Aggregate queries can expose personal data through differencing attacks, study warns
A technical analysis highlights how AI query layers over sensitive HR data can leak personal information even when individual queries appear anonymized. The core risk lies in 'differencing attacks,' where two separately compliant aggregate queries are subtracted to identify a single individual — for example, revealing that a specific employee is a union member. Under GDPR Article 9, such disclosures of special-category data carry serious legal implications, regardless of whether the output looks like a simple number. A self-hosted tool called Nowl is being piloted to address this by enforcing population-based thresholds rather than query-shape rules, though it acknowledges gaps including no cross-query budget or l-diversity guarantee. The authors stress that true anonymization requires confirming sensitive field classification, anchoring checks to actual population counts, and maintaining audit logs across all queries including rejections.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.

Discussion (0)
Log in to join the discussion and vote.
Log in