Future Generation Computer Systems Optimization of privacy-utility trade-offs under informational self-determination

Future Generation Computer Systems Optimization of privacy-utility trade-offs under informational self-determination
复制标题

下一代计算机系统信息自决下隐私-效用权衡的优化

DOI:
--
复制
发表时间:
--
期刊:
影响因子:
--
通讯作者:
R. Zheng
R. Zheng
中科院分区:
--
文献类型:
--
作者:
Xiaolan Xu;P. Xu;Xiaoyan Wu;Hua Lin;Yin Chen;Xiaohua Hu;Jiangquan Yu;R. Zheng

文献摘要

被引文献

相似文献

·一个通用的、新颖的框架,用于衡量和优化隐私效用的权衡。·对智能电网试点项目的真实世界数据的分析证明和应用。·隐私-效用权衡在信息自我评估下得到优化。物联网的普及导致用户(数据生产者)的智能设备产生了海量的个人数据,如智能手机、可穿戴设备和其他嵌入式传感器。大规模转移这些数据是一种常见的要求,尤其是对于大数据分析系统,而运行和管理这些系统的第三方distributeddatatocentralizedcomputationalsystemsforanalysis.Nevertheless,(数据消费者)并不总是能保证用户的隐私。他们的主要兴趣是toimproveutilitythatisusuallyametricrelatedtotheperformance,成本和服务质量。有几种技术可以屏蔽用户生成的数据以确保隐私,例如差异隐私。参考本文中的“隐私设置”,设置询问数据的处理程序一方面减少了数据分析的效用,另一方面增加了隐私。本文研究隐私设置的参数设置,它调节最大效用、最小隐私和最小效用、最大隐私之间的权衡,其中效用指的是聚集函数估计的准确性。隐私设置可以作为系统范围的参数和策略(同构数据共享)普遍应用。尽管如此,它们也可以由每个用户自主应用,或者在(金钱)激励(异类数据共享)的影响下决定。后一种通过信息自主共享数据的多样性对隐私-效用轨迹起着关键作用,本文在理论和经验上都表明了这一点。介绍了一种通用的、新颖的计算框架,用于衡量隐私-效用权衡及其帕累托最优。该框架计算了一系列这样的权衡,这些权衡形成了同质和异质数据共享下的隐私效用轨迹。该框架的实际使用是使用来自智能电网试点项目的真实世界数据进行的实验评估,在该试点项目中,能源消费者通过调节共享电力需求数据的质量来保护自己的隐私,而公用事业公司则对网络中的总负荷进行准确的估计,以管理电网。超过20,000个不同的隐私设置被应用来塑造计算轨迹,这些轨迹反过来为数据消费者和生产者提供了参与可行的参与式数据共享系统的巨大潜力。
• A generic, novel framework for measuring & optimizing privacy-utility trade-offs. • An analytical proof & application to real-world data from a Smart-Grid pilot project. • Privacy-utility tradeoffs are optimized under informational self-evaluation. The pervasiveness of Internet of Things results in vast volumes of personal data generated by smart devices of users (data producers) such as smart phones, wearables and other embedded sensors. It is a common requirement, especially for Big Data analytics systems, to transfer these large in scale and distributeddatatocentralizedcomputationalsystemsforanalysis.Nevertheless,thirdpartiesthatrunand manage these systems (data consumers) do not always guarantee users’ privacy. Their primary interest is toimproveutilitythatisusuallyametricrelatedtotheperformance,costsandthequalityofservice.There are several techniques that mask user-generated data to ensure privacy, e.g. differential privacy. Setting upaprocessformaskingdata,referredtointhispaperasa‘privacysetting’,decreasesontheonehandthe utility of data analytics, while, on the other hand, increases privacy. This paper studies parameterizations of privacy settings that regulate the trade-off between maximum utility, minimum privacy and minimum utility, maximum privacy, where utility refers to the accuracy in the estimations of aggregation functions. Privacy settings can be universally applied as system-wide parameterizations and policies (homogeneous data sharing). Nonetheless they can also be applied autonomously by each user or decided under the influence of (monetary) incentives (heterogeneous data sharing). This latter diversity in data sharing by informational self-determination plays a key role on the privacy-utility trajectories as shown in this paper both theoretically and empirically. A generic and novel computational framework is introduced for measuring privacy-utility trade-offs and their Pareto optimization. The framework computes a broad spectrum of such trade-offs that form privacy-utility trajectories under homogeneous and heterogeneous data sharing. The practical use of the framework is experimentally evaluated using real-world data from a Smart Grid pilot project in which energy consumers protect their privacy by regulating the quality of the shared power demand data, while utility companies make accurate estimations of the aggregate load in the network to manage the power grid. Over 20 , 000 differential privacy settings are applied to shape the computational trajectories that in turn provide a vast potential for data consumers and producers to participate in viable participatory data sharing systems.