Formal privacy analyses for Open Banking

Luigi D. C. Soares*, Mário S. Alvim, Di Bu*, Natasha Fernandes, Yin Liao

*Corresponding author for this work

Research output: Chapter in Book/Report/Conference proceedingConference proceeding contributionpeer-review

Abstract

The term “Open Banking” describes a series of global initiatives to allow the sharing of customer data between financial companies to facilitate competition within their sector. In this paper, we formalise in the rigorous framework of quantitative information flow (QIF) relevant privacy risks in a concrete Open Banking scenario, namely: (i) transaction-history recovery and (ii) collateral attribute-inferences using external correlations. We provide extensive analyses of these risks in real-world data from Open Banking, supplied by a fintech in Australia. We show that the Open Banking system studied presents considerable privacy risks with respect to transactions, both in the presence and in the absence of demographic data. Finally, we exemplify potential real-world collateral attribute-inference attacks, in which we show how an attacker might leverage scientific correlations to infer individuals’ level of neuroticism and self-control from their transaction history. We hope that this work may: (i) help financial customers in Australia make better-informed decisions about what kind of information, and how much of it, to share via Open Banking; (ii) raise awareness about the potential privacy risks of Open Banking in other countries; and (iii) foster the development of privacy regulation in digital finance and the open data economy.

Original languageEnglish
Title of host publicationFormal Methods
Subtitle of host publicationfoundations and applications : 27th Brazilian Symposium, SBMF 2024, Vitória, Brazil, December 4-6, 2024, proceedings
EditorsSidney C. Nogueira, Ciprian Teodorov
Place of PublicationCham
PublisherSpringer, Springer Nature
Pages171-193
Number of pages23
ISBN (Electronic)9783031781162
ISBN (Print)9783031781155
DOIs
Publication statusPublished - 2025
Event27th Brazilian Symposium on Formal Methods, SBMF 2024 - Vitória, Brazil
Duration: 4 Dec 20246 Dec 2024

Publication series

NameLecture Notes in Computer Science
PublisherSpringer
Volume15403
ISSN (Print)0302-9743
ISSN (Electronic)1611-3349

Conference

Conference27th Brazilian Symposium on Formal Methods, SBMF 2024
Country/TerritoryBrazil
CityVitória
Period4/12/246/12/24

Keywords

  • Open Banking
  • Privacy-Risk Analysis
  • Quantitative Information Flow

Cite this