another well-known solution to prevent membership
inference in aggregated datasets. Differentially pri-
vate mechanisms introduce noise in order to minimize
changes in the data distribution caused by adding or
removing a user. However, differential privacy typi-
cally cannot be applied to data collections as small as
lifelogging datasets (Section 1).
More recent works have identified adversarial
neural networks as a solution to protect time series
data collected from smartphones (Malekzadeh et al.,
2019). Such networks train a release mechanism that
is used to “sanitize” the samples, concealing personal
information. Their effectiveness on mobile sensor
data suggests that they may also be used to anonymize
fitness records from wearables.
We demonstrated that it is possible for the adversary
to de-anonymize the records of anonymous users in an
aggregated data collection, and uniquely re-identify
minority individuals within the datasets based on their
gender, height, and BMI.
We also showed that an adversary can de-anonymize
all users (minority or majority) in the dataset based
on their daily routine with 93.5% accuracy, if she has
access to some of their fitness data.
Finally, we discussed how applying k-anonymity to
quasi-identifiers (i.e., physical characteristics) would
not guarantee users’ privacy, since the adversary is
still able to glean information on those attributes
through the presented inference model.
