So Chi, if you want to join us for the next talk, you will talk about data re-identification in the age of AI. And this is also a very, very nice topic from my point of view and in link with the previous subject because, yes, we are a lot identifiable through the web. And we need to find out how it is possible to make the tool useful to all the games.Hello everyone, my name is Chi Chung. Actually my full name is a little bit long, so I just use Chi Chung. And I'm a boss doc in Telecom Parisuit. I'm working in data re-identification. So today I'm happy to be here to share with you some insight about data re-identification in the age of AI. Actually, this talk, I want to focus in three questions. The first one is, what is data re-identification? And the second one is, why does AI make it more serious? And last, how can we reduce the risk of data re-identification? So let's start.Okay. So as you know that AI is part of our daily life, I'm pretty sure that all of you use AI every day, right? Is there anyone that doesn't use AI? Okay, really? Are you sure that you don't use it?Actually, even we don't use AI every day, but it appears in our daily life like we can see face recognition at the airport or some voice assistant at home or some application or service that used to track the phone location. Especially we use ChatGPT or the other AI assistant. So every day we chat with that and it can record some data from us, right? We actually, we think that we try to hide some personal information. For example, we already removed the real name, the phone number, the email address. But actually, with some personal information, it can connect this glue to make it can identify the real person. And So here the risk is that not only one data point, it is ability to link enough all of the information, all of thesmall information together to figure out that person. So actually, day by day, we provide some information that we didn't pay attention about that. For example, we may use the chat GPT to pass some text or to upload some file or sometimes we want to get some help from chat GPT to update the CV, for example. And in this case, you already provide some personal information, right? And there's some real circumstance, for example, in 2023, the Samsung engineer, they leaked some code through chat GPT.The link from actually can become another sook that can link people and behavior and some identity together. So this is the chart that I, sorry. This one? Is it okay? Okay, how? This is the lights, right? Yeah, for example, if we use some prompt to change GPT and this information may be stored in some vendor logs and the data may be leaked out and this can identify you. So what is pre-identification? The short definition of pre-identification is that the process of combining multiple information that we feel is harmless, but after all it can infer the specific person. For example, we have some information about GBS trades or some purchase information or some Netflix history. And this information, if we combine together,can point back to you So, um... Why they need to re-identify you and who try to re-identify. Actually, depends on the purpose of the person. For example, the privacy team, they can test if the data is up to share to the other people or not. Or some company, they want to do some advertisement or do some survey. So they want to collect the data and they want to re-identify some person. Another one is that the hacker or the attacker, they want to re-identify data to do some bad thing, for example, to scam or to do some cheating to get some benefit from that.But actually, even they have different purpose, but the way that they do, the method that they do are all the same. And nowadays, because AI develops so fast, so it also increase the risk of leaking our personal data. For example, the AI system, it may reproduce the piece of data that they have seen in their memory, or they can use some public information like photo, post, or profile that can be connected across platforms to link together to identify some people. Or even if they repeat, they try to repeat asking some question and it can reveal some hidden data or even some sensitive pattern. So when the identity is exposed, the heart becomes personal. And that's what I want to mention.Like AI also make an important role in the data leaking out, so we should pay attention about that. And this is not only theory, actually in practice, there already some cases happen. For example, in 2006, from the data set of AOL search log, the search history is more a real person identity. And in 2008, with the Netflix price, the anonymous movie rating could be matched back to some user. So it caused the re-identification problem. Or with some local location data, for example, phone trace can reveal the home or the workplace or the routine of some person.So re-identification can lead to a loss of privacy, stalking, or loss of trust, and even legal risk for the company. And, um... Because of this problem, actually we should, the personal data just like our personal assets, so we need to protect it. And the law also have some rules to protect, that is what GDPR come in. This is the law in European that can help to protect the personal data. Actually, before coming in France, in my country, in Vietnam, we actually didn't pay much about the personal data. So when I first come here, I feel a little bit where like why it's difficult to see the footprint in the camera that the people put at home or even some house they don't allow to put the camera outside, right? So.At first when coming here, I also feel worried about this problem. And because in our country, in Vietnam, or even in China or in some Asian country, the CCTVs or everywhere, even in your house, you can put the camera and... You don't need to ask for any permission from your government or from your neighbor. You just put the camera in front of your house to protect, like to survey the people around your house. So that's the difference between Asian country, especially my country, and in Europe. Here, I just want to mention about the GDPR law, and there's some main points that I want to mention. Like, actually, when the data, we already removed the name, the phone number, or some personal information, but the GDPR still asks if this person can still be identified.So if this, with the remaining data, that this person can still be re-identified, means that this is still personal data and needs to be protected. And this one already mentioned in Article 4. Identifiability includes what others can reasonably link together, means that if this data we get still can link together to figure out, to identify some person. So this is still... Still personal data, and this is mentioned in recital 26. The privacy must be built in by design and by default, which is mentioned in Article 25. And another important point is that if we have some serious violation, then this one can lead to major file in the Article 83. So this is some main points in GDPR that we pay attention about the personal data.So, how to reduce the risk of pre-identification? Actually, for the cybersecurity engineering, we have some special method to prevent the data leak out. For example, we can put some noise in the data to make the individual person hide from the crowd. By using the differential privacy, we can keep the data locally. This one, For example, your data keep being in the phone and not upload somewhere else to learn something. And we can use a K anonymity, which creates some group that makes K minus one other role, just similar to the other role. We can use aggregation to make some group research, for example. And this is just the academic method, the technical method that we do toprotect the data when we want, at the beginning when we design, before we release the data. However, personal data is some asset that belongs to each of us, so we need to pay attention about our asset and we try to protect it as much as possible to prevent leaking out our personal information. So this is the slogan that I just want to tell you about the data re-identification problem. And yeah, that's all for the talk. I'm happy to take any questions and thank you for your listening.You talk about the privacy and the way we get to it across federated learning and all this stuff. But actually the problem is that big companies, they are earning more and more companies. For example, if I take Meta, they have all the Instagram and social media related applications. And after that they get maybe the production of power. So how can we go deeper in the privacy in a world where people are earning more and more money? And they cannot be more slim to not use all their tools in order to get identification of people. Actually, for some companies like social media networks like Facebook, that kind of information we cannot protect because sometimes you upload some personal information. For example, I check in some place and I show some personal photo that I'm in display and I enjoy some things, some music or something. And this belongs to our... Our personalprivacy, I mean that this one is our behavior. We already leaked the personal information and Facebook, for example, or Twitter or any social media, they just show the information without any... Any constraint that this information is important, but in some case like healthcare data or financial data, I mean some important data, that one actually is really need to be protected. For example, if the person has some serious disease and they don't want to let the other people know about that because it also affects their career or something. So the protection, the data protection actually depends on the field. Not in general, but some people, they really love their privacy. They don't want to show any personal data. For example, they don't like posting somesome photo or some personal thinking on Facebook or somewhere else. So if I want all my professional stuff to stay on LinkedIn and all my social media related posts to stay on Instagram, despite the fact that they are owned by the same company, is it a problem or... Ah, you mean that you put different data in different place, right? I think if someone target at you, they still can find that kind of information.Okay, okay.