Skip to main content
QUICK REVIEW

[論文レビュー] A Predictive Differentially-Private Mechanism for Mobility Traces

Konstantinos Chatzikokolakis, Catuscia Palamidessi|arXiv (Cornell University)|Nov 16, 2013
Privacy-Preserving Technologies in Data参考文献 26被引用数 6
ひとこと要約

本稿では、ユーザーの軌跡における時間的相関を活用して、プライバシー予算の消費を削減する予測可能な微分プライバシー機構を提案する。将来の位置を予測し、それらの予測をプライバシー的に検証した後、ノイズを加えたデータを公開することで、独立したノイズ追加に比べて、特に相関が高い移動パターンにおいて顕著に効率が向上する。

ABSTRACT

With the increasing popularity of GPS-enabled hand-held devices, location-based applications and services have access to accurate and real-time location information, raising serious privacy concerns for their millions of users. Trying to address these issues, the notion of geo-indistinguishability was recently introduced, adapting the well-known concept of Differential Privacy to the area of location-based systems. A Laplace-based obfuscation mechanism satisfying this privacy notion works well in the case of a sporadic use; Under repeated use, however, independently applying noise leads to a quick loss of privacy due to the correlation between the location in the trace. In this paper we show that correlations in the trace can be in fact exploited in terms of a prediction function that tries to guess the new location based on the previously reported locations. The proposed mechanism tests the quality of the predicted location using a private test; in case of success the prediction is reported otherwise the location is sanitized with new noise. If there is considerable correlation in the input trace, the extra cost of the test is small compared to the savings in budget, leading to a more efficient mechanism. We evaluate the mechanism in the case of a user accessing a location-based service while moving around in a city. Using a simple prediction function and two budget spending stategies, optimizing either the utility or the budget consumption rate, we show that the predictive mechanim can offer substantial improvements over the independently applied noise.

研究の動機と目的

  • 微分プライバシー下での繰り返しの位置クエリにおいて、独立したノイズ追加の非効率性を是正すること。
  • 標準的なラプラス機構を用いる場合に発生する、移動トレースにおける相関によるプライバシー劣化を克服すること。
  • プライバシーの強化と予測コンponentを分離することで、柔軟性と拡張性を備えたモジュラーなフレームワークを設計すること。
  • 予測可能なユーザー移動パターンを活用することで、位置ベースのサービスにおける利便性と予算効率を向上させること。
  • 地理的不辺別性制約下で、実際のGPS軌跡データセットを用いて、本機構の有効性を実証すること。

提案手法

  • 時間的依存性を活用するため、ユーザー移動を相関のある位置の系列としてモデル化する。
  • 履歴軌跡データに基づいて、次の位置を推定する予測関数を用いる。
  • 微分プライバシー機構を用いて、予測の正確性をプライバシー的に検証するテストを実装する。
  • 予測がプライベートテストに合格した場合、予測された位置を公開する。そうでない場合は、真の位置に新規のラプラスノイズを追加する。
  • 地理的不辺別性フレームワーク内に本機構を統合し、攻撃者に対する事前知識に依存しない強力なプライバシー保証を確保する。
  • 2つの予算最適化戦略を適用する:1つは利便性を最大化し、もう1つは予算消費レートを最小化する。

実験結果

リサーチクエスチョン

  • RQ1移動トレースにおける相関を活用することで、微分プライバシー的場所公開におけるプライバシー予算の消費を削減できるか?
  • RQ2利便性と予算効率の観点から、予測機構は独立したノイズ追加に比べてどの程度優れているか?
  • RQ3予測の正確性とプライベートな検証が、全体のプライバシー-利便性トレードオフに与える影響は何か?
  • RQ4提案された機構は、地理的不辺別性を越えて、他の d_X-プライバシー定義にも一般化可能か?
  • RQ5異なる予算配分戦略が、実世界の移動データにおける利便性とプライバシー予算の消費に与える影響は何か?

主な発見

  • 実GPS軌跡データセットにおいて、予測機構は独立したノイズ追加に比べて利便性と予算効率の両面で優れている。
  • 軌跡の相関が強い場合には、プライベート検証のコストがノイズ使用量の削減を上回るため、顕著なプライバシー予算の節約が達成される。
  • 攻撃者の事前知識に依存しない地理的不辺別性下でも、本機構は強力なプライバシー保証を維持する。
  • フレームワークはモジュラーかつ拡張可能であり、さまざまな予測関数やプライバシー定義との統合が可能である。
  • 実験的評価により、本機構が多数のテストシナリオで性能向上を達成することが確認された。特に直線的または予測可能な移動パターンにおいて顕著である。
  • プライベートな予測検証の使用により、繰り返しクエリが行われる状況でも、プライバシーを損なわず効率的な予算管理が可能である。

より良い研究を、今すぐ始めましょう

論文の読解から最終レビューまで、研究時間を劇的に削減しましょう。

クレジットカード登録不要

このレビューはAIが作成し、人間の編集者が確認しました。