This repository is the public verification supplement for the study of high-precision ENEM performance scores as quasi-identifiers. It publishes aggregate evidence, declarative schemas, claim-facing metadata, synthetic examples, and presentation generators. It does not reproduce the restricted record-level linkage pipelines.
Knowing Millions of Students Too Well: High-Entropy Scores as Deterministic Quasi-Identifiers for Re-Identification and Data Leakage in the Brazilian High School Exam
Authors:
- Henrique Lindemann
- Eder John Scheid
- Lisandro Zambenedetti Granville
- Muriel Figueredo Franco
Published in Computers & Security (Elsevier), 2026. DOI: 10.1016/j.cose.2026.105080
The package supports verification of reported populations, equivalence-class counts, linkage outcomes, sensitivity analyses, privacy--utility results, accessibility-proxy exposure, and release-specific recalculability. It excludes nominal source files, candidate-level joins, identity crosswalks, canonical name pairs, person trackers, deterministic record hashes, and operational loaders. See scope and boundary.
Manuscript pointers use the directory names below. Open the family README first; it gives the scope and points to the relevant files.
score-distinctiveness: entropy, self-information, equivalence classes, and longitudinal individualization.score-generalization: fixed score transformations and aggregate privacy--utility outcomes.vector-a-institutional: the bounded UFRGS 2024 institutional scenario.vector-b-self-disclosure: qualitative mechanism only; no retained corpus.vector-c-governmental: aggregate annual linkage and longitudinal deduplication evidence.accessibility-proxies: conditional proxy exposure through exam-book codes.recalculabilityandlinked-attribute-catalog: release-design evidence and documentary metadata-only descriptions of attributable field groups.schemas: claim-facing field definitions, adversary models, and the complete exam-book-code mapping.
python3 tools/build_release.py --verify-onlyThe command reads only files in this repository and checks all aggregate invariants and claims, deterministic tables and figures, manifest hashes, and the publication boundary. Maintainers separately verify the allowlisted schemas against real CSV headers before updating release metadata.
The exact aggregate source commit is recorded in
verification/manifest.json; do not infer it from the public repository HEAD.
This package records
a2c43903d3249807bf86b387f09c48996fed411d. Start with the
verification guide, then consult
data sources, provenance, and the
glossary.
Repository-authored software and documentation are available under the MIT License.