Although the bulk of the research in privacy and statistical disclosure control is designed for static data, more and more data are often collected as continuous streams, and extensions of popular privacy tools and models have been proposed for this scenario. However, most of these proposals require buffers, where incoming individuals are momentarily stored, anonymized, and then released following a delay, thus considering a data stream as a succession of batches while it is by nature continuous. Having a delay unavoidably alters data freshness but also, more critically, inordinately exerts constraints on what can be achieved in terms of protection and information preservation. By considering randomized response, and specifically its recent bistochastic extension, in the context of dynamic data, this paper proposes a protocol for the anonymization of data streams that achieves zero delay while exhibiting formal privacy guarantees. Using a new tool in the privacy literature that introduces the concept of elementary plausible deniability, we show that it is feasible to achieve an atomic processing of individuals entering a stream, in-stead of proceeding by batches. We illustrate the application of the proposed approach by an empirical example.
翻译:尽管隐私与统计披露控制领域的研究主要针对静态数据,但越来越多的数据以连续流的形式被采集,为此研究人员已提出流行隐私工具与模型的扩展方案。然而,大多数方案需要缓冲区——将流入个体暂时存储、匿名化后延迟释放,这本质上是将连续数据流视为批量处理的序列。延迟机制不仅不可避免会降低数据新鲜度,更严重的是会对数据保护与信息保留能力造成过度约束。本文通过在动态数据场景中应用随机化响应技术(特别是其最新的双随机化扩展),提出一种实现零延迟且具备形式化隐私保障的数据流匿名化协议。利用隐私研究领域引入"基本可否认性"概念的新工具,我们证明可以实现对数据流中个体进行原子级处理,而非采用批量处理模式。通过实证案例展示了所提方法的应用效果。