Differentially Private Inductive Miner

Fuente: arXiv
Salvato in:
Dettagli Bibliografici
Autori principali: Schulze, Max, Zisgen, Yorck, Kirschte, Moritz, Mohammadi, Esfandiar, Koschmider, Agnes
Natura: Preprint
Pubblicazione: 2024
Soggetti:
Accesso online:
Tags: Aggiungi Tag
Nessun Tag, puoi essere il primo ad aggiungerne!!
_version_ 1866908072787574784
author Schulze, Max
Zisgen, Yorck
Kirschte, Moritz
Mohammadi, Esfandiar
Koschmider, Agnes
author_facet Schulze, Max
Zisgen, Yorck
Kirschte, Moritz
Mohammadi, Esfandiar
Koschmider, Agnes
contents Protecting personal data about individuals, such as event traces in process mining, is an inherently difficult task since an event trace leaks information about the path in a process model that an individual has triggered. Yet, prior anonymization methods of event traces like k-anonymity or event log sanitization struggled to protect against such leakage, in particular against adversaries with sufficient background knowledge. In this work, we provide a method that tackles the challenge of summarizing sensitive event traces by learning the underlying process tree in a privacy-preserving manner. We prove via the so-called Differential Privacy (DP) property that from the resulting summaries no useful inference can be drawn about any personal data in an event trace. On the technical side, we introduce a differentially private approximation (DPIM) of the Inductive Miner. Experimentally, we compare our DPIM with the Inductive Miner on 14 real-world event traces by evaluating well-known metrics: fitness, precision, simplicity, and generalization. The experiments show that our DPIM not only protects personal data but also generates faithful process trees that exhibit little utility loss above the Inductive Miner.
format Preprint
id arxiv_https___arxiv_org_abs_2407_04595
institution arXiv
publishDate 2024
record_format arxiv
spellingShingle Differentially Private Inductive Miner
Schulze, Max
Zisgen, Yorck
Kirschte, Moritz
Mohammadi, Esfandiar
Koschmider, Agnes
Cryptography and Security
Databases
Protecting personal data about individuals, such as event traces in process mining, is an inherently difficult task since an event trace leaks information about the path in a process model that an individual has triggered. Yet, prior anonymization methods of event traces like k-anonymity or event log sanitization struggled to protect against such leakage, in particular against adversaries with sufficient background knowledge. In this work, we provide a method that tackles the challenge of summarizing sensitive event traces by learning the underlying process tree in a privacy-preserving manner. We prove via the so-called Differential Privacy (DP) property that from the resulting summaries no useful inference can be drawn about any personal data in an event trace. On the technical side, we introduce a differentially private approximation (DPIM) of the Inductive Miner. Experimentally, we compare our DPIM with the Inductive Miner on 14 real-world event traces by evaluating well-known metrics: fitness, precision, simplicity, and generalization. The experiments show that our DPIM not only protects personal data but also generates faithful process trees that exhibit little utility loss above the Inductive Miner.
title Differentially Private Inductive Miner
topic Cryptography and Security
Databases
url https://arxiv.org/abs/2407.04595