{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,3,31]],"date-time":"2026-03-31T18:45:25Z","timestamp":1774982725756,"version":"3.50.1"},"reference-count":68,"publisher":"Association for Computing Machinery (ACM)","issue":"6","license":[{"start":{"date-parts":[[2024,12,18]],"date-time":"2024-12-18T00:00:00Z","timestamp":1734480000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"funder":[{"name":"German Federal Ministry for Education and Research","award":["01IS18025A"],"award-info":[{"award-number":["01IS18025A"]}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Proc. ACM Manag. Data"],"published-print":{"date-parts":[[2024,12,18]]},"abstract":"<jats:p>In today's data-driven world, organizations face increasing pressure to comply with data disclosure policies, which require data masking measures and robust access control mechanisms. This paper presents Mascara, a middleware for specifying and enforcing data disclosure policies. Mascara extends traditional access control mechanisms with data masking to support partial disclosure of sensitive data. We introduce data masks to specify disclosure policies flexibly and intuitively and propose a query modification approach to rewrite user queries into disclosure-compliant ones. We present a utility estimation framework to estimate the information loss of masked data based on relative entropy, which Mascara leverages to select the disclosure-compliant query that minimizes information loss. Our experimental evaluation shows that Mascara effectively chooses the best disclosure-compliant query with a success rate exceeding 90%, ensuring users get data with the lowest possible information loss. Additionally, Mascara's overhead compared to normal execution without data protection is negligible, staying lower than 300ms even for extreme scenarios with hundreds of possible disclosure-compliant queries.<\/jats:p>","DOI":"10.1145\/3698808","type":"journal-article","created":{"date-parts":[[2024,12,20]],"date-time":"2024-12-20T16:40:35Z","timestamp":1734712835000},"page":"1-28","source":"Crossref","is-referenced-by-count":2,"title":["Disclosure-Compliant Query Answering"],"prefix":"10.1145","volume":"2","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-1022-9015","authenticated-orcid":false,"given":"Rudi","family":"Poepsel-Lemaitre","sequence":"first","affiliation":[{"name":"BIFOLD &amp; Technische Universit\u00e4t Berlin, Berlin, Germany"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0009-0006-2322-4527","authenticated-orcid":false,"given":"Kaustubh","family":"Beedkar","sequence":"additional","affiliation":[{"name":"Indian Institute of Technology Delhi, Delhi, India"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0009-0009-0964-026X","authenticated-orcid":false,"given":"Volker","family":"Markl","sequence":"additional","affiliation":[{"name":"BIFOLD &amp; Technische Universit\u00e4t Berlin, Berlin, Germany"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2024,12,20]]},"reference":[{"key":"e_1_2_2_1_1","unstructured":"2018. California Consumer Privacy Act (CCPA). https:\/\/www.caprivacy.org\/"},{"key":"e_1_2_2_2_1","unstructured":"2018. General Data Protection Regulation (GDPR). https:\/\/gdpr-info.eu\/"},{"key":"e_1_2_2_3_1","unstructured":"2018. General Data Protection Regulation (GDPR): Recital 26. https:\/\/gdpr-info.eu\/recitals\/no-26\/"},{"key":"e_1_2_2_4_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.tcs.2010.12.031"},{"key":"e_1_2_2_5_1","doi-asserted-by":"publisher","DOI":"10.1016\/B978-012088469-8.50047-4"},{"key":"e_1_2_2_6_1","doi-asserted-by":"publisher","DOI":"10.5555\/1287369.1287383"},{"key":"e_1_2_2_7_1","volume-title":"Amazon Redshift: Dynamic data masking. Retrieved","author":"Redshift Amazon","year":"2024","unstructured":"Amazon Redshift. 2024. Amazon Redshift: Dynamic data masking. Retrieved April 5, 2024 from https:\/\/docs.aws.amazon.com\/redshift\/latest\/dg\/t_ddm.html"},{"key":"e_1_2_2_8_1","doi-asserted-by":"publisher","DOI":"10.14778\/3476311.3476359"},{"key":"e_1_2_2_9_1","first-page":"50","article-title":"Navigating Compliance with Data Transfers in Federated Data Processing","volume":"45","author":"Beedkar Kaustubh","year":"2022","unstructured":"Kaustubh Beedkar, Jorge-Arnulfo Quian\u00e9-Ruiz, and Volker Markl. 2022. Navigating Compliance with Data Transfers in Federated Data Processing. IEEE Data Eng. Bull. 45, 1 (2022), 50--61.","journal-title":"IEEE Data Eng. Bull."},{"key":"e_1_2_2_10_1","doi-asserted-by":"publisher","DOI":"10.1145\/3448016.3453687"},{"key":"e_1_2_2_11_1","doi-asserted-by":"publisher","DOI":"10.1145\/3183713.3190662"},{"key":"e_1_2_2_12_1","doi-asserted-by":"publisher","DOI":"10.1007\/s00778-006-0023-0"},{"key":"e_1_2_2_13_1","doi-asserted-by":"publisher","DOI":"10.1145\/3299869.3319894"},{"key":"e_1_2_2_14_1","doi-asserted-by":"publisher","DOI":"10.1108\/TQM-02--2021-0061"},{"key":"e_1_2_2_15_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.bdr.2015.08.001"},{"key":"e_1_2_2_16_1","doi-asserted-by":"publisher","unstructured":"Dorothy E. Denning Selim G. Akl Matthew Morgenstern Peter G Neumann Roger R. Schell and Mark Heckman. 1986. Views for Multilevel Database Security. (1986) 156--156. https:\/\/doi.org\/10.1109\/SP.1986.10012","DOI":"10.1109\/SP.1986.10012"},{"key":"e_1_2_2_17_1","volume-title":"11th Conference on Innovative Data Systems Research, CIDR 2021, Virtual Event, January 11--15, 2021, Online Proceedings. www.cidrdb.org. http:\/\/cidrdb.org\/cidr2021\/papers\/cidr2021_paper24","author":"Deshpande Amol","year":"2021","unstructured":"Amol Deshpande. 2021. Sypse: Privacy-first Data Management through Pseudonymization and Partitioning. In 11th Conference on Innovative Data Systems Research, CIDR 2021, Virtual Event, January 11--15, 2021, Online Proceedings. www.cidrdb.org. http:\/\/cidrdb.org\/cidr2021\/papers\/cidr2021_paper24.pdf"},{"key":"e_1_2_2_18_1","volume-title":"Retiring Adult: New Datasets for Fair Machine Learning.","author":"Ding Frances","year":"2021","unstructured":"Frances Ding, Moritz Hardt, John Miller, and Ludwig Schmidt. 2021. Retiring Adult: New Datasets for Fair Machine Learning. (2021), 6478--6490. https:\/\/proceedings.neurips.cc\/paper\/2021\/hash\/32e54441e6382a7fbacbbbaf3c450059-Abstract.html"},{"key":"e_1_2_2_19_1","doi-asserted-by":"publisher","DOI":"10.1007\/11787006_1"},{"key":"e_1_2_2_20_1","first-page":"48","article-title":"Query processing with K-anonymity","volume":"3","author":"Eltabakh Mohamed Y","year":"2012","unstructured":"Mohamed Y Eltabakh, Jalaja Padma, Yasin N Silva, Pei He, Walid G Aref, and Elisa Bertino. 2012. Query processing with K-anonymity. International Journal of Data Engineering (IJDE) 3, 2 (2012), 48--65.","journal-title":"International Journal of Data Engineering (IJDE)"},{"key":"e_1_2_2_21_1","doi-asserted-by":"publisher","DOI":"10.1145\/501978.501980"},{"key":"e_1_2_2_22_1","doi-asserted-by":"publisher","DOI":"10.1145\/3336191.3371856"},{"key":"e_1_2_2_23_1","unstructured":"Federal Institute for Drugs and Medical Devices (BfArM). 2023. International Statistical Classification of Diseases - German Modification (ICD-10-GM). https:\/\/www.bfarm.de\/EN\/Code-systems\/Classifications\/ICD\/ICD-10-GM\/_node.html"},{"key":"e_1_2_2_24_1","doi-asserted-by":"publisher","DOI":"10.1109\/LICS.2015.35"},{"key":"e_1_2_2_25_1","doi-asserted-by":"publisher","DOI":"10.1145\/2902251.2902288"},{"key":"e_1_2_2_26_1","doi-asserted-by":"publisher","DOI":"10.1145\/369275.369284"},{"key":"e_1_2_2_27_1","doi-asserted-by":"publisher","DOI":"10.1007\/s007780100054"},{"key":"e_1_2_2_28_1","doi-asserted-by":"publisher","DOI":"10.14778\/3503585.3503586"},{"key":"e_1_2_2_29_1","doi-asserted-by":"publisher","DOI":"10.1137\/1.9781611974973.75"},{"key":"e_1_2_2_30_1","volume-title":"The 15 biggest data breaches of the 21st century. https:\/\/www.csoonline.com\/article\/2130877\/the-biggest-data-breaches-of-the-21st-century.html","author":"Hill Michael","unstructured":"Michael Hill and Dan Swinhoe. 2021. The 15 biggest data breaches of the 21st century. https:\/\/www.csoonline.com\/article\/2130877\/the-biggest-data-breaches-of-the-21st-century.html"},{"key":"e_1_2_2_31_1","volume-title":"User Guide. Retrieved","author":"IBM Corporation","year":"2024","unstructured":"IBM Corporation. 2024. DB2 Version 12.1: User Guide. Retrieved April 5, 2024 from https:\/\/www.ibm.com\/docs\/en\/db2"},{"key":"e_1_2_2_32_1","volume-title":"Java Microbenchmark Harness (JMH). Retrieved","author":"JMH","year":"2024","unstructured":"JMH 2023. Java Microbenchmark Harness (JMH). Retrieved April 5, 2024 from https:\/\/github.com\/openjdk\/jmh"},{"key":"e_1_2_2_33_1","doi-asserted-by":"publisher","DOI":"10.14778\/3489496.3489516"},{"key":"e_1_2_2_34_1","doi-asserted-by":"publisher","DOI":"10.14778\/3342263.3342274"},{"key":"e_1_2_2_35_1","volume-title":"On information and sufficiency. The annals of mathematical statistics 22, 1","author":"Kullback Solomon","year":"1951","unstructured":"Solomon Kullback and Richard A Leibler. 1951. On information and sufficiency. The annals of mathematical statistics 22, 1 (1951), 79--86."},{"key":"e_1_2_2_36_1","unstructured":"Dalibo Labs. [n. d.]. Anonymization Data Masking for PostgreSQL. https:\/\/postgresql-anonymizer.readthedocs.io\/en\/ stable\/"},{"key":"e_1_2_2_37_1","volume-title":"8th Biennial Conference on Innovative Data Systems Research, CIDR","author":"Leis Viktor","year":"2017","unstructured":"Viktor Leis, Bernhard Radke, Andrey Gubichev, Alfons Kemper, and Thomas Neumann. 2017. Cardinality Estimation Done Right: Index-Based Join Sampling. In 8th Biennial Conference on Innovative Data Systems Research, CIDR 2017, Chaminade, CA, USA, January 8--11, 2017, Online Proceedings. www.cidrdb.org. http:\/\/cidrdb.org\/cidr2017\/papers\/p9-leis-cidr17.pdf"},{"key":"e_1_2_2_38_1","doi-asserted-by":"publisher","DOI":"10.1145\/1807085.1807104"},{"key":"e_1_2_2_39_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.apenergy.2023.121217"},{"key":"e_1_2_2_40_1","doi-asserted-by":"publisher","DOI":"10.1109\/FOCS.2007.66"},{"key":"e_1_2_2_41_1","unstructured":"Microsoft. [n. d.]. Dynamic Data Masking. https:\/\/learn.microsoft.com\/en-us\/azure\/azure-sql\/database\/dynamic-datamasking-overview?view=azuresql"},{"key":"e_1_2_2_42_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICDE.1989.47234"},{"key":"e_1_2_2_43_1","doi-asserted-by":"publisher","DOI":"10.1145\/1806907.1806913"},{"key":"e_1_2_2_44_1","doi-asserted-by":"publisher","DOI":"10.14778\/3583140.3583164"},{"key":"e_1_2_2_45_1","unstructured":"Oracle. [n. d.]. Oracle Data Masking and Subsetting. https:\/\/www.oracle.com\/security\/database-security\/data-masking\/"},{"key":"e_1_2_2_46_1","doi-asserted-by":"publisher","DOI":"10.1145\/3478290"},{"key":"e_1_2_2_47_1","doi-asserted-by":"publisher","DOI":"10.14778\/3407790.3407835"},{"key":"e_1_2_2_48_1","doi-asserted-by":"publisher","DOI":"10.14778\/3551793.3551805"},{"key":"e_1_2_2_49_1","doi-asserted-by":"publisher","DOI":"10.1145\/1938551.1938580"},{"key":"e_1_2_2_50_1","volume-title":"Giuseppe Migliara, Katrin Glocker, Ilona Binenbaum,Walter Ricciardi, and Stefania Boccia.","author":"Pastorino Roberta","year":"2019","unstructured":"Roberta Pastorino, Corrado De Vito, Giuseppe Migliara, Katrin Glocker, Ilona Binenbaum,Walter Ricciardi, and Stefania Boccia. 2019. Benefits and challenges of Big Data in healthcare: an overview of the European initiatives. European journal of public health 29, Supplement_3 (2019), 23--27."},{"key":"e_1_2_2_51_1","unstructured":"PostgreSQL 2023. PL\/pgSQL - SQL Procedural Language. Retrieved April 5 2024 from https:\/\/www.postgresql.org\/docs\/current\/plpgsql.html"},{"key":"e_1_2_2_52_1","doi-asserted-by":"publisher","DOI":"10.1002\/spe.2812"},{"key":"e_1_2_2_53_1","unstructured":"MEDIA Protocol. 2018. What The Facebook\/Cambridge Analytica Scandal Means To The Digital Content Ecosystem. https:\/\/medium.com\/@mediaprotocolsm\/what-the-facebook-cambridge-analytica-scandal-means-to-the-digitalcontent-ecosystem-7ddcba19761"},{"key":"e_1_2_2_54_1","doi-asserted-by":"publisher","DOI":"10.1145\/1007568.1007631"},{"key":"e_1_2_2_55_1","doi-asserted-by":"publisher","DOI":"10.1109\/35.312842"},{"key":"e_1_2_2_56_1","doi-asserted-by":"publisher","DOI":"10.1016\/S0065-2458(08)60206-5"},{"key":"e_1_2_2_57_1","doi-asserted-by":"publisher","DOI":"10.1145\/3316416.3316420"},{"key":"e_1_2_2_58_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-981-99-7677-5_4"},{"key":"e_1_2_2_59_1","first-page":"737","article-title":"Risk and anxiety: A theory of data-breach harms","volume":"96","author":"Solove Daniel J","year":"2017","unstructured":"Daniel J Solove and Danielle Keats Citron. 2017. Risk and anxiety: A theory of data-breach harms. Tex. L. Rev. 96 (2017), 737.","journal-title":"Tex. L. Rev."},{"key":"e_1_2_2_60_1","doi-asserted-by":"publisher","DOI":"10.1145\/16856.16888"},{"key":"e_1_2_2_61_1","volume-title":"Technical Report","author":"Transaction Processing Performance Council","year":"2024","unstructured":"Transaction Processing Performance Council. 2017. TPC Benchmark H (Decision Support) Standard Specification. Technical Report. Transaction Processing Performance Council. http:\/\/www.tpc.org\/tpch\/ Accessed: 2024-04--16."},{"key":"e_1_2_2_62_1","doi-asserted-by":"publisher","DOI":"10.1145\/2723372.2723721"},{"key":"e_1_2_2_63_1","doi-asserted-by":"publisher","DOI":"10.1145\/3448016.3452808"},{"key":"e_1_2_2_64_1","volume-title":"Data-driven solutions to transportation problems","author":"Wang Yinhai","unstructured":"Yinhai Wang and Ziqiang Zeng. 2018. Data-driven solutions to transportation problems. Elsevier."},{"key":"e_1_2_2_65_1","doi-asserted-by":"publisher","DOI":"10.1145\/3588721"},{"key":"e_1_2_2_66_1","doi-asserted-by":"publisher","DOI":"10.14778\/3551793.3551861"},{"key":"e_1_2_2_67_1","doi-asserted-by":"publisher","DOI":"10.14778\/3430915.3430927"},{"key":"e_1_2_2_68_1","doi-asserted-by":"publisher","DOI":"10.14778\/3461535.3461539"}],"container-title":["Proceedings of the ACM on Management of Data"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3698808","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3698808","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,3,31]],"date-time":"2026-03-31T17:46:31Z","timestamp":1774979191000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3698808"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024,12,18]]},"references-count":68,"journal-issue":{"issue":"6","published-print":{"date-parts":[[2024,12,18]]}},"alternative-id":["10.1145\/3698808"],"URL":"https:\/\/doi.org\/10.1145\/3698808","relation":{},"ISSN":["2836-6573"],"issn-type":[{"value":"2836-6573","type":"electronic"}],"subject":[],"published":{"date-parts":[[2024,12,18]]}}}