Search papers, labs, and topics across Lattice.
This paper conducts a comprehensive privacy analysis of local combination synthetic data generation methods, specifically SMOTE, Simulant, and Avatar, which are commonly used in healthcare to share anonymized data. The study reveals that these methods are vulnerable to various privacy attacks, including membership inference, linkage, and reconstruction attacks, leading to significant privacy leakage. The findings challenge the assumption that outputs from these methods can be considered anonymous, highlighting the need for more robust privacy safeguards in synthetic data generation.
Local combination synthetic data methods leak substantial privacy, undermining their perceived anonymity in sensitive applications like healthcare.
Synthetic data is seen as a promising solution for sharing data in sensitive contexts. However, recent work on privacy attacks have shown that there are still significant residual risks, especially for synthetic data generations methods that are not based on formal approaches such as differential privacy. In this paper, we investigate the privacy risks associated with local combination approaches for generating synthetic data in which synthetic profiles are built by combining real neighbouring profiles. More precisely, we focus on three methods from this family, namely SMOTE, Simulant and Avatar, which have been recently used as a way to share'anonymised data'in the healthcare domain. In particular, we conduct an extensive privacy analysis through a diverse set of attacks: membership inference, linkage and reconstruction attacks. Our results demonstrate substantial privacy leakage for all three methods, raising serious doubts about whether their outputs should be regarded as anonymous in practice.