Skip to content

Can We Explain What We Anonymize? On the Impact of Data Anonymization on Post-hoc Model Explanations

Jul 2026 · 2026 IEEE European Symposium on Security and Privacy Workshops (EuroS&PW) · pp. 20-28 · 1 citation · 27 references

Abstract

Privacy-preserving data publishing and explainable artificial intelligence (XAI) are both essential for trustworthy machine learning, yet their interaction remains largely underexplored. In practice, models are often trained on anonymized datasets, but little is known about how classical anonymization techniques affect post-hoc explanations. In this paper, we provide a systematic empirical study of how feature attribution rankings change under widely used anonymization models, including k-anonymity, $\ell$-diversity, t closeness, and $(\alpha, k)$-anonymity. Across multiple real-world datasets and classifiers, we compare explanations generated by SHAP and LIME and quantify their stability using rank correlation and hypothesis testing. Our findings reveal a fundamental trade-off: explainable privacy-preserving models are feasible under mild privacy constraints, but strict anonymization requirements often lead to unstable explanations and severe utility degradation.

View source

Similar papers

Conference Open access 2026

From Privacy-Utility Trade-Offs to Policies: Optimized Anonymization Recommendations for Data Trustees in Data Spaces

: As data spaces emerge to facilitate sovereign data exchange, geospatial data has become a critical resource across various domains. However, sharing sensitive geodata, such as cadastral property records, presents a privacy-utility trade-off. While the European Data Governance Act (DGA) establishes data trustees as the technical intermediaries authorized to perform necessary anonymization, a gap remains between theoretical spatial privacy algorithms and their practical, policy-driven application. This research addresses this gap by presenting an empirical evaluation of 11 spatial anonymization methods applied to complex polygon geometries. Using a dataset of 2,147 forested cadastral parcels, we quantify the trade-offs using privacy metrics ( k -anonymity, differential privacy ε ) and utility measures (Hausdorff distance, area deviation, centroid shift). Our results identify algorithmic failure modes, such as the “sparse forest” phenomenon, and demonstrate the improved performance of combined hybrid approaches. To operationalize these findings, we integrate our results into the architecture of data trustees operating within various domain-specific data spaces. We demonstrate how the empirically derived, use-case-specific anonymization guidelines can be translated into machine-interpretable Open Digital Rights Language (ODRL) policies. By mapping spatial transformation algorithms to ODRL constraints, this research provides data trustees with an approach to automatically enforce spatial privacy and sovereignty within data spaces.

Michael Steinert, Bekzod Nazarov, Thorsten Reitz et al. · 0 citations
Conference Jul 2026

Embedding-Space Anonymization for Privacy-Preserving AI Systems

This paper studies embedding-space privacy as a representation-level learning problem. Rather than altering raw records directly, the proposed framework applies embeddingspace transformation to full-record representations through Gaussian perturbation and adversarial representation sanitization. The method is evaluated through ablation across utility metrics, linkage attacks, attribute-inference attacks, and membership-inference tests. The primary empirical evaluation uses a synthetic fusion recommendation benchmark built from MovieLens [1], [2] 32M behavior and Adult-derived demographics [3], while a secondary synthetic medical benchmark is used to examine cross-domain transferability under more constrained conditions. The strongest results appear in the recommendation experiments. Under grouped demographic privacy evaluation, the combined condition preserves recommendation utility with $N D C G {@} K=0.6312$ while reducing exact and entity linkage from 0.7090/0.7204 to 0.0001/0.0000. Sensitive-target attacker performance remains near the majority baseline, supporting the claim of empirical privacy improvement without visible ranking degradation in that benchmark. The healthcare experiments also demonstrate meaningful embedding transformation and linkage reduction, though the current benchmark remains datalimited and therefore less conclusive for utility-focused evaluation. Overall, the findings support the conclusion that embeddingspace transformation can preserve downstream utility while substantially reducing linkage risk and sensitive-information recoverability under explicit attacker evaluation. The findings support embedding-space transformation as a practical privacypreserving strategy for embedding-driven AI systems under explicit attacker evaluation.

D. Panagoulias, Evangelia-Aikaterini Tsichrintzi, E. Sakkopoulos · 0 citations
Preprint Aug 2026

Dependency Triad: A Metric to Quantify the Dependencies Between Attributes for Local Differential Privacy

A novel metric, ``Dependency Triad''(DT), is proposed, which summarizes the pairwise dependency information relevant to CPL using three parameters and yields a conservative estimator of pairwise CPL, which is particularly suitable for high-cardinality attributes.

Sandaru Jayawardana, S. Ulukus, Ming Ding et al. · 0 citations
Open access Jul 2026

A New Multidimensional Data Anonymization Algorithm for Privacy-Preserving Data Publishing

Developing a privacy-preserving data publishing algorithm that prevents individuals’ identity information from being disclosed without ignoring the utility of the data is still an important goal to be achieved. Finding the optimal balance between data utility and data privacy is an NP-hard problem. In this study, a new k-anonymization-based data anonymization algorithm is proposed. The proposed algorithm partitions the data space with a new efficient partitioning strategy based on the k-dimensional tree (KD-tree), resolves the boundary problem while maintaining the trade-off balance, and introduces a new mechanism to address the problems caused by outliers. Moreover, it can be applied to both numerical and categorical data. The experimental results indicate that the proposed algorithm achieves competitive or improved performance compared with the baseline algorithms across seven commonly used evaluation metrics. Overall, the findings suggest that the proposed framework can improve the utility–privacy trade-off in multidimensional k-anonymization.

Burak Cem Kara, Can Eyüpoğlu, Oktay Karakuş · 0 citations
Review Open access Aug 2026

Recent Advances in Text Anonymization: A Systematic Review

This survey provides the first comprehensive and systematic review of text anonymization methods published between 2020 and 2025, covering 48 primary studies identified through a structured search and rigorous screening procedure and reveals a growing shift from identifier‐centric de‐identification toward context‐aware anonymization.

Marina Litvak, A. Jorge · 0 citations
Open access Oct 2026

CoP: Coordinated Perturbation for Controlled Disclosure Under Local Differential Privacy

CoP is proposed, a coordinated perturbation mechanism designed to mitigate CIL in multidimensional data collection while preserving utility and significantly outperforms state-of-the-art LDP mechanisms in reducing disclosure while preserving analytical accuracy.

Sandaru Jayawardana, Ming Ding, Kanchana Thilakarathna · 0 citations