Formalizing Anonymity for Software Development
Abstract
1. Introduction
1.1. Anonymity
1.2. Research Goals
1.3. Methodology
2. Theoretical Foundations
2.1. The Concept of Anonymity
2.2. Relevant Legal Sources
2.2.1. The EU General Data Protection Regulation
To determine whether a natural person is identifiable, account should be taken of all the means reasonably likely to be used, such as singling out, either by the controller or by another person to identify the natural person directly or indirectly. To ascertain whether means are reasonably likely to be used to identify the natural person, account should be taken of all objective factors, such as the costs of and the amount of time required for identification, taking into consideration the available technology at the time of the processing and technological developments. (Recital 26 GDPR)
2.2.2. The US Family Educational Rights and Privacy Act
2.2.3. The US Health Insurance Portability and Accountability Act Privacy Rule
2.3. Threats to and Attacks on Anonymity
2.3.1. Threats
- Identity disclosure (re-identification): An attacker is able to identify an individual within a set of anonymous records.
- Membership disclosure: An attacker is able to identify whether a certain individual is contained in a set of anonymous records, even without being able to clearly determine which specific data record belongs to that individual.
- Attribute disclosure: An attacker is able to identify a sensitive attribute of an individual from a set of anonymous records; for example, the attacker may identify that the individual is in a certain age group and that all members of the dataset within that age group have the same disease.
- Singling out: This refers to the possibility of isolating “some or all records which identify an individual in the dataset” ([20], p. 11). Therefore, successful singling out will lead to the identity of an individual being disclosed.
- Linkability: The “ability to link at least two records concerning the same data subject or a group of data subjects (either in the same database or in two different databases)” [20] (p. 11). Successfully linking records may not be sufficient to identify an individual, but can enable membership or attribute disclosure.
- Inference: “The possibility to deduce, with significant probability, the value of an attribute from the values of a set of other attributes” ([20], p. 12). Thus, successful inference will lead to attribute disclosure.
2.3.2. Attack Vectors
Re-Identification Attacks
Predicate Singling out Attacks
Reconstruction Attacks
Tracing Attacks
2.4. Anonymization Techniques
2.5. Models of Anonymity and Their Properties
3. Formal Models of Anonymity
3.1. k-Anonymity and Related Models
3.1.1. Basic Concept
3.1.2. The HIPAA Safe Harbor Model
3.1.3. Analysis
3.2. Differential Privacy
3.2.1. Basic Concept
- Flipping a coin secretly;
- If it is tails, answering truthfully;
- If it is heads, flipping the coin again in secret, then answering “yes” for heads and “no” for tails.
3.2.2. Global vs. Local Differential Privacy
3.2.3. Analysis
3.3. Game-Theoretic Modelling
3.3.1. Basic Concept
3.3.2. The FERPA Data Protection Game
3.3.3. The ARX Game-Theoretic Model
3.3.4. Analysis
3.4. Predicate Singling out
3.4.1. The Basic Concept
3.4.2. Analysis
4. Cross-Model Analysis
4.1. Comparison of the Different Models
4.2. Limitations of Modelling Anonymity
4.3. Some Comments on Implementing Anonymization in Software
5. Conclusions
Author Contributions
Funding
Data Availability Statement
Conflicts of Interest
Abbreviations
| CFR | (US) Code of Federal Regulations |
| DP | Differential Privacy |
| ECHR | European Convention on Human Rights |
| EDPB | European Data Protection Board |
| EU | European Union |
| FERPA | (US) Family Educational Rights and Privacy Act |
| GDPR | General Data Protection Regulation |
| GTM | Game-Theoretic Modelling/Model |
| HIPAA | (US) Health Insurance Portability and Accountability Act |
| IEC | International Electrotechnical Commission |
| ISO | International Organization for Standardization |
| PET | Privacy-Enhancing Technique |
| PHI | Protected Health Information |
| PII | Personally Identifiable Information |
| Pr | probability |
| PSO | Predicate Singling Out |
| QI | Quasi-Identifier |
| US | United States |
| U.S.C. | United States Code |
| ZIP code | Zone Improvement Plan code (postal code) |
References
- Cohen, J.E. What Privacy Is For. Harv. Law Rev. 2013, 126, 1904–1933. [Google Scholar]
- Solove, D. “I’ve Got Nothing to Hide” and Other Misunderstandings of Privacy. San Diego Law Rev. 2007, 44, 745. [Google Scholar]
- Nissim, K.; Wood, A. Is Privacy Privacy? Philos. Trans. R. Soc. A Math. Phys. Eng. Sci. 2018, 376, 20170358. [Google Scholar] [CrossRef] [Scilit]
- Hölzel, J. Differential Privacy and the GDPR. Eur. Data Prot. Law Rev. 2019, 5, 184–196. [Google Scholar] [CrossRef] [Scilit]
- United Nations. The PET Guide: The United Nations Guide on Privacy-Enhancing Technologies for Official Statistics; Technical report; United Nations Committee of Experts on Big Data and Data Science for Official Statistics: New York, NY, USA, 2023. [Google Scholar]
- Kucur, E.N.; Buyuktanir, T.; Ugurelli, M.; Yildiz, K. Privacy-Preserving Machine Learning Techniques: Cryptographic Approaches, Challenges, and Future Directions. Appl. Sci. 2026, 16, 277. [Google Scholar] [CrossRef] [Scilit]
- Golle, P. Revisiting the Uniqueness of Simple Demographics in the US Population. In Proceedings of the 5th ACM Workshop on Privacy in Electronic Society, WPES ’06, New York, NY, USA, 30 October 2006; pp. 77–80. [Google Scholar] [CrossRef] [Scilit]
- Sweeney, L. Weaving Technology and Policy Together to Maintain Confidentiality. J. Law Med. Ethics 1997, 25, 98–110. [Google Scholar] [CrossRef] [Scilit]
- Dwork, C.; Smith, A.; Steinke, T.; Ullman, J. Exposed! A Survey of Attacks on Private Data. Annu. Rev. Stat. Its Appl. 2017, 4, 61–84. [Google Scholar] [CrossRef] [Scilit]
- Nissenbaum, H. Privacy as Contextual Integrity. Wash. Law Rev. 2004, 79, 119–157. [Google Scholar]
- Pabst, S. Unbeobachtete Kommunikation; Springer VS: Wiesbaden, Germany, 2018. [Google Scholar] [CrossRef] [Scilit]
- ISO/IEC 29100; Information Technology—Security Techniques—Privacy Framework. International Organization for Standardization: Geneva, Switzerland, 2024.
- Dalenius, T. Finding a Needle In a Haystack or Identifiying Anonymous Census Records. J. Off. Stat. 1986, 2, 329–336. [Google Scholar]
- Sweeney, L. k-Anonymity: A model for protecting privacy. Int. J. Uncertain. Fuzzyness Knowl.-Based Syst. 2002, 10, 557–570. [Google Scholar] [CrossRef] [Scilit]
- Warren, S.D.; Brandeis, L.D. The Right to Privacy. Harv. Law Rev. 1890, 4, 193–220. [Google Scholar] [CrossRef] [Scilit]
- Kneuper, R. Anonymisierte Daten brauchen keinen Datenschutz—wirklich nicht? In Selbstbestimmung, Privatheit und Datenschutz: Gestaltungsoptionen für einen europäischen Weg; Friedewald, M., Kreutzer, M., Hansen, M., Eds.; Springer Fachmedien: Wiesbaden, Germany, 2022; pp. 171–188. [Google Scholar] [CrossRef] [Scilit]
- Petrlic, R.; Sorge, C.; Ziebarth, W. Datenschutz: Einführung in Technischen Datenschutz, Datenschutzrecht und Angewandte Kryptographie, 2nd ed.; Springer Vieweg: Wiesbaden, Germany, 2022. [Google Scholar]
- Altman, M.; Cohen, A.; Falzon, F.; Markatou, E.A.; Nissim, K.; Reymond, M.J.; Saraogi, S.; Wood, A. A Principled Approach to Defining Anonymization. 2022. Available online: https://ssrn.com/abstract=4104748 (accessed on 25 May 2026).
- Dwork, C.; Roth, A. The Algorithmic Foundations of Differential Privacy. Found. Trends® Theor. Comput. Sci. 2014, 9, 211–407. [Google Scholar] [CrossRef] [Scilit]
- Article 29 Data Protection Working Party. Opinion 05/2014 on Anonymisation Techniques; European Commission: Brussels, Belgium, 2014. [Google Scholar]
- Cohen, A.; Nissim, K. Towards Formalizing the GDPR’s Notion of Singling out. Proc. Natl. Acad. Sci. USA 2020, 117, 8344–8352. [Google Scholar] [CrossRef] [Scilit]
- Dinur, I.; Nissim, K. Revealing Information While Preserving Privacy. In Proceedings of the Twenty-Second ACM SIGMOD-SIGACT-SIGART Symposium on Principles of Database Systems, PODS ’03, San Diego, CA, USA, 9–11 June 2003; pp. 202–210. [Google Scholar] [CrossRef] [Scilit]
- Dwork, C.; Smith, A.; Steinke, T.; Ullman, J.; Vadhan, S. Robust Traceability from Trace Amounts. In Proceedings of the 2015 IEEE 56th Annual Symposium on Foundations of Computer Science, Berkeley, CA, USA, 17–20 October 2015; pp. 650–669. [Google Scholar] [CrossRef] [Scilit]
- JASON. Consistency of Data Products and Formal Privacy Methods for the 2020 Census; Technical Report JSR-21-02; The MITRE Corporation: McLean, VA, USA, 2022. [Google Scholar]
- Homer, N.; Szelinger, S.; Redman, M.; Duggan, D.; Tembe, W.; Muehling, J.; Pearson, J.V.; Stephan, D.A.; Nelson, S.F.; Craig, D.W. Resolving Individuals Contributing Trace Amounts of DNA to Highly Complex Mixtures Using High-Density SNP Genotyping Microarrays. PLoS Genet. 2008, 4, e1000167. [Google Scholar] [CrossRef] [Scilit] [PubMed]
- Carlini, N.; Chien, S.; Nasr, M.; Song, S.; Terzis, A.; Tramèr, F. Membership Inference Attacks From First Principles. In Proceedings of the 2022 IEEE Symposium on Security and Privacy (SP), San Francisco, CA, USA, 22–26 May 2022; pp. 1897–1914. [Google Scholar] [CrossRef] [Scilit]
- Mattern, J.; Mireshghallah, F.; Jin, Z.; Schölkopf, B.; Sachan, M.; Berg-Kirkpatrick, T. Membership Inference Attacks against Language Models via Neighbourhood Comparison. In Proceedings of the Findings of the Association for Computational Linguistics: ACL 2023, Toronto, ON, Canada, 9–14 July 2023; Rogers, A., Boyd-Graber, J., Okazaki, N., Eds.; Association for Computational Linguistics: Stroudsburg, PA, USA, 2023; pp. 11330–11343. [Google Scholar] [CrossRef] [Scilit]
- Fluitt, A.; Cohen, A.; Altman, M.; Nissim, K.; Viljoen, S.; Wood, A. Opinions · Data Protection’s Composition Problem. Eur. Data Prot. Law Rev. 2019, 5, 285–292. [Google Scholar] [CrossRef] [Scilit]
- Kenthapadi, K.; Mishra, N.; Nissim, K. Denials Leak Information: Simulatable Auditing. J. Comput. Syst. Sci. 2013, 79, 1322–1340. [Google Scholar] [CrossRef] [Scilit]
- Nissim, K.; Bembenek, A.; Wood, A.; Bun, M.; Gaboardi, M.; Gasser, U.; O’Brien, D.R.; Steinke, T.; Vadhan, S. Bridging the Gap between Computer Science and Legal Approaches to Privacy. Harv. J. Law Technol. 2018, 31, 687–780. [Google Scholar]
- Cohen, A. Attacks on Deidentification’s Defenses. In Proceedings of the 31st USENIX Security Symposium (USENIX Security 22), Boston, MA, USA, 10–12 August 2022; USENIX Association: Berkeley, CA, USA, 2022; pp. 1469–1486. [Google Scholar]
- Samarati, P.; Sweeney, L. Protecting privacy when disclosing information: k-anonymity and its enforcement through generalization and suppression. In Proceedings of the IEEE Symposium on Research in Security and Privacy (S&P), Oakland, CA, USA, 4–6 May 1998. [Google Scholar]
- Kneuper, R. Data Protection for Software Development and IT. A Practical Introduction; Springer: Berlin/Heidelberg, Germany, 2025. [Google Scholar] [CrossRef] [Scilit]
- Machanavajjhala, A.; Gehrke, J.; Kifer, D.; Venkitasubramaniam, M. L-Diversity: Privacy beyond k-Anonymity. In Proceedings of the 22nd International Conference on Data Engineering (ICDE’06), Atlanta, Georgia, 3–7 April 2006; p. 24. [Google Scholar] [CrossRef] [Scilit]
- Li, N.; Li, T.; Venkatasubramanian, S. T-Closeness: Privacy Beyond k-Anonymity and l-Diversity. In Proceedings of the 2007 IEEE 23rd International Conference on Data Engineering, Istanbul, Turkey, 15–20 April 2007; pp. 106–115. [Google Scholar] [CrossRef] [Scilit]
- Office for Civil Rights (OCR). Guidance Regarding Methods for De-identification of Protected Health Information in Accordance with the Health Insurance Portability and Accountability Act (HIPAA) Privacy Rule. Technical Report, 2012. Available online: https://www.hhs.gov/hipaa/for-professionals/privacy/special-topics/de-identification/index.html (accessed on 25 May 2026).
- Prasser, F.; Eicher, J.; Spengler, H.; Bild, R.; Kuhn, K.A. Flexible Data Anonymization Using ARX–Current Status and Challenges Ahead. Softw. Pract. Exp. 2020, 50, 1277–1304. [Google Scholar] [CrossRef] [Scilit]
- Dwork, C.; McSherry, F.; Nissim, K.; Smith, A. Calibrating Noise to Sensitivity in Private Data Analysis. In Proceedings of the Theory of Cryptography; Halevi, S., Rabin, T., Eds.; Springer: Berlin/Heidelberg, Germany, 2006; pp. 265–284. [Google Scholar] [CrossRef] [Scilit]
- Wood, A.; Altman, M.; Bembenek, A.; Bun, M.; Gaboardi, M.; Honaker, J.; Nissim, K.; O’Brien, D.; Steinke, T.; Vadhan, S. Differential Privacy: A Primer for a Non-Technical Audience. Vanderbilt J. Entertain. Technol. Law 2018, 21, 209–276. [Google Scholar] [CrossRef] [Scilit]
- Kairouz, P.; Oh, S.; Viswanath, P. The Composition Theorem for Differential Privacy. arXiv 2015, arXiv:1311.0776. [Google Scholar] [CrossRef] [Scilit]
- Kasiviswanathan, S.P.; Lee, H.K.; Nissim, K.; Raskhodnikova, S.; Smith, A. What Can We Learn Privately? SIAM J. Comput. 2011, 40, 793–826. [Google Scholar] [CrossRef] [Scilit]
- Ozturk, O.; Buyuktanir, B.; Baydogmus, G.K.; Yildiz, K. Differential Privacy in Federated Learning: Mitigating Inference Attacks with Randomized Response. arXiv 2025, arXiv:2509.13987. Available online: https://arxiv.org/abs/2509.13987v1 (accessed on 25 May 2026).
- NIST SP 800-226; Guidelines for Evaluating Differential Privacy Guarantees. NIST: Gaithersburg, MD, USA, 2025.
- Wan, Z.; Vorobeychik, Y.; Xia, W.; Clayton, E.W.; Kantarcioglu, M.; Ganta, R.; Heatherly, R.; Malin, B.A. A Game Theoretic Framework for Analyzing Re-Identification Risk. PLoS ONE 2015, 10, e0120592. [Google Scholar] [CrossRef] [Scilit]
- Prasser, F.; Gaupp, J.; Wan, Z.; Xia, W.; Vorobeychik, Y.; Kantarcioglu, M.; Kuhn, K.; Malin, B. An Open Source Tool for Game Theoretic Health Data De-Identification. AMIA Annu. Symp. Proc. 2018, 2017, 1430–1439. [Google Scholar] [PubMed]
- Salem, A.; Cherubin, G.; Evans, D.; Köpf, B.; Paverd, A.; Suri, A.; Tople, S.; Zanella-Béguelin, S. SoK: Let the Privacy Games Begin! A Unified Treatment of Data Inference Privacy in Machine Learning. In Proceedings of the 2023 IEEE Symposium on Security and Privacy (SP), San Francisco, CA, USA, 21–25 May 2023; pp. 327–345. [Google Scholar] [CrossRef] [Scilit]
- Altman, M.; Cohen, A.; Nissim, K.; Wood, A. What a Hybrid Legal-Technical Analysis Teaches Us About Privacy Regulation: The Case of Singling Out. 2020. Available online: https://ssrn.com/abstract=3681729 (accessed on 25 May 2026).
| Model | Approach | Limitations |
|---|---|---|
| k-anonymity, ℓ-diversity, t-closeness | ensuring that individuals cannot be distinguished based on QI | poor protection against membership and attribute disclosure |
| differential privacy | quantifying knowledge gain due to inclusion of an individual | global DP: need for trustworthy curator |
| local DP: reduced accuracy of results | ||
| game-theoretic models | modelling of attacks on anonymity and protection against them | separate model needed for each anonymization mechanism or context |
| predicate singling out | modelling of one specific privacy property | no guarantee for anonymity in general |
| Model | Generality | Availability of Algorithms | Composability | Robustness Against Postprocessing | No Reliance on Distributional Assumptions |
|---|---|---|---|---|---|
| k-anonymity, ℓ-diversity, t-closeness | limited | high | no | no | no |
| differential privacy | limited | high | yes | yes | yes |
| game-theoretic models | medium | low | yes | yes | yes |
| predicate singling out | high | low | no | yes | no |
Disclaimer/Publisher’s Note: The statements, opinions and data contained in all publications are solely those of the individual author(s) and contributor(s) and not of MDPI and/or the editor(s). MDPI and/or the editor(s) disclaim responsibility for any injury to people or property resulting from any ideas, methods, instructions or products referred to in the content. |
© 2026 by the authors. Licensee MDPI, Basel, Switzerland. This article is an open access article distributed under the terms and conditions of the Creative Commons Attribution (CC BY) license.
Share and Cite
Schenke, J.; Kneuper, R. Formalizing Anonymity for Software Development. Software 2026, 5, 21. https://doi.org/10.3390/software5020021
Schenke J, Kneuper R. Formalizing Anonymity for Software Development. Software. 2026; 5(2):21. https://doi.org/10.3390/software5020021
Chicago/Turabian StyleSchenke, Johanna, and Ralf Kneuper. 2026. "Formalizing Anonymity for Software Development" Software 5, no. 2: 21. https://doi.org/10.3390/software5020021
APA StyleSchenke, J., & Kneuper, R. (2026). Formalizing Anonymity for Software Development. Software, 5(2), 21. https://doi.org/10.3390/software5020021

