Skip to main content
QUICK REVIEW

[论文解读] Quantifying Surveillance in the Networked Age: Node-based Intrusions and Group Privacy.

Laura Radaelli, Piotr Sapieżyński|arXiv (Cornell University)|Mar 23, 2018
Privacy-Preserving Technologies in Data参考文献 17被引用 14
一句话总结

本文通过引入节点可观测性和边可观测性度量,形式化了网络化系统中的群体隐私问题,表明枢纽节点会增加监控风险,而聚类则会降低风险。利用合成数据和真实移动数据,研究发现仅 compromising 1% 的节点即可暴露 46% 的通信内容,揭示了以个体为中心的隐私模型在系统层面的脆弱性。

ABSTRACT

From the right to be left alone to the right to selective disclosure, privacy has long been thought as the control individuals have over the information they share and reveal about themselves. However, in a world that is more connected than ever, the choices of the people we interact with increasingly affect our privacy. This forces us to rethink our definition of privacy. We here formalize and study, as local and global node- and edge-observability, Bloustein's concept of group privacy. We prove edge-observability to be independent of the graph structure, while node-observability depends only on the degree distribution of the graph. We show on synthetic datasets that, for attacks spanning several hops such as those implemented by social networks and current US laws, the presence of hubs increases node-observability while a high clustering coefficient decreases it, at fixed density. We then study the edge-observability of a large real-world mobile phone dataset over a month and show that, even under the restricted two-hops rule, compromising as little as 1% of the nodes leads to observing up to 46% of all communications in the network. More worrisome, we also show that on average 36\% of each person's communications would be locally edge-observable under the same rule. Finally, we use real sensing data to show how people living in cities are vulnerable to distributed node-observability attacks. Using a smartphone app to compromise 1\% of the population, an attacker could monitor the location of more than half of London's population. Taken together, our results show that the current individual-centric approach to privacy and data protection does not encompass the realities of modern life. This makes us---as a society---vulnerable to large-scale surveillance attacks which we need to develop protections against.

研究动机与目标

  • 通过节点可观测性和边可观测性度量,形式化 Bloustein 提出的网络环境中群体隐私概念。
  • 分析图结构(尤其是度分布、聚类和枢纽节点)对监控暴露的影响。
  • 利用大规模移动数据集,评估节点 compromised 对通信和位置隐私的现实影响。
  • 证明当前以个体为中心的隐私模型无法有效防范大规模、分布式监控攻击。

提出的方法

  • 定义局部和全局的节点可观测性与边可观测性作为正式度量,用于量化网络中的监控暴露程度。
  • 证明边可观测性独立于图结构,而节点可观测性仅取决于度分布。
  • 使用合成网络模型,模拟在不同结构特性(密度、聚类、枢纽节点)下的多跳监控攻击。
  • 分析一个月内的真实移动电话数据集,测量在两跳规则下的边可观测性。
  • 部署智能手机应用,模拟分布式节点 compromised,评估城市人群中位置隐私暴露程度。
  • 利用真实传感数据,建模低概率节点 compromised 所引发的城市级监控风险。

实验结果

研究问题

  • RQ1在监控场景中,网络结构(特别是度分布、聚类和枢纽节点)如何影响节点可观测性和边可观测性?
  • RQ2在真实网络中, compromising 少量节点在多大程度上会导致广泛通信监控?
  • RQ3两跳监控规则对个体通信和位置可观测性产生何种影响?
  • RQ4对 1% 人口的分布式攻击是否足以实现对城市人群的大规模监控?
  • RQ5当前以个体为中心的隐私模型在多大程度上无法防范群体层面的监控风险?

主要发现

  • 在真实移动网络中,仅 compromising 1% 的节点,即可在两跳监控规则下观察到高达 46% 的全部通信。
  • 当仅 1% 的节点被 compromising 时,平均每个个体的 36% 通信内容在局部具有边可观测性。
  • 枢纽节点的存在会提高节点可观测性,而较高的聚类系数则会降低节点可观测性,即使在固定网络密度下也是如此。
  • 通过智能手机应用 compromising 伦敦 1% 的人口,即可实现实时位置数据中对超过一半城市人口的监控。
  • 节点可观测性仅取决于网络的度分布,而边可观测性则与图结构无关。
  • 研究结果揭示了以个体为中心的隐私模型存在系统性漏洞,凸显了在联网社会中推行集体隐私保护机制的必要性。

更好的研究,从现在开始

从阅读论文到最终审阅,大幅缩短您的研究时间。

无需绑定信用卡

本解读由 AI 生成,并经人工编辑审核。