Pith. sign in

REVIEW 6 cited by

How To Break Anonymity of the Netflix Prize Dataset

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv cs/0610105 v2 pith:MZ6TK4QD submitted 2006-10-18 cs.CR cs.DB

classification cs.CRcs.DB
keywords netflixdatasetmovieadversarybackgroundde-anonymizationindividualknowledge
verification ladder T0 review T1 audit T2 compute T3 formal
0 comments
read the original abstract

We present a new class of statistical de-anonymization attacks against high-dimensional micro-data, such as individual preferences, recommendations, transaction records and so on. Our techniques are robust to perturbation in the data and tolerate some mistakes in the adversary's background knowledge. We apply our de-anonymization methodology to the Netflix Prize dataset, which contains anonymous movie ratings of 500,000 subscribers of Netflix, the world's largest online movie rental service. We demonstrate that an adversary who knows only a little bit about an individual subscriber can easily identify this subscriber's record in the dataset. Using the Internet Movie Database as the source of background knowledge, we successfully identified the Netflix records of known users, uncovering their apparent political preferences and other potentially sensitive information.

Discussion (0). Continue with ORCID to comment.

Forward citations

Cited by 6 Pith papers

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score. Full citation record

  1. Minimax Private Estimation of Smooth Optimal-Transport Maps

    math.ST 2026-06 unverdicted novelty 7.0 of 10

    First DP procedure for smooth OT map estimation achieving near-minimax optimality in d≥2 and minimax in d=1, with matching lower bounds.

  2. Privacy-Preserving Credit Risk Prediction with Alternative Data

    cs.LG 2026-06 unverdicted novelty 6.0 of 10

    PrivacyCredit is a machine learning method that combines traditional and alternative data for credit risk prediction while satisfying privacy-preserving, model-confidential, and lossless properties.

  3. A Common Pool of Privacy Problems: Legal and Technical Lessons from a Large-Scale Web-Scraped Machine Learning Dataset

    cs.CR 2025-06 unverdicted novelty 6.0 of 10

    An empirical audit of one web-scraped ML training dataset reveals persistent PII after sanitization, which the authors combine with legal analysis to highlight privacy risks and advocate redefining 'publicly available...

  4. Learning Private Representations through Entropy-based Adversarial Training

    cs.LG 2025-07 reject novelty 5.0 of 10

    Focal entropy, an off-centered entropy that focuses confusion on similar sensitive classes, improves the utility versus privacy trade-off in adversarial representation learning.

  5. Inferring Sensitive Attributes from Knowledge Graph Embeddings: Attack and Defense Strategies

    cs.CR 2026-05 unverdicted novelty 4.0 of 10

    Attribute inference attacks succeed on KGE outputs and randomization-based sanitization offers partial mitigation at the cost of recommendation utility.

  6. Privacy Parameter Variation Using RAPPOR on a Malware Dataset

    cs.CR 2019-07 unverdicted novelty 2.0 of 10

    RAPPOR is applied with ε=10, 1.0, 0.1 (and a finer sweep 0.5-1.0) to filtered Android app datasets of 10k, 100k, and 1.2M records to examine privacy-utility effects.

Pith tools