Skip to main content
QUICK REVIEW

[Paper Review] Back to the Drawing Board: Revisiting the Design of Optimal Location Privacy-preserving Mechanisms

Simon Oya, Carmela Troncoso|arXiv (Cornell University)|May 24, 2017
Privacy-Preserving Technologies in Data24 references11 citations
TL;DR

This paper challenges the assumption that minimizing adversary estimation error alone ensures strong location privacy, demonstrating that optimal mechanisms under this criterion can still leak significant privacy. It proposes augmenting privacy evaluation with complementary metrics—conditional entropy for information-theoretic uncertainty and worst-case quality loss for utility guarantees—and introduces a mechanism that maximizes conditional entropy while maintaining optimal average error, outperforming prior methods on multi-dimensional privacy criteria using real-world datasets.

ABSTRACT

In the last years we have witnessed the appearance of a variety of strategies to design optimal location privacy-preserving mechanisms, in terms of maximizing the adversary's expected error with respect to the users' whereabouts. In this work, we take a closer look at the defenses created by these strategies and show that, even though they are indeed optimal in terms of adversary's correctness, not all of them offer the same protection when looking at other dimensions of privacy. To avoid "bad" choices, we argue that the search for optimal mechanisms must be guided by complementary criteria. We provide two example auxiliary metrics that help in this regard: the conditional entropy, that captures an information-theoretic aspect of the problem; and the worst-case quality loss, that ensures that the output of the mechanism always provides a minimum utility to the users. We describe a new mechanism that maximizes the conditional entropy and is optimal in terms of average adversary error, and compare its performance with previously proposed optimal mechanisms using two real datasets. Our empirical results confirm that no mechanism fares well on every privacy criteria simultaneously, making apparent the need for considering multiple privacy dimensions to have a good understanding of the privacy protection a mechanism provides.

Motivation & Objective

  • To challenge the prevailing assumption that minimizing adversary estimation error ensures strong privacy in location obfuscation mechanisms.
  • To demonstrate that mechanisms optimal under average error criteria can still provide weak privacy when evaluated through other dimensions.
  • To propose complementary privacy metrics—conditional entropy and worst-case quality loss—to guide the design of more robust location privacy mechanisms.
  • To develop and evaluate a new mechanism that maximizes conditional entropy while preserving optimal average error performance.
  • To empirically compare multiple mechanisms across multiple privacy criteria using real-world location datasets.

Proposed method

  • Proposes conditional entropy as an information-theoretic metric to quantify uncertainty in the adversary's posterior belief about the true location.
  • Introduces worst-case quality loss as a utility-bound metric ensuring minimum service quality even under adversarial estimation.
  • Develops a mechanism that maximizes conditional entropy while maintaining optimality in average adversary estimation error using a posterior exponential mechanism.
  • Adapts the remapping technique from Chatzikokolakis et al. (2016) to construct optimal mechanisms from any base obfuscation mechanism.
  • Employs linear programming and Bayesian modeling to design mechanisms under utility constraints, with a focus on user-centric, sporadic location reporting.
  • Uses real-world datasets (Gowalla and Brightkite) to empirically evaluate mechanisms across multiple privacy and utility metrics.

Experimental results

Research questions

  • RQ1Can mechanisms that minimize average adversary estimation error still provide weak privacy when evaluated through alternative criteria?
  • RQ2How do information-theoretic metrics like conditional entropy and worst-case quality loss improve the evaluation of location privacy mechanisms?
  • RQ3Is it possible to design a mechanism that is optimal in average error while also maximizing conditional entropy?
  • RQ4How do different privacy metrics correlate, and can a single mechanism perform well across all dimensions?
  • RQ5What is the empirical performance of optimal mechanisms when evaluated using multiple privacy criteria on real-world data?

Key findings

  • No single mechanism performs well across all privacy criteria simultaneously, confirming the need for multi-dimensional evaluation.
  • The proposed mechanism maximizes conditional entropy while maintaining optimal average error, outperforming existing mechanisms on information-theoretic privacy.
  • The remapping technique from Chatzikokolakis et al. (2016) is shown to be a generic method for constructing optimal mechanisms from any obfuscation mechanism.
  • Empirical results on Gowalla and Brightkite datasets confirm that mechanisms optimal under average error can still result in high adversary correctness and low uncertainty, indicating poor privacy.
  • Conditional entropy and worst-case quality loss serve as effective complementary metrics for evaluating and guiding the design of privacy-preserving mechanisms.
  • The study demonstrates that relying solely on adversary error as a metric leads to suboptimal privacy choices, even when mechanisms are mathematically optimal under that criterion.

Better researchstarts right now

From reading papers to final review, dramatically reduce your research time.

No credit card · Free plan available

This review was created by AI and reviewed by human editors.