English

$(\ell,\delta)$-Diversity: Linkage-Robustness via a Composition Theorem

Information Theory 2025-06-25 v2 math.IT

Abstract

In this paper, we consider the problem of degradation of anonymity upon linkages of anonymized datasets. We work in the setting where an adversary links together t2t\geq 2 anonymized datasets in which a user of interest participates, based on the user's known quasi-identifiers, which motivates the use of \ell-diversity as the notion of dataset anonymity. We first argue that in the worst case, such linkage attacks can reveal the exact sensitive attribute of the user, even when each dataset respects \ell-diversity, for moderately large values of \ell. This issue motivates our definition of (approximate) (,δ)(\ell,\delta)-diversity -- a parallel of (approximate) (ϵ,δ)(\epsilon,\delta)-differential privacy (DP) -- which simply requires that a dataset respect \ell-diversity, with high probability. We then present a mechanism for achieving (,δ)(\ell,\delta)-diversity, in the setting of independent and identically distributed samples. Next, we establish bounds on the degradation of (,δ)(\ell,\delta)-diversity, via a simple ``composition theorem,'' similar in spirit to those in the DP literature, thereby showing that approximate diversity, unlike standard diversity, is roughly preserved upon linkage. Finally, we describe simple algorithms for maximizing utility, measured in terms of the number of anonymized ``equivalence classes,'' and derive explicit lower bounds on the utility, for special sample distributions.

Keywords

Cite

@article{arxiv.2506.18405,
  title  = {$(\ell,\delta)$-Diversity: Linkage-Robustness via a Composition Theorem},
  author = {V. Arvind Rameshwar and Anshoo Tandon},
  journal= {arXiv preprint arXiv:2506.18405},
  year   = {2025}
}

Comments

10 pages, 2 tables, 2 figures

R2 v1 2026-07-01T03:29:01.888Z