Privacy-utility trades in crowdsourced signal map obfuscation

Privacy-utility trades in crowdsourced signal map obfuscation
复制标题

众包信号图混淆中的隐私-实用性交易

DOI:
10.1016/j.comnet.2022.109187
复制
发表时间:
2022
期刊:
影响因子:
5.6
通讯作者:
Kairouz, Peter
Kairouz, Peter
中科院分区:
计算机科学3区
文献类型:
--
作者:
Zhang, Jiang;Clark, Lillian;Clark, Matthew;Psounis, Konstantinos;Kairouz, Peter

文献摘要

相似文献

蜂窝提供商和数据聚合公司众包来自用户设备的蜂窝信号强度测量以生成信号地图,其可用于提高网络性能。认识到这种数据收集可能与人们日益增长的隐私意识不一致,我们考虑在数据离开移动终端之前对此类数据进行模糊处理。其目标是提高隐私性,使得难以从混淆的数据中恢复敏感特征(例如用户ID和用户行踪),同时仍然允许网络提供商使用数据来改善网络服务(即创建准确的信号映射)。为了研究这种隐私效用的权衡,我们确定了隐私和效用指标和适合信号强度测量的威胁模型。然后,我们使用几种卓越的技术来混淆测量结果,包括差分隐私,生成对抗隐私和信息理论隐私技术,以便对各种有前途的混淆方法进行基准测试,并为现实世界的工程师提供指导,这些工程师的任务是构建保护隐私而不损害实用性的信号映射。我们的评估结果,基于多个,不同的,真实世界的信号映射数据集,证明了同时实现足够的隐私和实用性的可行性,混淆策略在其设计中使用数据集的结构和预期用途,并以平均情况为目标,而不是最坏情况,保证。
Cellular providers and data aggregating companies crowdsource cellular signal strength measurements from user devices to generate signal maps, which can be used to improve network performance. Recognizing that this data collection may be at odds with growing awareness of privacy concerns, we consider obfuscating such data before the data leaves the mobile device. The goal is to increase privacy such that it is difficult to recover sensitive features from the obfuscated data (e.g. user ids and user whereabouts), while still allowing network providers to use the data for improving network services (i.e. create accurate signal maps). To examine this privacy-utility tradeoff, we identify privacy and utility metrics and threat models suited to signal strength measurements. We then obfuscate the measurements using several preeminent techniques, spanning differential privacy, generative adversarial privacy, and information-theoretic privacy techniques, in order to benchmark a variety of promising obfuscation approaches and provide guidance to real-world engineers who are tasked to build signal maps that protect privacy without hurting utility. Our evaluation results, based on multiple, diverse, real-world signal map datasets, demonstrate the feasibility of concurrently achieving adequate privacy and utility, with obfuscation strategies which use the structure and intended use of datasets in their design, and target average-case, rather than worst-case, guarantees.