Rethinking Anonymity Claims in Synthetic Data Generation: A Model-Centric Privacy Attack Perspective
Organizations: UCL · SAS · UC Riverside
Abstract
Training generative machine learning models to produce synthetic tabular data has become a popular approach for enhancing privacy in data sharing. As this typically involves processing sensitive personal information, releasing either the trained model or generated synthetic datasets can still pose privacy risks. Yet, recent research, commercial deployments, and privacy regulations like the General Data Protection Regulation (GDPR) largely assess anonymity at the level of an individual dataset. In this paper, we rethink anonymity claims about synthetic data from a model-centric perspective, arguing that meaningful assessments must account for the underlying generative model and be grounded in state-of-the-art privacy attacks. This perspective better reflects real-world deployments, where trained models are often accessible for interaction or querying. We interpret the GDPR's definitions of personal data and anonymization under such access assumptions to identify the identifiability risks that must be mitigated and map them to privacy attacks across threat settings. We then argue that synthetic data techniques alone do not ensure sufficient anonymization. Finally, we compare the two mechanisms most commonly used with synthetic data -- Differential Privacy (DP) and Similarity-based Privacy Metrics (SBPMs) -- and argue that while DP can offer robust protections against identifiability risks, SBPMs lack adequate safeguards. Overall, our work connects regulatory notions of identifiability with model-centric privacy attacks, enabling more responsible and trustworthy assessment of synthetic data systems by researchers, practitioners, and policymakers.
Figures & tables
| Regulatory Risk | Privacy Attacks Type | Specific Privacy Attack (Assumptions) |
| Singling out | Differencing Attacks | - |
| Linkability | Membership Inference Attacks | GroundHog ( Stadler et al., 2022 ) (black-box; training algo, representative data) |
| Querybased ( Houssiau et al., 2022a ) (black-box; training algo, representative data) | ||
| DOMIAS ( van Breugel et al., 2023 ) (no-box; reference test data) | ||
| AuditSynth ( Annamalai et al., 2024b ) (white-box; training algorithm) | ||
| MIDST ( Wu et al., 2025 ) (white/black-box; training algo, representative data) |
| Privacy Criterion | DP | SBPMs |
|---|---|---|
| Adversarial Model | well-defined | undefined |
| Privacy Guarantees | general | empirical |
| Privacy Analysis | worst-case | average-case |
| Privacy Risk | overestimation | underestimation |
| Plausible Deniability | yes | no |
| Privacy Subject | generative model | synthetic data |
| Consideration | DP | SBPMs |
|---|---|---|
| Utility | reduced | not affected |
| Fairness | reduced/disparate | not affected |
| Consistency | not always | no |
| Interpretation | challenging | seems intuitive |
| Computational Performance | slow | fast |
| Implementation and Adoption | difficult | easy |