Jump to content

Linkage attack

From Consumer Rights Wiki
Revision as of 17:08, 17 August 2025 by JackFromWisconsin (talk | contribs) (tag as incomplete)

⚠️ Article status notice: This article has been marked as incomplete

This article needs additional work for its sourcing and verifiability to meet the wiki's Content Guidelines and be in line with our Mission Statement for comprehensive coverage of consumer protection issues. In particular:

  1. No references

This notice will be removed once the issue/s highlighted above have been addressed and sufficient documentation has been added to establish the systemic nature of these issues. Once you believe the article is ready to have its notice removed, visit the discord and post to the #appeals channel.

Learn more ▼


A linkage attack (also known as a record linkage or de-anonymization attack) occurs when anonymized data is combined with one or more external datasets to re-identify individuals. In essence, overlap in quasi-identifying details—like ratings, timestamps, demographic traits, or behavioral patterns—can act like a fingerprint that links a supposedly anonymous record back to a real person.

For example, researchers demonstrated that by matching Netflix’s anonymized movie ratings (ratings, dates, movie IDs) with the same user’s public IMDb ratings, they could re-identify specific users from the Netflix dataset. This minor overlap in non-identifying data enabled them to connect the dots despite the lack of explicit identifiers.