[论文解读] Protecting Location with Dynamic Differential Privacy under Temporal Correlations
本文提出动态微分隐私以保护移动用户的位置隐私,通过建模轨迹中的时间相关性实现。提出敏感度外壳与平面各向同性机制(PIM),在确保严格隐私保障的同时最小化噪声,实现最优效用,已在真实世界数据集上得到验证。
Concerns on location privacy frequently arise with the rapid development of GPS enabled devices and location-based applications. While spatial transformation techniques such as location perturbation or generalization have been studied extensively, most techniques rely on syntactic privacy models without rigorous privacy guarantee. Many of them only consider static scenarios or perturb the location at single timestamps without considering temporal correlation of a moving user's locations, and hence are vulnerable to various inference attacks. While differential privacy has been accepted as a de facto standard for privacy protection, applying differential privacy in location based applications presents new challenges, as the protection needs to be enforced on the fly for a single user and needs to incorporate temporal correlation between a user's locations. In this paper, we propose a systematic solution to preserve location privacy with rigorous privacy guarantee. First, we propose a new definition, dynamic differential privacy, to account for the temporal correlation in location data. Second, we show that the well known $\ell_1$ norm sensitivity fails to capture the geometric sensitivity in multidimensional space and propose a new notion, sensitivity hull, based on which the utility of dynamic differential privacy is bounded. Third, to obtain the optimal utility we present a planar isotropic mechanism (PIM), which is the first mechanism achieving the lower bound of differential privacy. We also implement PIM on real-world datasets to demonstrate its performance.
研究动机与目标
- 解决现有空间转换技术在位置数据中缺乏严格隐私保障的问题。
- 对移动用户轨迹中的时间相关性进行建模,以防止推理攻击。
- 开发一种适应演化位置序列的动态微分隐私框架。
- 建立一种几何敏感度度量——敏感度外壳——以捕捉多维噪声需求。
- 设计一种最优机制(PIM),实现微分隐私在位置数据中所需噪声的理论下限。
提出的方法
- 提出动态微分隐私作为一种新的隐私定义,以考虑顺序位置数据中的时间依赖性。
- 引入敏感度外壳——一种基于连续用户位置之间差值的L1范数的几何构造——以量化多维空间中的敏感度。
- 证明传统ℓ1范数敏感度无法捕捉高维位置数据中的几何约束。
- 设计平面各向同性机制(PIM),通过沿与敏感度外壳对齐的平面分布注入噪声,以最小化效用损失。
- 证明PIM实现了微分隐私所需噪声的理论下限,确保最优效用。
- 在真实世界GPS数据集上实现并评估PIM,以验证隐私-效用权衡。
实验结果
研究问题
- RQ1如何在实时环境中有效将微分隐私应用于具有时间相关性的动态位置数据?
- RQ2在多维位置数据中,何种几何敏感度度量比ℓ1范数更准确?
- RQ3能否设计一种噪声注入机制,在保持微分隐私的同时实现理论最小噪声?
- RQ4与传统敏感度度量相比,所提出的敏感度外壳如何改善隐私-效用权衡?
- RQ5平面各向同性机制(PIM)在真实世界位置数据集中的表现如何?
主要发现
- 敏感度外壳在多维位置数据中提供了比ℓ1范数更准确且具有几何意义的敏感度度量。
- 平面各向同性机制(PIM)实现了微分隐私所需噪声的理论下限,确保最优效用。
- PIM在保持强隐私保障的同时,显著降低了噪声幅度,优于标准机制。
- 所提出的动态微分隐私框架通过建模轨迹中的时间相关性,有效抵抗推理攻击。
- 在真实世界GPS数据集上的评估证实,PIM在时间相关性下保持了高实用性与强隐私保护。
更好的研究,从现在开始
从阅读论文到最终审阅,大幅缩短您的研究时间。
无需绑定信用卡
本解读由 AI 生成,并经人工编辑审核。