Data Mining in Health Care / en Anonymity’s ARX nemesis /news/2025-10/anonymitys-arx-nemesis <span>Anonymity’s ARX nemesis</span> <span><span>Nathan Kahl</span></span> <span><time datetime="2025-10-20T11:12:08-04:00" title="Monday, October 20, 2025 - 11:12">Mon, 10/20/2025 - 11:12</time> </span> <div class="layout layout--gmu layout--twocol-section layout--twocol-section--70-30"> <div class="layout__region region-first"> <div data-block-plugin-id="field_block:node:news_release:body" class="block block-layout-builder block-field-blocknodenews-releasebody"> <div class="field field--name-body field--type-text-with-summary field--label-visually_hidden"> <div class="field__label visually-hidden">Body</div> <div class="field__item"><p><span class="intro-text">A team of faculty and students from 鶹Ƶ recently discovered a vulnerability in a widely used anonymization tool. They presented their findings last week in Taiwan at the </span><a href="https://www.sigsac.org/ccs/CCS2025/" title="ACM CCS"><span class="intro-text">Association for Computing Machinery Conference on Computer and Communications Security (ACM CCS)</span></a><span class="intro-text">, one of the world’s most prestigious computer security conferences, with a very low paper acceptance rate.</span></p> <p>The problem they discovered was with ARX, an open-source data anonymization tool, which provides what is referred to as <em>k</em>-anonymity. It is a commonly used tool in clinical settings to maintain data privacy. The discovery is particularly important at a time when more and more private data is being used in a variety settings and systems.</p> <p>Evgenios Kornaropoulos, an assistant professor in the <a href="https://cs.gmu.edu" title="Computer science">Department of Computer Science</a>, said, “Sometimes this type of microdata is very valuable. Tools like ARX anonymize the data so it’s compliant with HIPAA, and then that data can be shared with policymakers, engineers, scientists, and others who will make policy decisions and scientific studies based on this information.”&nbsp;</p> <p>While many people receiving medical care are comfortable with their information being included in larger data sets for purposes of medical discovery, they likely do not want personal, identifiable information released.</p> <figure role="group" class="align-left"> <div> <div class="field field--name-image field--type-image field--label-hidden field__item"> <img src="/sites/g/files/yyqcgq291/files/styles/small_content_image/public/2025-10/somiya_presenting.jpeg?itok=J1ansOsf" width="350" height="263" alt="Somiya Chhillar speaking at the ACCESS Academy" loading="lazy"> </div> </div> <figcaption>Chhillar presented findings at ACM CCS in Taiwan.&nbsp;</figcaption> </figure> <p>“For patients, and especially those from more vulnerable or marginalized communities, data privacy is not an abstract concern, it’s deeply tied to trust in the health care system," said paper co-author Rebecca Sutter, a professor in the <a href="https://nursing.gmu.edu" title="Nursing">School of Nursing</a>, and director of the <a href="https://publichealth.gmu.edu/mapclinics" title="MAP">MAP Clinics</a>. "The integrity of tools like ARX matters because they underpin how we protect patient information while advancing public health research. When anonymization fails, it’s not only a technical vulnerability, it’s a human one."</p> <p>Computer science PhD student Somiya Chhillar, lead author on the paper, said that the ubiquity of ARX was a reason they chose to study it. “We wanted to see how ARX really operates and how the algorithm works. While we were doing that, we realized that a few of the steps that it takes are very opportunistic, and because of that, it leaks information that we shouldn't be finding out by just looking at the anonymized data.”</p> <p>Chhillar said that ARX follows a “greedy strategy,” explaining that there is a tension between privacy and utility. When data is shared, it should be useful without leaking information. The best metric for deciding the data usefulness is measured by information loss while the data is being made private. “The algorithm tries to minimize information loss while anonymizing the data, and ideally, we want the least possible information loss. And that's the greedy aspect of it; it's not always going for the most private, it’s just going for the most utilit<strong>y.”</strong></p> <p>This is what backfires, said Kornaropoulos, because experts (or attackers) can reverse engineer the anonymization steps the algorithm took throughout its execution to maximize utility and figure out properties of the data that were there before and after this anonymization step.</p> <p>Kornaropoulos praised his student’s dedication to the discovery, noting that Chhillar “worked on this project for a while, and this code base of ARX is an elaborate tool, with thousands of lines of code. She had to go through it to truly internalize understand everything that's going on there,” he said.</p> <p>The project was supported by a <a href="https://cyberinitiative.org" title="CCI">Commonwealth Cyber Initiative (CCI)</a> grant from the program, “Securing Interactions between Humans and Machines,” and as a requirement of the grant, the project crossed different parts of the university. The College of Engineering and Computing collaborated with 鶹Ƶ and Partners (MAP) Clinics, which provided <strong>the data.</strong></p> </div> </div> </div> </div> <div class="layout__region region-second"> <div data-block-plugin-id="field_block:node:news_release:field_associated_people" class="block block-layout-builder block-field-blocknodenews-releasefield-associated-people"> <h2>In This Story</h2> <div class="field field--name-field-associated-people field--type-entity-reference field--label-visually_hidden"> <div class="field__label visually-hidden">People Mentioned in This Story</div> <div class="field__items"> <div class="field__item"><a href="/profiles/evgenios" hreflang="en">Evgenios Kornaropoulos</a></div> <div class="field__item"><a href="/profiles/rsutter2" hreflang="und">Rebecca Sutter, DNP, APRN, BC-FNP</a></div> </div> </div> </div> <div data-block-plugin-id="inline_block:text" data-inline-block-uuid="30b1167e-304a-45f9-88b5-13a68b5c60e5" class="block block-layout-builder block-inline-blocktext"> </div> <div data-block-plugin-id="inline_block:call_to_action" data-inline-block-uuid="8ef98303-35f1-4073-ae4d-1f1a562f856d"> <div class="cta"> <a class="cta__link" href="https://cec.gmu.edu/strengths/cybersecurity"> <p class="cta__title">Learn more about Cybersecurity at George 鶹Ƶ <i class="fas fa-arrow-circle-right"></i> </p> <span class="cta__icon"></span> </a> </div> </div> <div data-block-plugin-id="inline_block:text" data-inline-block-uuid="db1cdb29-2248-499d-a67a-b80231e75b6e" class="block block-layout-builder block-inline-blocktext"> </div> <div data-block-plugin-id="inline_block:news_list" data-inline-block-uuid="b4a204af-9cf8-4501-8c96-e0ad82cc5004" class="block block-layout-builder block-inline-blocknews-list"> <h2>Related Stories</h2> <div class="views-element-container"><div class="view view-news view-id-news view-display-id-block_1 js-view-dom-id-4b195586d09dec67b2719dedc6a4aac9b9a692d72ff9ef7d65fd19d188a0ba99"> <div class="view-content"> <div class="news-list-wrapper"> <ul class="news-list"> <li class="news-item"><div class="views-field views-field-title"><span class="field-content"><a href="/news/2025-10/george-mason-and-kings-college-london-win-google-award-fight-ai-driven-romance-scams" hreflang="en">George 鶹Ƶ and King’s College London win Google Award to fight AI-driven romance scams targeting older adults </a></span></div><div class="views-field views-field-field-publish-date"><div class="field-content">October 26, 2025</div></div></li> <li class="news-item"><div class="views-field views-field-title"><span class="field-content"><a href="/news/2025-10/anonymitys-arx-nemesis" hreflang="en">Anonymity’s ARX nemesis</a></span></div><div class="views-field views-field-field-publish-date"><div class="field-content">October 20, 2025</div></div></li> <li class="news-item"><div class="views-field views-field-title"><span class="field-content"><a href="/news/2025-08/bluetooth-blues-george-mason-turns-bug-big-win" hreflang="en">Bluetooth blues? George 鶹Ƶ turns a bug into a big win </a></span></div><div class="views-field views-field-field-publish-date"><div class="field-content">August 20, 2025</div></div></li> <li class="news-item"><div class="views-field views-field-title"><span class="field-content"><a href="/news/2025-08/one-tiny-flip-opens-backdoor-ai" hreflang="en">One tiny flip that opens a backdoor in AI</a></span></div><div class="views-field views-field-field-publish-date"><div class="field-content">August 12, 2025</div></div></li> <li class="news-item"><div class="views-field views-field-title"><span class="field-content"><a href="/news/2025-01/unlocking-privacy-encrypted-ingenuity-security-expert-receives-nsf-career-award" hreflang="en">Unlocking privacy with encrypted ingenuity: Security expert receives NSF CAREER award </a></span></div><div class="views-field views-field-field-publish-date"><div class="field-content">January 27, 2025</div></div></li> </ul> </div> </div> </div> </div> </div> </div> </div> <div class="layout layout--gmu layout--twocol-section layout--twocol-section--30-70"> <div> </div> <div class="layout__region region-second"> <div data-block-plugin-id="field_block:node:news_release:field_content_topics" class="block block-layout-builder block-field-blocknodenews-releasefield-content-topics"> <h2>Topics</h2> <div class="field field--name-field-content-topics field--type-entity-reference field--label-visually_hidden"> <div class="field__label visually-hidden">Topics</div> <div class="field__items"> <div class="field__item"><a href="/taxonomy/term/2186" hreflang="en">computer science</a></div> <div class="field__item"><a href="/taxonomy/term/3346" hreflang="en">Cyber Security</a></div> <div class="field__item"><a href="/taxonomy/term/5846" hreflang="en">Data Mining in Health Care</a></div> <div class="field__item"><a href="/taxonomy/term/4186" hreflang="en">Commonwealth Cyber Initiative (CCI)</a></div> <div class="field__item"><a href="/taxonomy/term/271" hreflang="en">Research</a></div> </div> </div> </div> </div> </div> Mon, 20 Oct 2025 15:12:08 +0000 Nathan Kahl 343951 at Panagiota Kitsantas, PhD /profiles/pkitsant <span>Panagiota Kitsantas, PhD</span> <span><span>admin_alpha</span></span> <span><time datetime="2015-10-20T19:24:01-04:00" title="Tuesday, October 20, 2015 - 19:24">Tue, 10/20/2015 - 19:24</time> </span> <div class="layout layout--gmu layout--twocol-section layout--twocol-section--30-70"> <div class="layout__region region-first"> <div data-block-plugin-id="field_block:node:profile:field_headshot" class="block block-layout-builder block-field-blocknodeprofilefield-headshot"> <div class="field field--name-field-headshot field--type-image field--label-hidden field__item"> <img src="/sites/g/files/yyqcgq291/files/2021-03/Panagiota%20Kitsantas.jpg" width="510" height="768" alt="Headshot photo of Panagiota Kitsantas" loading="lazy"> </div> </div> <div data-block-plugin-id="field_block:node:profile:field_org_positions" class="block block-layout-builder block-field-blocknodeprofilefield-org-positions"> <div class="field field--name-field-org-positions field--type-text-long field--label-visually_hidden"> <div class="field__label visually-hidden">Titles and Organizations</div> <div class="field__item"><p>Interim chair, HAP</p> </div> </div> </div> <div data-block-plugin-id="field_block:node:profile:field_contact_information" class="block block-layout-builder block-field-blocknodeprofilefield-contact-information"> <h2>Contact Information</h2> <div class="field field--name-field-contact-information field--type-text-long field--label-hidden field__item"><div class="profile-bio-section"><strong>Email:&nbsp;</strong>pkitsant@gmu.edu</div> <div class="profile-bio-section"><span class="info-staff"><strong>Phone</strong>: 703-993-1980</span></div> </div> </div> <div data-block-plugin-id="inline_block:text" data-inline-block-uuid="ec61105d-cd12-42bb-b977-7237c4946b62" class="block block-layout-builder block-inline-blocktext"> <div class="field field--name-body field--type-text-with-summary field--label-hidden field__item"><h2>CV</h2> <p><a href="https://mymasonportal.gmu.edu/bbcswebdav/xid-197943401_1" target="_blank">Download Panagiota Kitsantas&nbsp;curriculum vitae (CV) here.</a></p> </div> </div> <div data-block-plugin-id="field_block:node:profile:field_personal_websites" class="block block-layout-builder block-field-blocknodeprofilefield-personal-websites"> <h2>Personal Websites</h2> <div class="field field--name-field-personal-websites field--type-link field--label-hidden field__items"> <div class="field field--name-field-personal-websites field--type-link field--label-hidden field__item"><a href="https://orcid.org/0000-0003-0261-9002">ORCID</a></div> </div> </div> </div> <div class="layout__region region-second"> <div data-block-plugin-id="field_block:node:profile:field_bio" class="block block-layout-builder block-field-blocknodeprofilefield-bio"> <h2>Biography</h2> <div class="field field--name-field-bio field--type-text-long field--label-hidden field__item"><p>Dr. Kitsantas is a Professor of Biostatistics/Epidemiology in the Department of Health Administration and Policy (HAP). She has also served as the PhD Program Director in Health Services Research at HAP. Previously, she was the Chair of the Department of Population Health at the Schmidt College of Medicine, Florida Atlantic University.&nbsp;</p> <p>Her research focuses on integrating data science with statistical/epidemiological methods to address health issues in vulnerable populations of women and their children. Dr. Kitsantas is the Principal Investigator of an NIH-funded study examining comorbidities in pregnant Women with prenatal alcohol exposure and adverse birth outcomes. She has also received funding from the Consortium for Medical Marijuana Clinical Outcomes Research to study medical cannabis use among pregnant and non-pregnant women of reproductive age. She has authored and co-authored numerous manuscripts on a wide range of topics, including infant feeding practices, childhood obesity, infant mortality, and various other issues related to maternal health.<br>Dr. Kitsantas teaches courses in health statistics and research methods, with a strong interest in incorporating AI tools into educational practices to enhance student learning.</p> <h3>Research/Scholarship Interests</h3> <p>Substance use and misuse (e.g., e-cigarettes, alcohol, opioids, and cannabis) among pregnant and non-pregnant women of childbearing age and children, particularly among vulnerable populations such as those with disabilities; machine learning applications in population health; artificial intelligence in teaching and learning.</p> <h3>Select Journal Publications</h3> <p>Matarazzo, A.*, Hennekens, C.H., Dunn, J.*, Mejia, M.C., Levine, R.S., &amp; Kitsantas, P. (2025). New clinical and public health challenges: Increasing trends in United States alcohol related mortality. American Journal of Medicine, 138(3), 477-486.</p> <p>Kitsantas, P., Benson, K.*, Rubenstein, A.*, Mejia, M. C., Levine, R. S., Hennekens, C. H., &amp; Wood, S. K. (2025). Prenatal cannabis use and adverse health outcomes in neonates and early childhood. Pediatrics and neonatology, S1875-9572(24)00229-8. Advance online publication. https://doi.org/10.1016/j.pedneo.2024.11.004</p> <p>Kitsantas, P., Densley, S.*, Rao, M.*, Sacca, L., Levine, R.S., Hennekens, C.H., &amp; Mejia, M.C. (2024). Increases in drug-related infant mortality in the United States. Journal of Perinatal Medicine, 52(6), 660-664</p> <p>Kitsantas, P., Aljoudi, S. M.*, &amp; Sacca, L. (2024). Perception of Risk of Harm from Cannabis Use Among Women of Reproductive Age with Disabilities. Cannabis and cannabinoid research, 9(6), e1615–e1622. https://doi.org/10.1089/can.2023.0199</p> <p>Yang, J.*, Mejia, M.C., Sacca, L., Hennekens, C.H., Kitsantas, P. (Oct 2024). Trends in marijuana use among adolescents in the United States. Pediatric Reports, 16(4):872-879. doi:10.3390/pediatric16040074</p> <p>Kitsantas, P., &amp; Pursell, S.R. (2024). Are healthcare providers caring for pregnant and postpartum women ready to confront the perinatal cannabis use challenge? American Journal of Perinatology, 41(S 01):e3249-e3254.</p> <p>Kitsantas, P., Gimm, G., &amp; Aljoudi, S. M*. (2023). Treatment outcomes among pregnant women with cannabis use disorder. Addictive behaviors, 144, 107723. <a href="https://doi.org/10.1016/j.addbeh.2023.107723">https://doi.org/10.1016/j.addbeh.2023.107723</a></p> <h3>Honors and Awards</h3> <ul> <li>Recipient of the Shirley S. Travis Habit of Excellence Award, 2014</li> <li>Recipient of the College of Health and Human Services Master Teacher Award, 2014</li> <li>Recipient of the 鶹Ƶ Teacher of Distinction Award, 2014</li> </ul> <h3>Professional Affiliations/Memberships</h3> <ul> <li>Member, American College of Epidemiology</li> <li>Member, American Public Health Association</li> </ul> <h3>Degrees</h3> <ul> <li><strong>PhD, Statistics</strong>, Florida State University &nbsp;</li> <li><strong>MS, Statistics</strong>, Florida State University</li> <li><strong>MS, Health Sciences</strong>, James Madison University</li> <li><strong>BA, Biology</strong>, Queens College of the City University of New York</li> </ul> </div> </div> </div> </div> Tue, 20 Oct 2015 23:24:01 +0000 admin_alpha 57786 at