Chinese Journal of Network and Information Security ›› 2023, Vol. 9 ›› Issue (3): 49-59.doi: 10.11959/j.issn.2096-109x.2023037

• Papers • Previous Articles     Next Articles

Adaptive selection method of desensitization algorithm based on privacy risk assessment

Lijun ZU1,2, Yalin CAO3, Xiaohua MEN2, Zhihui LYU1, Jiawei YE1, Hongyi LI1, Liang ZHANG3   

  1. 1 School of Financial Technology, Fudan University, Shanghai 200433, China
    2 China UnionPay Co., Ltd, Shanghai 201210, China
    3 Huawei Technologies Co., Ltd, Nanjing 210012, China
  • Revised:2023-05-30 Online:2023-06-25 Published:2023-06-01
  • Supported by:
    The National Key R&D Program of China(2021YFC330060)

Abstract:

The financial industry deals with a vast amount of sensitive data in its business operations.However, the conventional approach of binding financial data for desensitization and using desensitization algorithms is becoming inefficient due to the fast-paced growth of financial businesses and the proliferation of data types.Additionally, manual verification and assessment of desensitized data by security experts are time-consuming and may carry potential privacy risks due to the improper selection of desensitization algorithms.While prior research has emphasized desensitization methods and privacy-preserving technologies, limited work has been conducted on desensitization algorithms from the perspective of automation.To address this issue, an adaptive recommendation framework was propose for selecting desensitization strategies that consider various factors, such as existing privacy protection technologies, data quality requirements of business scenarios, security risk requirements of financial institutions, and data attributes.Specifically, a dual-objective evaluation function was established for privacy risk and data quality to optimize the selection of desensitization algorithm parameters for different algorithms.Furthermore, the desensitization algorithm and parameters were adaptively selected by considering the data attributes through a multi-decision factor system and desensitization effect evaluation system.Compared to traditional approaches, the proposed framework effectively tackle issues of reduced data usability and inadequate personal data privacy protection that derive from manual intervention.Testing on a dataset with multiple financial institution types, the experiments show that the proposed method achieves a recommendation accuracy exceeding 95%, while the desensitized privacy risk level differed by less than 10% from the expected level.Additionally, the recommendation efficiency is 100 times faster than expert manual processing.

Key words: automatic data desensitization, privacy risk assessment, artificial intelligence, financial sensitive data

CLC Number: 

No Suggested Reading articles found!