{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,3]],"date-time":"2026-05-03T10:59:16Z","timestamp":1777805956121,"version":"3.51.4"},"reference-count":52,"publisher":"SAGE Publications","issue":"2","license":[{"start":{"date-parts":[[2015,6,3]],"date-time":"2015-06-03T00:00:00Z","timestamp":1433289600000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/journals.sagepub.com\/page\/policies\/text-and-data-mining-license"}],"content-domain":{"domain":["journals.sagepub.com"],"crossmark-restriction":true},"short-container-title":["Journal of Computer Security"],"published-print":{"date-parts":[[2015,6,3]]},"abstract":"<jats:p>Abstract<\/jats:p>\n                  <jats:p>Data owners are expected to disclose micro-data for research, analysis, and various other purposes. In disclosing micro-data with sensitive attributes, the goal is usually two fold. First, the data utility of disclosed data should be maximized for analysis purposes. Second, the private information contained in such data must be to an acceptable level. Typically, a disclosure algorithm evaluates potential generalization functions in a predetermined order, and then discloses the first generalization that satisfies the desired privacy property. Recent studies show that adversarial inferences using knowledge about such disclosure algorithms can usually render the algorithm unsafe. In this paper, we show that an existing unsafe algorithm can be transformed into a large family of safe algorithms, namely, k-jump algorithms. We then prove that the data utility of different k-jump algorithms is generally incomparable. The comparison of data utility is independent of utility measures and syntactic privacy models. Finally, we analyze the computational complexity of k-jump algorithms, and confirm the necessity of safe algorithms even when a secret choice is made among algorithms.<\/jats:p>","DOI":"10.3233\/jcs-140514","type":"journal-article","created":{"date-parts":[[2015,7,1]],"date-time":"2015-07-01T11:52:55Z","timestamp":1435751575000},"page":"131-165","update-policy":"https:\/\/doi.org\/10.1177\/sage-journals-update-policy","source":"Crossref","is-referenced-by-count":2,"title":["<i>k<\/i>\n                    -jump: A strategy to design publicly-known algorithms for privacy preserving micro-data disclosure"],"prefix":"10.1177","volume":"23","author":[{"given":"Wen Ming","family":"Liu","sequence":"first","affiliation":[{"name":"Concordia University, Montreal, QC, Canada. E-mails:\u00a0,\u00a0"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Lingyu","family":"Wang","sequence":"additional","affiliation":[{"name":"Concordia University, Montreal, QC, Canada. E-mails:\u00a0,\u00a0"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Lei","family":"Zhang","sequence":"additional","affiliation":[{"name":"Google Inc., New York, NY, USA. E-mail:\u00a0"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Shunzhi","family":"Zhu","sequence":"additional","affiliation":[{"name":"Xiamen University of Technology, Xiamen, China. E-mail:\u00a0"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"179","published-online":{"date-parts":[[2015,6,3]]},"reference":[{"key":"ref001","doi-asserted-by":"publisher","DOI":"10.1145\/76894.76895"},{"key":"ref002","unstructured":"[2]G.\u00a0Aggarwal, T.\u00a0Feder, K.\u00a0Kenthapadi, R.\u00a0Motwani, R.\u00a0Panigrahy, D.\u00a0Thomas and A.\u00a0Zhu, k-anonymity: Algorithms and hardness, Technical report, Stanford University, 2004."},{"key":"ref003","doi-asserted-by":"crossref","unstructured":"[3]G.\u00a0Aggarwal, T.\u00a0Feder, K.\u00a0Kenthapadi, R.\u00a0Motwani, R.\u00a0Panigrahy, D.\u00a0Thomas and A.\u00a0Zhu, Anonymizing tables, in: ICDT\u201905, 2005, pp.\u00a0246\u2013258.","DOI":"10.1007\/978-3-540-30570-5_17"},{"key":"ref004","unstructured":"[4]G.\u00a0Aggarwal, T.\u00a0Feder, K.\u00a0Kenthapadi, R.\u00a0Motwani, R.\u00a0Panigrahy, D.\u00a0Thomas and A.\u00a0Zhu, Approximation algorithms for k-anonymity,\n                      Journal of Privacy Technology\n                      (2005), Paper number 20051120001."},{"key":"ref005","doi-asserted-by":"crossref","unstructured":"[5]R.J.\u00a0Bayardo and R.\u00a0Agrawal, Data privacy through optimal k-anonymization, in: ICDE, 2005, pp.\u00a0217\u2013228.","DOI":"10.1109\/ICDE.2005.42"},{"key":"ref006","doi-asserted-by":"publisher","DOI":"10.1145\/1121995.1121997"},{"key":"ref007","doi-asserted-by":"crossref","unstructured":"[7]S.\u00a0Chawla, C.\u00a0Dwork, F.\u00a0McSherry, A.\u00a0Smith and H.\u00a0Wee, Toward privacy in public databases, in: Theory of Cryptography Conference, 2005.","DOI":"10.1007\/978-3-540-30576-7_20"},{"key":"ref008","doi-asserted-by":"publisher","DOI":"10.1145\/5925.5928"},{"key":"ref009","doi-asserted-by":"crossref","unstructured":"[9]C.\u00a0Clifton and T.\u00a0Tassa, On syntactic anonymity and differential privacy, in: ICDEW\u201913, 2013, pp.\u00a088\u201393.","DOI":"10.1109\/ICDEW.2013.6547433"},{"key":"ref010","unstructured":"[10]L.H.\u00a0Cox, Solving confidentiality protection problems in tabulations using network optimization: A network model for cell suppression in the U.S. economic censuses, in: Proceedings of the International Seminar on Statistical Confidentiality, 1982."},{"key":"ref011","unstructured":"[11]L.H.\u00a0Cox, New results in disclosure avoidance for tabulations, in: International Statistical Institute Proceedings, 1987, pp.\u00a083\u201384."},{"key":"ref012","doi-asserted-by":"crossref","unstructured":"[12]L.H.\u00a0Cox, Suppression, methodology and statistical disclosure control,\n                      Journal of the American Statistical Association\n                      (1995), 377\u2013385.","DOI":"10.1080\/01621459.1980.10477481"},{"key":"ref013","doi-asserted-by":"publisher","DOI":"10.1016\/0378-3758(82)90058-1"},{"key":"ref014","unstructured":"[14]A.\u00a0Deutsch, Privacy in database publishing: a Bayesian perspective, in: Handbook of Database Security: Applications and Trends, Springer, 2007, pp.\u00a0464\u2013490."},{"key":"ref015","doi-asserted-by":"crossref","unstructured":"[15]A.\u00a0Deutsch and Y.\u00a0Papakonstantinou, Privacy in database publishing, in: ICDT, 2005, pp.\u00a0230\u2013245.","DOI":"10.1007\/978-3-540-30570-5_16"},{"key":"ref016","first-page":"363","volume":"26","author":"Diaconis P.","year":"1995","journal-title":"Annals of Statistics"},{"key":"ref017","doi-asserted-by":"publisher","DOI":"10.1145\/320064.320068"},{"key":"ref018","doi-asserted-by":"crossref","unstructured":"[18]A.\u00a0Dobra and S.E.\u00a0Feinberg, Bounding entries in multi-way contingency tables given a set of marginal totals, in: Foundations of Statistical Inference: Proceedings of the Shoresh Conference, 2000, Springer, 2003.","DOI":"10.1007\/978-3-642-57410-8_1"},{"key":"ref019","doi-asserted-by":"crossref","unstructured":"[19]Y.\u00a0Du, T.\u00a0Xia, Y.\u00a0Tao, D.\u00a0Zhang and F.\u00a0Zhu, On multidimensional k-anonymity with local recoding generalization, in: ICDE, 2007, pp.\u00a01422\u20131424.","DOI":"10.1109\/ICDE.2007.369026"},{"key":"ref020","unstructured":"[20]G.T.\u00a0Duncan and S.E.\u00a0Feinberg, Obtaining information while preserving privacy: A Markov perturbation method for tabular data, in: Joint Statistical Meetings, Anaheim, CA, 1997."},{"key":"ref021","doi-asserted-by":"crossref","unstructured":"[21]C.\u00a0Dwork, Differential privacy, in: ICALP (2), 2006, pp.\u00a01\u201312.","DOI":"10.1007\/11787006_1"},{"key":"ref022","doi-asserted-by":"crossref","unstructured":"[22]C.\u00a0Dwork, F.\u00a0Mcsherry, K.\u00a0Nissim and A.\u00a0Smith, Calibrating noise to sensitivity in private data analysis, in: TCC\u201906, 2006, pp.\u00a0265\u2013284.","DOI":"10.1007\/11681878_14"},{"key":"ref023","doi-asserted-by":"publisher","DOI":"10.1080\/01621459.1972.10481199"},{"key":"ref024","doi-asserted-by":"publisher","DOI":"10.1145\/1749603.1749605"},{"key":"ref025","doi-asserted-by":"crossref","unstructured":"[25]X.\u00a0Jin, N.\u00a0Zhang and G.\u00a0Das, Algorithm-safe privacy-preserving data publishing, in: EDBT\u201910, 2010, pp.\u00a0633\u2013644.","DOI":"10.1145\/1739041.1739116"},{"key":"ref026","doi-asserted-by":"publisher","DOI":"10.1016\/j.is.2011.03.001"},{"key":"ref027","doi-asserted-by":"crossref","unstructured":"[27]K.\u00a0Kenthapadi, N.\u00a0Mishra and K.\u00a0Nissim, Simulatable auditing, in: PODS, 2005, pp.\u00a0118\u2013127.","DOI":"10.1145\/1065167.1065183"},{"key":"ref028","doi-asserted-by":"crossref","unstructured":"[28]D.\u00a0Kifer and A.\u00a0Machanavajjhala, No free lunch in data privacy, in: SIGMOD\u201911, 2011, pp.\u00a0193\u2013204.","DOI":"10.1145\/1989323.1989345"},{"key":"ref029","doi-asserted-by":"crossref","unstructured":"[29]J.\u00a0Kleinberg, C.\u00a0Papadimitriou and P.\u00a0Raghavan, Auditing Boolean attributes, in: PODS, 2000, pp.\u00a086\u201391.","DOI":"10.1145\/335168.335210"},{"key":"ref030","doi-asserted-by":"crossref","unstructured":"[30]K.\u00a0LeFevre, D.\u00a0DeWitt and R.\u00a0Ramakrishnan, Incognito: Efficient full-domain k-anonymity, in: SIGMOD, 2005, pp.\u00a049\u201360.","DOI":"10.1145\/1066157.1066164"},{"key":"ref031","doi-asserted-by":"crossref","unstructured":"[31]N.\u00a0Li, T.\u00a0Li and S.\u00a0Venkatasubramanian, t-closeness: Privacy beyond k-anonymity and l-diversity, in: ICDE, 2007, pp.\u00a0106\u2013115.","DOI":"10.1109\/ICDE.2007.367856"},{"key":"ref032","doi-asserted-by":"crossref","unstructured":"[32]N.\u00a0Li, W.\u00a0Qardaji and D.\u00a0Su, On sampling, anonymization, and differential privacy or, k-anonymization meets differential privacy, in: ASIACCS\u201912, 2012, pp.\u00a032\u201333.","DOI":"10.1145\/2414456.2414474"},{"key":"ref033","unstructured":"[33]N.\u00a0Li, W.H.\u00a0Qardaji and D.\u00a0Su, Provably private data anonymization: Or, k-anonymity meets differential privacy, in:\n                      CoRR\n                      , 2011, abs\/1101.2604v1."},{"key":"ref034","doi-asserted-by":"crossref","unstructured":"[34]W.M.\u00a0Liu and L.\u00a0Wang, Privacy streamliner: a two-stage approach to improving algorithm efficiency, in: CODASPY, 2012, pp.\u00a0193\u2013204.","DOI":"10.1145\/2133601.2133626"},{"key":"ref035","doi-asserted-by":"crossref","unstructured":"[35]W.M.\u00a0Liu, L.\u00a0Wang and L.\u00a0Zhang,\n                      k\n                      -jump strategy for preserving privacy in micro-data disclosure, in: ICDT\u201910, 2010, pp.\u00a0104\u2013115.","DOI":"10.1145\/1804669.1804684"},{"key":"ref036","doi-asserted-by":"publisher","DOI":"10.1145\/1217299.1217302"},{"key":"ref037","doi-asserted-by":"crossref","unstructured":"[37]A.\u00a0Meyerson and R.\u00a0Williams, On the complexity of optimal k-anonymity, in: ACM PODS, 2004, pp.\u00a0223\u2013228.","DOI":"10.1145\/1055558.1055591"},{"key":"ref038","doi-asserted-by":"crossref","unstructured":"[38]G.\u00a0Miklau and D.\u00a0Suciu, A formal analysis of information disclosure in data exchange, in: SIGMOD, 2004, pp.\u00a0575\u2013586.","DOI":"10.1145\/1007568.1007633"},{"key":"ref039","doi-asserted-by":"publisher","DOI":"10.1109\/69.971193"},{"key":"ref040","doi-asserted-by":"crossref","unstructured":"[40]J.\u00a0Schlorer, Identification and retrieval of personal records from a statistical bank, in: Methods Info. Med., 1975, pp.\u00a07\u201313.","DOI":"10.1055\/s-0038-1635690"},{"key":"ref041","doi-asserted-by":"crossref","unstructured":"[41]A.\u00a0Slavkovic and S.E.\u00a0Feinberg, Bounds for cell entries in two-way tables given conditional relative frequencies, in: Privacy in Statistical Databases, 2004.","DOI":"10.1007\/978-3-540-25955-8_3"},{"key":"ref042","doi-asserted-by":"publisher","DOI":"10.1142\/S0218488502001648"},{"key":"ref043","doi-asserted-by":"crossref","unstructured":"[43]R.C.\u00a0Wong and A.W.\u00a0Fu, Privacy-Preserving Data Publishing: An Overview, Morgan and Claypool Publishers, 2010.","DOI":"10.1007\/978-3-031-01834-3"},{"key":"ref044","unstructured":"[44]R.C.\u00a0Wong, A.W.\u00a0Fu, K.\u00a0Wang and J.\u00a0Pei, Minimality attack in privacy preserving data publishing, in: VLDB, 2007, pp.\u00a0543\u2013554."},{"key":"ref045","doi-asserted-by":"crossref","unstructured":"[45]R.C.\u00a0Wong, J.\u00a0Li, A.\u00a0Fu and K.\u00a0Wang, (\n                      \u03b1\n                      -\n                      k\n                      )-anonymity: An enhanced\n                      k\n                      -anonymity model for privacy-preserving data publishing, in: KDD, 2006, pp.\u00a0754\u2013759.","DOI":"10.1145\/1150402.1150499"},{"key":"ref046","doi-asserted-by":"crossref","unstructured":"[46]X.\u00a0Xiao and Y.\u00a0Tao, Personalized privacy preservation, in: SIGMOD, 2006, pp.\u00a0229\u2013240.","DOI":"10.1145\/1142473.1142500"},{"key":"ref047","doi-asserted-by":"crossref","unstructured":"[47]X.\u00a0Xiao and Y.\u00a0Tao, Anatomy: Simple and effective privacy preservation, in: VLDB\u201906, 2006, pp.\u00a0139\u2013150.","DOI":"10.1145\/1142473.1142500"},{"key":"ref048","doi-asserted-by":"publisher","DOI":"10.1145\/1735886.1735887"},{"key":"ref049","doi-asserted-by":"crossref","unstructured":"[49]X.\u00a0Xiao, G.\u00a0Wang and J.\u00a0Gehrke, Differential privacy via wavelet transforms, in: ICDE\u201910, 2010, pp.\u00a0225\u2013236.","DOI":"10.1109\/ICDE.2010.5447831"},{"key":"ref050","doi-asserted-by":"crossref","unstructured":"[50]L.\u00a0Zhang, S.\u00a0Jajodia and A.\u00a0Brodsky, Information disclosure under realistic assumptions: privacy versus optimality, in: CCS, 2007, pp.\u00a0573\u2013583.","DOI":"10.1145\/1315245.1315316"},{"key":"ref051","doi-asserted-by":"crossref","unstructured":"[51]L.\u00a0Zhang, L.\u00a0Wang, S.\u00a0Jajodia and A.\u00a0Brodsky, Exclusive strategy for generalization algorithms in micro-data disclosure, in: Data and Applications Security XXII, Lecture Notes in Computer Science, Vol.\u00a05094, Springer, 2008, pp.\u00a0190\u2013204.","DOI":"10.1007\/978-3-540-70567-3_15"},{"key":"ref052","doi-asserted-by":"crossref","unstructured":"[52]L.\u00a0Zhang, L.\u00a0Wang, S.\u00a0Jajodia and A.\u00a0Brodsky, L-cover: Preserving diversity by anonymity, in: SDM\u201909, 2009, pp.\u00a0158\u2013171.","DOI":"10.1007\/978-3-642-04219-5_10"}],"container-title":["Journal of Computer Security"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/journals.sagepub.com\/doi\/pdf\/10.3233\/JCS-140514","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/journals.sagepub.com\/doi\/full-xml\/10.3233\/JCS-140514","content-type":"application\/xml","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/journals.sagepub.com\/doi\/pdf\/10.3233\/JCS-140514","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,4,29]],"date-time":"2026-04-29T20:44:51Z","timestamp":1777495491000},"score":1,"resource":{"primary":{"URL":"https:\/\/journals.sagepub.com\/doi\/10.3233\/JCS-140514"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2015,6,3]]},"references-count":52,"journal-issue":{"issue":"2","published-print":{"date-parts":[[2015,6,3]]}},"alternative-id":["10.3233\/JCS-140514"],"URL":"https:\/\/doi.org\/10.3233\/jcs-140514","relation":{},"ISSN":["0926-227X","1875-8924"],"issn-type":[{"value":"0926-227X","type":"print"},{"value":"1875-8924","type":"electronic"}],"subject":[],"published":{"date-parts":[[2015,6,3]]}}}