Evidence: well sourced. Imported from the supplied 65-Case Master Edition, dated September 19, 2026. Source links and classifications are retained as an attributed case account; import is not an independent source review.

Case at a glance

Case number
025
Date / range
2015
Sector
Re-identification and inference
Genetic asset
Genomic beacon responses and target variant information
Security principle
Query Interface Leakage

Event summary

A genomic beacon may answer only whether a variant exists in a dataset, yet a sequence of yes/no responses can support membership inference. Minimal answers can still reveal a sensitive whole when queries accumulate.

Source: doi.org — Genomic Beacon Re-Identification source 1.

Source: ga4gh.org — Genomic Beacon Re-Identification source 2.

The case in context

A beacon can provide a very small answer to each query while revealing more through a collection of responses. The research example asks whether someone with knowledge of a target's variants can use that pattern to infer dataset membership.

The individual response and the whole interface need different privacy assessments. Authentication, query limits, and other defenses affect the circumstances under which an inference might work. This case concerns a published demonstration and its assumptions; it is not a claim that every deployed beacon exposes its participants or that a live service was attacked.

Acquisition and processing

target genotype → repeated API queries → response pattern → likelihood test → membership inference → disease-cohort exposure

The sequence of events

  1. target genotype
  2. repeated API queries
  3. response pattern
  4. likelihood test
  5. membership inference
  6. disease-cohort exposure

What became inferable or exposed

Genomic beacon responses and target variant information

A genomic beacon may answer only whether a variant exists in a dataset, yet a sequence of yes/no responses can support membership inference. Minimal answers can still reveal a sensitive whole when queries accumulate.

Security dimensions

Confidentiality

The confidentiality question concerns genomic beacon responses and target variant information. Exposure and further inference must be distinguished from the fact of collection or availability.

Integrity

The integrity question is whether the described material, permissions, processing, or interpretation can be relied upon. Query Interface Leakage identifies the particular boundary examined here.

Availability

Access and continuity are assessed for the described event; potential effects are not presented as confirmed outages or losses.

Provenance

The relevant chain follows genomic beacon responses and target variant information through the stages shown below. Missing public detail is not proof that internal records did not exist.

GeneticSecurity.org analysis

Genetic Exposure Radius

Not assessed

No single level is assigned where the supplied dossier gives a range, conditional outcome, or broad institutional consequence. The affected parties and proposed assessment are shown separately.

Confidence: not assigned. Classification: GeneticSecurity.org analysis.

Genetic Persistence Risk

Not assessed

Persistence depends on the specific biological material or information retained. A potential effect is not treated as an observed genomic disclosure.

Confidence: not assigned. Classification: GeneticSecurity.org analysis.

Genetic Provenance Integrity

Not assessed

A numeric provenance level is not inferred from the existence of a source or court record. It requires evidence of the relevant custody and processing controls.

Confidence: not assigned. Classification: GeneticSecurity.org analysis.

Proposed classification and its limits

Suggested GER: GER-0/1. Suggested GPR: GPR-4/5. GPI: not central.

These are proposed classifications from the supplied case dossier. Conditional scores describe an assumed exposure; they are not evidence that it occurred. A single numeric value is left unassigned when the asset or outcome is not sufficiently bounded.

What this case does not prove

The research does not establish that every beacon is vulnerable under every dataset size, query rule, or defensive configuration.

Mitigations and lessons

  • Authentication
  • Query budgets
  • Rate limits
  • Minimum cohort sizes
  • Response perturbation
  • Aggregation
  • Auditing
  • Access tiers
  • Privacy testing before deployment

Primary sources

Secondary sources

No additional source listed. See the evidence notes for limitations.

Policy and standards

Genetic Security Policy and Standards

Review and correction history

Source edition: September 19, 2026. Imported case account; no substantive corrections recorded.

Correction policy and log

Cite this case

GS-CASE-025. The Yes-or-No Oracle: Re-identifying People Through a Genomic Beacon. GeneticSecurity.org. https://geneticsecurity.org/cases/025-genomic-beacon-membership-inference/