[Paper Review] Under the Hood of Membership Inference Attacks on Aggregate Location Time-Series.
This paper investigates why membership inference attacks succeed on aggregate location time-series by analyzing data volume and mobility pattern regularity. It adapts existing location privacy defenses to the aggregate setting, demonstrating that tailored defenses can reduce inference risks while preserving utility for common mobility analytics.
Aggregate location statistics are used in a number of mobility analytics to express how many people are in a certain location at a given time (but not who). However, prior work has shown that an adversary with some prior knowledge of a victim's mobility patterns can mount membership inference attacks to determine whether or not that user contributed to the aggregates. In this paper, we set to understand why such inferences are successful and what can be done to mitigate them. We conduct an in-depth feature analysis, finding that the volume of data contributed and the regularity and particularity of mobility patterns play a crucial role in the attack. We then use these insights to adapt defenses proposed in the location privacy literature to the aggregate setting, and evaluate their privacy-utility trade-offs for common mobility analytics. We show that, while there is no silver bullet that enables arbitrary analysis, there are defenses that provide reasonable utility for particular tasks while reducing the extent of the inference.
Motivation & Objective
- To understand the root causes of success in membership inference attacks on aggregate location time-series.
- To identify key data characteristics—such as data volume and mobility pattern regularity—that enable such attacks.
- To adapt existing location privacy defenses to the aggregate data setting.
- To evaluate the privacy-utility trade-offs of these defenses for common mobility analytics tasks.
Proposed method
- Conducted in-depth feature analysis to identify data volume and mobility pattern regularity as critical factors in attack success.
- Adapted defenses from the location privacy literature to function in the aggregate data setting.
- Evaluated privacy-utility trade-offs using standard mobility analytics workloads.
- Used empirical evaluation to assess how well defenses reduce membership inference success while maintaining analytical utility.
Experimental results
Research questions
- RQ1What data characteristics make aggregate location time-series vulnerable to membership inference attacks?
- RQ2How do data volume and pattern regularity influence the success of such attacks?
- RQ3Which existing location privacy defenses can be effectively adapted to the aggregate setting?
- RQ4What is the privacy-utility trade-off of these adapted defenses for real-world mobility analytics?
Key findings
- Data volume and the regularity of mobility patterns are key factors enabling successful membership inference attacks on aggregate location data.
- Adapted defenses significantly reduce the success rate of membership inference attacks.
- No single defense works universally across all analytics tasks, but several provide strong privacy protection with acceptable utility loss.
- The most effective defenses preserve utility for specific mobility analytics tasks while substantially reducing inference risk.
Better researchstarts right now
From reading papers to final review, dramatically reduce your research time.
No credit card · Free plan available
This review was created by AI and reviewed by human editors.