Cargando…
Controlling the signal: Practical privacy protection of genomic data sharing through Beacon services
BACKGROUND: Genomic data is increasingly collected by a wide array of organizations. As such, there is a growing demand to make summary information about such collections available more widely. However, over the past decade, a series of investigations have shown that attacks, rooted in statistical i...
Autores principales: | , , , |
---|---|
Formato: | Online Artículo Texto |
Lenguaje: | English |
Publicado: |
BioMed Central
2017
|
Materias: | |
Acceso en línea: | https://www.ncbi.nlm.nih.gov/pmc/articles/PMC5547445/ https://www.ncbi.nlm.nih.gov/pubmed/28786360 http://dx.doi.org/10.1186/s12920-017-0282-1 |
_version_ | 1783255691015749632 |
---|---|
author | Wan, Zhiyu Vorobeychik, Yevgeniy Kantarcioglu, Murat Malin, Bradley |
author_facet | Wan, Zhiyu Vorobeychik, Yevgeniy Kantarcioglu, Murat Malin, Bradley |
author_sort | Wan, Zhiyu |
collection | PubMed |
description | BACKGROUND: Genomic data is increasingly collected by a wide array of organizations. As such, there is a growing demand to make summary information about such collections available more widely. However, over the past decade, a series of investigations have shown that attacks, rooted in statistical inference methods, can be applied to discern the presence of a known individual’s DNA sequence in the pool of subjects. Recently, it was shown that the Beacon Project of the Global Alliance for Genomics and Health, a web service for querying about the presence (or absence) of a specific allele, was vulnerable. The Integrating Data for Analysis, Anonymization, and Sharing (iDASH) Center modeled a track in their third Privacy Protection Challenge on how to mitigate the Beacon vulnerability. We developed the winning solution for this track. METHODS: This paper describes our computational method to optimize the tradeoff between the utility and the privacy of the Beacon service. We generalize the genomic data sharing problem beyond that which was introduced in the iDASH Challenge to be more representative of real world scenarios to allow for a more comprehensive evaluation. We then conduct a sensitivity analysis of our method with respect to several state-of-the-art methods using a dataset of 400,000 positions in Chromosome 10 for 500 individuals from Phase 3 of the 1000 Genomes Project. All methods are evaluated for utility, privacy and efficiency. RESULTS: Our method achieves better performance than all state-of-the-art methods, irrespective of how key factors (e.g., the allele frequency in the population, the size of the pool and utility weights) change from the original parameters of the problem. We further illustrate that it is possible for our method to exhibit subpar performance under special cases of allele query sequences. However, we show our method can be extended to address this issue when the query sequence is fixed and known a priori to the data custodian, so that they may plan stage their responses accordingly. CONCLUSIONS: This research shows that it is possible to thwart the attack on Beacon services, without substantially altering the utility of the system, using computational methods. The method we initially developed is limited by the design of the scenario and evaluation protocol for the iDASH Challenge; however, it can be improved by allowing the data custodian to act in a staged manner. |
format | Online Article Text |
id | pubmed-5547445 |
institution | National Center for Biotechnology Information |
language | English |
publishDate | 2017 |
publisher | BioMed Central |
record_format | MEDLINE/PubMed |
spelling | pubmed-55474452017-08-09 Controlling the signal: Practical privacy protection of genomic data sharing through Beacon services Wan, Zhiyu Vorobeychik, Yevgeniy Kantarcioglu, Murat Malin, Bradley BMC Med Genomics Research BACKGROUND: Genomic data is increasingly collected by a wide array of organizations. As such, there is a growing demand to make summary information about such collections available more widely. However, over the past decade, a series of investigations have shown that attacks, rooted in statistical inference methods, can be applied to discern the presence of a known individual’s DNA sequence in the pool of subjects. Recently, it was shown that the Beacon Project of the Global Alliance for Genomics and Health, a web service for querying about the presence (or absence) of a specific allele, was vulnerable. The Integrating Data for Analysis, Anonymization, and Sharing (iDASH) Center modeled a track in their third Privacy Protection Challenge on how to mitigate the Beacon vulnerability. We developed the winning solution for this track. METHODS: This paper describes our computational method to optimize the tradeoff between the utility and the privacy of the Beacon service. We generalize the genomic data sharing problem beyond that which was introduced in the iDASH Challenge to be more representative of real world scenarios to allow for a more comprehensive evaluation. We then conduct a sensitivity analysis of our method with respect to several state-of-the-art methods using a dataset of 400,000 positions in Chromosome 10 for 500 individuals from Phase 3 of the 1000 Genomes Project. All methods are evaluated for utility, privacy and efficiency. RESULTS: Our method achieves better performance than all state-of-the-art methods, irrespective of how key factors (e.g., the allele frequency in the population, the size of the pool and utility weights) change from the original parameters of the problem. We further illustrate that it is possible for our method to exhibit subpar performance under special cases of allele query sequences. However, we show our method can be extended to address this issue when the query sequence is fixed and known a priori to the data custodian, so that they may plan stage their responses accordingly. CONCLUSIONS: This research shows that it is possible to thwart the attack on Beacon services, without substantially altering the utility of the system, using computational methods. The method we initially developed is limited by the design of the scenario and evaluation protocol for the iDASH Challenge; however, it can be improved by allowing the data custodian to act in a staged manner. BioMed Central 2017-07-26 /pmc/articles/PMC5547445/ /pubmed/28786360 http://dx.doi.org/10.1186/s12920-017-0282-1 Text en © The Author(s). 2017 Open AccessThis article is distributed under the terms of the Creative Commons Attribution 4.0 International License (http://creativecommons.org/licenses/by/4.0/), which permits unrestricted use, distribution, and reproduction in any medium, provided you give appropriate credit to the original author(s) and the source, provide a link to the Creative Commons license, and indicate if changes were made. The Creative Commons Public Domain Dedication waiver (http://creativecommons.org/publicdomain/zero/1.0/) applies to the data made available in this article, unless otherwise stated. |
spellingShingle | Research Wan, Zhiyu Vorobeychik, Yevgeniy Kantarcioglu, Murat Malin, Bradley Controlling the signal: Practical privacy protection of genomic data sharing through Beacon services |
title | Controlling the signal: Practical privacy protection of genomic data sharing through Beacon services |
title_full | Controlling the signal: Practical privacy protection of genomic data sharing through Beacon services |
title_fullStr | Controlling the signal: Practical privacy protection of genomic data sharing through Beacon services |
title_full_unstemmed | Controlling the signal: Practical privacy protection of genomic data sharing through Beacon services |
title_short | Controlling the signal: Practical privacy protection of genomic data sharing through Beacon services |
title_sort | controlling the signal: practical privacy protection of genomic data sharing through beacon services |
topic | Research |
url | https://www.ncbi.nlm.nih.gov/pmc/articles/PMC5547445/ https://www.ncbi.nlm.nih.gov/pubmed/28786360 http://dx.doi.org/10.1186/s12920-017-0282-1 |
work_keys_str_mv | AT wanzhiyu controllingthesignalpracticalprivacyprotectionofgenomicdatasharingthroughbeaconservices AT vorobeychikyevgeniy controllingthesignalpracticalprivacyprotectionofgenomicdatasharingthroughbeaconservices AT kantarcioglumurat controllingthesignalpracticalprivacyprotectionofgenomicdatasharingthroughbeaconservices AT malinbradley controllingthesignalpracticalprivacyprotectionofgenomicdatasharingthroughbeaconservices |