Internet Security

Privacy researchers devise a noise-exploitation attack that defeats dynamic anonymity

Privacy researchers in Europe believe they have the first proof that a long-theorised vulnerability in systems designed to protect privacy by aggregating and adding noise to data to mask individual identities is no longer just a theory. The research has implications for the immediate field of differential privacy and beyond — raising wide-ranging questions about…


Privacy researchers in Europe believe they have the first proof that a long-theorised vulnerability in systems designed to protect privacy by aggregating and adding noise to data to mask individual identities is no longer just a theory.

The research has implications for the immediate field of differential privacy and beyond — raising wide-ranging questions about how privacy is regulated if anonymization only works until a determined attacker figures out how to reverse the method that’s being used to dynamically fuzz the data.

Current EU law doesn’t recognise anonymous data as personal data. Although it does treat pseudoanonymized data as personal data because of the risk of re-identification.

Yet a growing body of research suggests the risk of de-anonymization on high dimension data sets is persistent. Even — per this latest research — when a database system has been very carefully designed with privacy protection in mind.

It suggests the entire business of protecting privacy needs to get a whole lot more dynamic to respond to the risk of perpetually evolving attacks.

Academics from Imperial College London and Université Catholique de Louvain are behind the new research.

This week, at the 28th USENIX Security Symposium, they presented a paper detailing a new class of noise-exploitation attacks on a query-based database that uses aggregation and noise injection to dynamically mask personal data.

The product they were looking at is a database querying framework, called Diffix — jointly developed by a German startup called Aircloak andtheMax Planck Institute for Software Systems.

On its website Aircloak bills the technology as “the first GDPR-grade anonymization” — aka Europe’s General Data Protection Regulation, which began being applied last year, raising the bar for privacy compliance by introducing a data protection regime that includes fines that can scale up to 4% of a data processor’s global annual turnover.

What Aircloak is essentially offering is to manage GDPR risk by providing anonymity as a commercial service — allowing queries to be run on a data-set that let analysts gain valuable insights without accessing the data itself.The promise being it’s privacy (and GDPR) ‘safe’ because it’s designed to mask individual identities by returning anonymized results.

The problem is personal data that’s re-identifiable isn’t anonymous data. And the researchers were able to craft attacks that undo Diffix’s dynamic anonymity — although Aircloak is confident it has already prevented this attack.

“What we did here is we studied the system and we showed that actually there is a vulnerability that exists in their system that allows us to use their system and to send carefully created queries that allow us to extract — to exfiltrate — information from the data-set that the system is supposed to protect,” explains Imperial College’s Yves-Alexandre de Montjoye, one of five co-authors of the research paper.

“Differential privacy really shows that every time you answer one of my questions you’re giving me information and at some point — to the extreme — if you keep answering every single one of my questions I will ask you so many questions that at some point I will have figured out every single thing that exists in the database because every time you give me a bit more information,” he says of the pre

Read More

Be the first to write a comment.

Leave a Reply

Your email address will not be published. Required fields are marked *

Internet Security

Niger Miners’ Deaths: CSOs Demand Transparent Probe, Caution Against Speculation

A coalition of civil society organisations led by Stand Up Nigeria (SUN) has appealed to Nigerians to remain calm and avoid spreading unverified information on social media over the deaths of 37 suspected illegal miners in the custody of the Nigeria Security and Civil Defence Corps (NSCDC) in Niger State…

A coalition of civil society organisations led by Stand Up Nigeria (SUN) has appealed to Nigerians to remain calm and avoid spreading unverified information on social media over the deaths of 37 suspected illegal miners in the custody of the Nigeria Security and Civil Defence Corps (NSCDC) in Niger State…
Read More

Continue Reading
Internet Security

Artists can express humanitarian concerns, but not undermine public order and security: Tan Kiat How

Advertisement Singapore Artistes can express humanitarian concerns, but not undermine public order and security: Tan Kiat How Senior Minister of State Tan Kiat How cited several performances dealing with social and humanitarian issues that had been allowed to proceed in Singapore. Robert Del Naja and Grant Marshall from Massive Attack stand with a Palestinian flag

Advertisement

Singapore

Artistes can express humanitarian concerns, but not undermine public order and security: Tan Kiat How

Senior Minister of State Tan Kiat How cited several performances dealing with social and humanitarian issues that had been allowed to proceed in Singapore.

Artistes can express humanitarian concerns, but not undermine public order and security: Tan Kiat How

Robert Del Naja and Grant Marshall from Massive Attack stand with a Palestinian flag onstage at the end of their performance in Singapore, July 29, 2026, in this screengrab from video obtained from social media. Simran Panaech/via REUTERS


New: You can now listen to articles.


This audio is generated by an AI tool.

Justin Ong Guang-Xi

Justin Ong Guang-Xi

Justin Ong Guang-Xi

10 Sep 2026 01:42PM
(Updated: 10 Sep 2026 02:06PM)



Bookmark



Bookmark



Share

SINGAPORE: Artistes can express humanitarian concerns about international conflicts, but such expression should not undermine public order, security or stability in Singapore, Senior Minister of State for Digital Development and Information Tan Kiat How said on Thursday (Sep 10).

“Singapore should not be used by foreigners as a platform to further political causes, including those relating to conflicts or political issues overseas,” he said.

Artistes, whether Singaporean or foreign, are expected to abide by Singapore’s laws and the conditions of the arts entertainment licence when performing here, he added.

Mr Tan was responding in parliament to MP Hazlina Abdul Halim (PAP-East Coast), who asked how authorities distinguish prohibited political advocacy from expressions of humanitarian concern.

CNA Games
Guess Word
Guess Word
Crack the word, one row at a time

Buzzword
Buzzword
Create words using the given letters

Mini Sudoku
Mini Sudoku
Tiny puzzle, mighty brain teaser

Mini Crossword
Mini Crossword
Small grid, big challenge

Word Search
Word Search
Spot as many words as you can

Show More

Show Less

She also asked how an artiste’s intent and the context of an expression are taken into account, and whether licensing conditions would be reviewed to exclude peaceful expressions of support for humanitarian causes.

Mr Tan said that besides an artiste’s intention, the Infocomm Media Development Authority (IMDA) considers the likely impact of a performance when assessing whether it meets licensing conditions.

Under IMDA’s Arts Entertainment Classification Code, content should not undermine public order, national security or stability.

The code, which sets out the framework for assessing and classifying live or public arts entertainment, also states that content should be “sensitive to the concerns of different racial or religious groups and the prevailing community expectations of what is necessary to safeguard racial harmony and religious harmony”.

In July, members of British band Massive Attack were issued stern warnings and barred from re-entering Singapore after flying a Palestinian flag during a concert, with one of the members shouting “Free Palestine”.


06:31 Min

The government recognises the humanitarian impact of international conflicts and that artistes may wish to express concern for those affected. Such expressions are not prohibited but should not undermine public order, national security or stability in Singapore. This condition is made clear in the Arts Entertainment Classification Code issued by the Infocomm Media Development Authority. Senior Minister of State for Digital Development and Information Tan Kiat How highlighted this approach in reply to an MP’s questions in parliament on Thursday (Sep 10). He stressed that Singapore should not be used by foreigners as a platform to further political causes, including those relating to conflicts or political issues overseas. 

Ms Hazlina asked Mr Tan for examples of performances involving social causes that had been allowed to take place.

He cited To The Unforgotten, an event held in May this year that featured a song, poem and multimedia artwork about the Israel-Gaza conflict. It was classified R18.

Another example was 6 Microlectures on Genocides. Also classified R18, the play comprised short works that explore themes of genocide, war crimes and contemporary conflicts, Mr Tan said.

He also pointed to the 2024 stand-up comedy show Namaste, which was classified Advisory 16 and included a segment in which comedians spoke about the Israel-Gaza conflict.

“So having material and content on causes itself is not prohibited, and the licensing framework is designed to, of course, protect young people from unwanted content, but also allow people to make decisions on what they can watch,” said Mr Tan.

“But at the same time, having some boundaries on the kind of content that may stir up public disorder or national security considerations.”

Mr Tan said assessments were “very contextual” and encouraged applicants for Arts Entertainment Licences to engage IMDA early.

“The earlier the applicants engage IMDA, the earlier conversations can start, and earlier we can give clarity and guidance on the kind of content that may be approved and

!–>!–>
Read More

Continue Reading
Internet Security

Trezor Email Provider Breached in Phishing Attack Targeting Crypto Users

Trezor warned users that attackers used a compromised third-party email provider to send a fake STM32 security alert, a phishing scam that also hit rival BitBox and other Bitcoin companies. The post Trezor Email Provider Breached in Phishing Attack Targeting Crypto Users appeared first on Crypto News Australia…

Trezor warned users that attackers used a compromised third-party email provider to send a fake STM32 security alert, a phishing scam that also hit rival BitBox and other Bitcoin companies.
The post Trezor Email Provider Breached in Phishing Attack Targeting Crypto Users appeared first on Crypto News Australia…
Read More

Continue Reading
Internet Security

Liquid ‘white hats’ return $270M in Bitcoin as network prepares restart

The actors returned 85% of the Bitcoin withdrawn from Liquid’s federation wallet following the security incident…

The actors returned 85% of the Bitcoin withdrawn from Liquid’s federation wallet following the security incident…
Read More

Continue Reading