Geographic masking is a key technique to protect individual privacy when sharing spatial point data. Among probabilistic approaches, donut masking is widely used because of its conceptual simplicity and ease of implementation. Whereas most previous studies have focused on average trends linking masking parameters to privacy and analytical utility, this study highlights the often-overlooked role of execution-level variability: differences in outcomes from repeated masking executions under the same parameter settings. Using synthetic crime data and census-based household distributions from Suginami Ward in Tokyo, we applied donut masking across a range of displacement radii and assessed its effects on both spatial k-anonymity and the preservation of spatial analytical results derived from K-function analysis. To quantify analytical preservation, we introduced two novel metrics based on p-value profiles: the Euclidean distance and consistency rate. Our results showed that while a larger displacement increased privacy, it also introduced substantial variability in the analytical outcomes. However, some executions, even under strong masking, exhibited high fidelity in the analysis results. Comparisons with other masking methods suggest that combining execution-level selection with probabilistic masking can help balance privacy protection and analytical preservation. Based on these findings, we proposed two practical strategies for selecting favorable executions: fixed-count selection and threshold-based iterations. Processing time assessments confirmed the feasibility of this approach in standard computing environments. Rather than viewing geographic masking as a fixed-parameter process, this study reframes it as a flexible selection problem that enables more effective anonymization with minimal analytical compromise.
Atsushi Masuyama (Tue,) studied this question.