Page 746

Ming Ding | Information Security and

Privacy Group | Data61, CSIROPrivacy risk assessment –Overview

•Privacy risk is more than re -identification

•Any unintentional disclosure of personal information could become a privacy violation (e.g.,

knowing someone has participated in an AI model training for a study of breast cancer)

•Risk metrics describe the level of privacy leakage risk

➢Each metric gives bounds on how effectively the adversary can succeed in obtaining private

information

•System model: goals, background information, data observation, data analytics capabilities,

etc.

Original data x

(sensitive info: s

non-sensitive info: u)Output/Observation y

(data, query answer, AI/ML

models/parameters, etc.)