Auditing Sum Queries

  • Francesco M. Malvestuto
  • Mauro Mezzini
Conference paper
Part of the Lecture Notes in Computer Science book series (LNCS, volume 2572)


In an on-line statistical database, the query system should leave unanswered queries asking for sums that could lead to the disclosure of confidential data. To check that, every sum query and previously answered sum queries should be audited. We show that, under a suitable query-overlap restriction, an auditing procedure can be efficiently worked out using flownetwork computation.


Unable to display preview. Download preview PDF.

Unable to display preview. Download preview PDF.


  1. 1.
    Adam, N.R., Wortmann, J.C.: Security control methods for statistical databases: a comparative study. ACM Computing Surveys 21 (1989) 515–556.CrossRefGoogle Scholar
  2. 2.
    Ahuja, R.K., Magnanti, T.L., Orlin, J.B.: Network flows. Prentice Hall, Englewood Cliffs, 1993.Google Scholar
  3. 3.
    Chin, F.Y., Ozsoyoglu, G.: Auditing and inference control in statistical databases. IEEE Trans. on Software Engineering 8 (1982) 574–582.CrossRefMathSciNetGoogle Scholar
  4. 4.
    Conforti, M., Rao, M.R.: Some new matroids on graphs: cut sets and the max cut problem. Mathematics of Operations Research 12 (1987) 193–204.MATHMathSciNetCrossRefGoogle Scholar
  5. 5.
    Cox, L.H.: Suppression methodology and statistical disclosure control. J. American Statistical Association 75 (1980) 377–385.MATHCrossRefGoogle Scholar
  6. 6.
    Cox, L.H., Zayatz, L.V.: An agenda for research on statistical disclosure limitation. J. Official Statistics 11 (1995) 205–220.Google Scholar
  7. 7.
    Gusfield, D.: A graph-theoretic approach to statistical data security. SIAM J. Computing 17 (1988) 552–571.MATHCrossRefMathSciNetGoogle Scholar
  8. 8.
    Kleinberg, J.M., Papadimitriou, C.H., Raghavan, P.: Auditing Boolean attributes. Proc. XIX ACM Symp. on “Principles of Database Systems” (2000) 86–91.Google Scholar
  9. 9.
    Malvestuto, F.M., Mezzini, M.: A linear algorithm for finding the invariant edges of an edge-weighted graph. SIAM J. on Computing 31 (2002) 1438–1455.MATHCrossRefMathSciNetGoogle Scholar
  10. 10.
    Malvestuto, F.M., Mezzini, M.: On the hardness of protecting sensitive information in a statistical database. Proc. World Multiconference on “Systemics, Cybernetics and Informatics”, vol. XIV (2001) 504–509.Google Scholar
  11. 11.
    Malvestuto, F.M., Moscarini, M.: Query evaluability in statistical databases. IEEE Transactions on Knowledge and Data Engineering 2 (1990) 425–430.CrossRefGoogle Scholar
  12. 12.
    Malvestuto, F.M., Moscarini, M.: An audit expert for large statistical databases. In Statistical Data Protection. EUROSTAT (1999) 29–43.Google Scholar
  13. 13.
    Willenborg, L., de Waal, T.: Statistical Disclosure Control in Practice. Lecture Notes in Statistics, Vol. 111. Springer-Verlag, New York (1996).MATHGoogle Scholar
  14. 14.
    Willenborg, L., de Waal, T.: Elements of Statistical Disclosure. Lecture Notes in Statistics, Vol. 155. Springer-Verlag, New York (2000).Google Scholar

Copyright information

© Springer-Verlag Berlin Heidelberg 2003

Authors and Affiliations

  • Francesco M. Malvestuto
    • 1
  • Mauro Mezzini
    • 2
  1. 1.Dipartimento di InformaticaUniversità “La Sapienza”RomaItaly
  2. 2.Telecom ItaliaRomaItaly

Personalised recommendations