopus 로고
    • An ad omnia approach to defining and achieving private data analysis
    • Springer, MR2581844
    • Dwork, C., 2008. An ad omnia approach to defining and achieving private data analysis. In: Lecture Notes in Computer Science. Springer, p. 10. MR2581844
    • (2008) Lecture Notes In Computer Science , pp. 10
    • Dwork, C.1
  • 30
    • 35048856104 scopus 로고    scopus 로고
    • Privacy-preserving datamining on vertically partitioned databases
    • MR2147523
    • Dwork, C., Nissam, K., 2004. Privacy-preserving datamining on vertically partitioned databases. In: Advances in Cryptology: Proceedings of Crypto. pp. 528-544. MR2147523
    • (2004) Advances In Cryptology: Proceedings of Crypto , pp. 528-544
    • Dwork, C.1    Nissam, K.2
  • 31
    • 0011572699 scopus 로고    scopus 로고
    • DIS: A new approach to the measurement of statistical dis- closure risk
    • Elliot, M., 2000. DIS: a new approach to the measurement of statistical dis- closure risk. International Journal of Risk Assessment and Management 2, 39-48.
    • (2000) International Journal of Risk Assessment and Management , vol.2 , pp. 39-48
    • Elliot, M.1
  • 34
    • 35048813475 scopus 로고    scopus 로고
    • Data swapping: Variations on a theme by Dalenius and Reiss
    • Domingo-Ferrer, J., Torra, V. (Eds.), of Lecture Notes in Computer Science. Springer Berlin/Heidelberg,
    • Fienberg, S.E., McIntyre, J., 2004. Data swapping: Variations on a theme by Dalenius and Reiss. In: Domingo-Ferrer, J., Torra, V. (Eds.), Privacy in Statistical Databases. Vol. 3050 of Lecture Notes in Computer Science. Springer Berlin/Heidelberg, pp. 519, http://dx.doi.org/10.1007/978-3-540-25955-8_2
    • (2004) Privacy In Statistical Databases , vol.3050 , pp. 519
    • Fienberg, S.E.1    McIntyre, J.2
  • 35
    • 0000983892 scopus 로고
    • Masking procedurse for microdata disclosure limitation
    • Fuller, W., 1993. Masking procedurse for microdata disclosure limitation. Journal of Official Statistics 9, 383-406.
    • (1993) Journal of Official Statistics , vol.9 , pp. 383-406
    • Fuller, W.1
  • 36
    • 84857327435 scopus 로고
    • General Assembly of the United Nations, Universal declaration of human rights
    • General Assembly of the United Nations, 1948. Universal declaration of human rights.
    • (1948)
  • 37
    • 0001582302 scopus 로고    scopus 로고
    • Post randomi-sation for statistical disclosure control: Theory and implementation
    • Gouweleeuw, J. P. Kooiman, L.W., de Wolf, P.-P., 1998. Post randomi-sation for statistical disclosure control: Theory and implementation. Journal of Official Statistics 14 (4), 463-478.
    • (1998) Journal of Official Statistics , vol.14 , Issue.4 , pp. 463-478
    • Gouweleeuw, J.P.1    Kooiman, L.W.2    de Wolf, P.-P.3
  • 38
    • 84857276838 scopus 로고
    • Tech. rep., U.S. Bureau of the Census (unpublished manuscript), Suitland, Mary- land, USA
    • Greenberg, B., 1987. Rank swapping for masking ordinal microdata. Tech. rep., U.S. Bureau of the Census (unpublished manuscript), Suitland, Mary- land, USA.
    • (1987) Rank Swapping For Masking Ordinal Microdata
    • Greenberg, B.1
  • 40
    • 34250686456 scopus 로고    scopus 로고
    • Multiple imputation: Review and theory, implementation and software
    • MR2380504
    • Harel, O., Zhou, X.-H., 2007. Multiple imputation: Review and theory, implementation and software. Statistics in Medicine 26, 3057-3077. MR2380504
    • (2007) Statistics In Medicine , vol.26 , pp. 3057-3077
    • Harel, O.1    Zhou, X.-H.2
  • 44
    • 33747456679 scopus 로고    scopus 로고
    • A framework for evaluating the utility of data altered to protect confidentiality
    • MR2246755
    • Karr, A., Kohnen, C.N., Oganian, A., Reiter, J.P., Sanil, A.P., 2006. A framework for evaluating the utility of data altered to protect confidentiality. American Statistician 60 (3), 224-232. MR2246755
    • (2006) American Statistician , vol.60 , Issue.3 , pp. 224-232
    • Karr, A.1    Kohnen, C.N.2    Oganian, A.3    Reiter, J.P.4    Sanil, A.P.5
  • 46
    • 0346832638 scopus 로고    scopus 로고
    • Multiple imputation and disclosure protection: The case of the 1995 survey of consumer finances
    • Kennickell, A.B., 1997. Multiple imputation and disclosure protection: the case of the 1995 survey of consumer finances. Record Linkage Techniques, 248-267.
    • (1997) Record Linkage Techniques , pp. 248-267
    • Kennickell, A.B.1
  • 47
    • 84857269604 scopus 로고
    • Limiting disclosure in microdata based on random noise and transformation
    • Kim, J., 1986. Limiting disclosure in microdata based on random noise and transformation. Bureau of the Census.
    • (1986) Bureau of the Census
    • Kim, J.1
  • 50
    • 0022130080 scopus 로고
    • A data distortion by probability distribution
    • Liew, C.K., Choi, U.J., Liew, C.J., 1985. A data distortion by probability distribution. ACM Trans. Database Syst. 10 (3), 395-411.
    • (1985) ACM Trans. Database Syst , vol.10 , Issue.3 , pp. 395-411
    • Liew, C.K.1    Choi, U.J.2    Liew, C.J.3
  • 53
    • 12844255741 scopus 로고    scopus 로고
    • Selective multiple mputation of keys for statistical disclosure control in microdata
    • Liu, F., Little, R.J.A., 2002. Selective multiple mputation of keys for statistical disclosure control in microdata. In: Proceedings Joint Statistical Meet. pp. 2133-2138.
    • (2002) Proceedings Joint Statistical Meet , pp. 2133-2138
    • Liu, F.1    Little, R.J.A.2
  • 56
    • 38749132361 scopus 로고    scopus 로고
    • A recursive search algorithm for statistical disclosure assessment
    • MR2412605
    • Manning, A.M., Haglin, D.J., Keane, J.A., 2008. A recursive search algorithm for statistical disclosure assessment. Data Min. Knowl. Discov. 16 (2), 165-196. MR2412605
    • (2008) Data Min. Knowl. Discov , vol.16 , Issue.2 , pp. 165-196
    • Manning, A.M.1    Haglin, D.J.2    Keane, J.A.3
  • 58
    • 77955017876 scopus 로고    scopus 로고
    • Assessing database privacy using the area under the receiver-operator characteristic curve
    • Matthews, G.J., Harel, O., Aseltine, R.H., 2010a. Assessing database privacy using the area under the receiver-operator characteristic curve. Health Services and Outcomes Research Methodology 10 (1), 1-15.
    • (2010) Health Services and Outcomes Research Methodology , vol.10 , Issue.1 , pp. 1-15
    • Matthews, G.J.1    Harel, O.2    Aseltine, R.H.3
  • 59
    • 77951988339 scopus 로고    scopus 로고
    • Examining the robustness of fully synthetic data techniques for data with binary variables
    • Matthews, G.J., Harel, O., Aseltine, R.H., 2010b. Examining the robustness of fully synthetic data techniques for data with binary variables. Journal of Statistical Computation and Simulation 80 (6), 609-624.
    • (2010) Journal of Statistical Computation and Simulation , vol.80 , Issue.6 , pp. 609-624
    • Matthews, G.J.1    Harel, O.2    Aseltine, R.H.3
  • 63
    • 0001626808 scopus 로고
    • Disclosure risk and disclosure avoidance for microdata
    • Paass, G., 1988. Disclosure risk and disclosure avoidance for microdata. Journal of Business and Economic Statistics 6 (4), 487-500.
    • (1988) Journal of Business and Economic Statistics , vol.6 , Issue.4 , pp. 487-500
    • Paass, G.1
  • 64
    • 84976672368 scopus 로고
    • The use of regression methodology for the compromise of confidential information in statistical databases
    • Palley, M., Simonoff, J., 1987. The use of regression methodology for the compromise of confidential information in statistical databases. ACM Trans. Database Systems 12 (4), 593-608.
    • (1987) ACM Trans. Database Systems , vol.12 , Issue.4 , pp. 593-608
    • Palley, M.1    Simonoff, J.2
  • 68
    • 0346202054 scopus 로고    scopus 로고
    • Satisfying disclosure restriction with synthetic data sets
    • Reiter, J.P., 2002. Satisfying disclosure restriction with synthetic data sets. Journal of Official Statistics 18 (4), 531-543.
    • (2002) Journal of Official Statistics , vol.18 , Issue.4 , pp. 531-543
    • Reiter, J.P.1
  • 69
    • 0346202055 scopus 로고    scopus 로고
    • Inference for partially synthetic, public use microdata sets
    • Reiter, J.P., 2003. Inference for partially synthetic, public use microdata sets. Survey Methodology 29 (2), 181-188.
    • (2003) Survey Methodology , vol.29 , Issue.2 , pp. 181-188
    • Reiter, J.P.1
  • 70
    • 36148943098 scopus 로고    scopus 로고
    • New approaches to data dissemination: A glimpse into the future (?)
    • MR2061931
    • Reiter, J.P., 2004a. New approaches to data dissemination: A glimpse into the future (?). Chance 17 (3), 11-15. MR2061931
    • (2004) Chance , vol.17 , Issue.3 , pp. 11-15
    • Reiter, J.P.1
  • 71
    • 36148976352 scopus 로고    scopus 로고
    • Simultaneous use of multiple imputation for missing data and disclosure limitation
    • Reiter, J.P., 2004b. Simultaneous use of multiple imputation for missing data and disclosure limitation. Survey Methodology 30 (2), 235-242.
    • (2004) Survey Methodology , vol.30 , Issue.2 , pp. 235-242
    • Reiter, J.P.1
  • 72
    • 29144432870 scopus 로고    scopus 로고
    • Estimating risks of identification disclosure in microdata
    • MR2236926
    • Reiter, J.P., 2005a. Estimating risks of identification disclosure in microdata. Journal of the American Statistical Association 100, 1103-1112. MR2236926
    • (2005) Journal of the American Statistical Association , vol.100 , pp. 1103-1112
    • Reiter, J.P.1
  • 73
    • 12844284643 scopus 로고    scopus 로고
    • Releasing multiply imputed, synthetic public use microdata: An illustration and empirical study
    • MR2113234
    • Reiter, J.P., 2005b. Releasing multiply imputed, synthetic public use microdata: An illustration and empirical study. Journal of the Royal Statistical Society, Series A: Statistics in Society 168 (1), 185-205. MR2113234
    • (2005) Journal of the Royal Statistical Society, Series A: Statistics In Society , vol.168 , Issue.1 , pp. 185-205
    • Reiter, J.P.1
  • 74
    • 36148937800 scopus 로고    scopus 로고
    • Using CART to generate partially synthetic public use microdata
    • Reiter, J.P., 2005c. Using CART to generate partially synthetic public use microdata. Journal of Official Statistics 21 (3), 441-462.
    • (2005) Journal of Official Statistics , vol.21 , Issue.3 , pp. 441-462
    • Reiter, J.P.1
  • 76
    • 0012776989 scopus 로고
    • Comment on Statistical disclosure limitation
    • Rubin, D.B., 1993. Comment on "Statistical disclosure limitation". Journal of Official Statistics 9, 461-468.
    • (1993) Journal of Official Statistics , vol.9 , pp. 461-468
    • Rubin, D.B.1
  • 78
    • 0036909696 scopus 로고    scopus 로고
    • The security of confidential numerical data in databases
    • Sarathy, R., Muralidhar, K., 2002a. The security of confidential numerical data in databases. Information Systems Research 13 (4), 389-403.
    • (2002) Information Systems Research , vol.13 , Issue.4 , pp. 389-403
    • Sarathy, R.1    Muralidhar, K.2
  • 79
    • 0036909696 scopus 로고    scopus 로고
    • The security of confidential numerical data in databases
    • Sarathy, R., Muralidhar, K., 2002b. The security of confidential numerical data in databases. Info. Sys. Research 13 (4), 389-403.
    • (2002) Info. Sys. Research , vol.13 , Issue.4 , pp. 389-403
    • Sarathy, R.1    Muralidhar, K.2
  • 80
    • 85047673373 scopus 로고    scopus 로고
    • Missing data: Our view of state of the art
    • Schafer, J.L., Graham, J.W., 2002. Missing data: Our view of state of the art. Psychological Methods 7 (2), 147-177.
    • (2002) Psychological Methods , vol.7 , Issue.2 , pp. 147-177
    • Schafer, J.L.1    Graham, J.W.2
  • 84
    • 54949127921 scopus 로고    scopus 로고
    • Assessing identification risk in survey microdata using log-linear models
    • MR2462887
    • Skinner, C., Shlomo, N., 2008. Assessing identification risk in survey microdata using log-linear models. Journal of the American Statistical Association 103, 989-1001. MR2462887
    • (2008) Journal of the American Statistical Association , vol.103 , pp. 989-1001
    • Skinner, C.1    Shlomo, N.2
  • 88
    • 0344971447 scopus 로고
    • The confidentiality and analytic usefulness of masked business microdata
    • American Statistical Association
    • Spruill, N.L., 1983. The confidentiality and analytic usefulness of masked business microdata. In: Proceedings of the Section on Survey ReserachMicrodata. American Statistical Association, pp. 602-607.
    • (1983) Proceedings of the Section On Survey ReserachMicrodata , pp. 602-607
    • Spruill, N.L.1
  • 89
    • 0030333205 scopus 로고    scopus 로고
    • Replacing personally-identifying information in medical records, the scrub system
    • Hanley and Belfus, Inc
    • Sweeney, L., 1996. Replacing personally-identifying information in medical records, the scrub system. In: American Medical Informatics Association. Hanley and Belfus, Inc., pp. 333-337.
    • (1996) American Medical Informatics Association , pp. 333-337
    • Sweeney, L.1
  • 93
    • 44949285668 scopus 로고
    • Optimal noise addition for preserving confidentiality in multivariate data
    • MR1108554
    • Tendick, P., 1991. Optimal noise addition for preserving confidentiality in multivariate data. Journal of Statistical Planning and Inference 27 (2), 341-353. MR1108554
    • (1991) Journal of Statistical Planning and Inference , vol.27 , Issue.2 , pp. 341-353
    • Tendick, P.1
  • 94
    • 84857276840 scopus 로고    scopus 로고
    • United Nations Economic Comission for Europe (UNECE), Manging statistical cinfidentiality and microdata access: Principles and guidlinesof good practice
    • United Nations Economic Comission for Europe (UNECE), 2007. Manging statistical cinfidentiality and microdata access: Principles and guidlinesof good practice.
    • (2007)
  • 95
    • 0013776710 scopus 로고
    • Randomized response: A survey technique for eliminating evasive answer bias
    • Warner, S.L., 1965. Randomized response: A survey technique for eliminating evasive answer bias. Journal of the American Statistical Association 60 (309), 63-69.
    • (1965) Journal of the American Statistical Association , vol.60 , Issue.309 , pp. 63-69
    • Warner, S.L.1
  • 96
  • 98
    • 0028787617 scopus 로고
    • The computer-based patient record and confidentiality
    • Woodward, B., 1995. The computer-based patient record and confidentiality. The New England Journal of Medicine, 1419-1422.
    • (1995) The New England Journal of Medicine , pp. 1419-1422
    • Woodward, B.1


* 이 정보는 Elsevier사의 SCOPUS DB에서 KISTI가 분석하여 추출한 것입니다.