Protecting location privacy: optimal strategy against localization attacks

Protecting location privacy: optimal strategy against localization attacks
复制标题

DOI:
10.1145/2382196.2382261
复制
发表时间:
2012-10
期刊:
Proceedings of the 2012 ACM conference on Computer and communications security
影响因子:
--
通讯作者:
R. Shokri;George Theodorakopoulos;C. Troncoso;J. Hubaux;J. L. Boudec
R. Shokri;George Theodorakopoulos;C. Troncoso;J. Hubaux;J. L. Boudec
中科院分区:
其他
文献类型:
--
作者:
R. Shokri;George Theodorakopoulos;C. Troncoso;J. Hubaux;J. L. Boudec

文献摘要

被引文献

相似文献

在基于位置的服务(LBS)中保护移动的用户位置隐私的主流方法是改变用户的实际位置以减少暴露给服务提供商的位置信息。一个有效的位置隐私保护机制(LPPM)背后的位置混淆算法必须考虑三个基本要素:用户的隐私要求,对手的知识和能力,以及最大限度地容忍服务质量下降的混淆的真实位置。我们提出了第一种方法,据我们所知,使设计师能够找到最佳的LPPM的LBS给定每个用户的服务质量约束对对手实施的最佳推理算法。这样的LPPM是一个最大化的预期失真(误差),最佳对手在重建用户的实际位置,同时满足用户的服务质量要求。我们形式化的相互优化的用户-对手的目标(位置隐私与本地化的正确性),通过使用Stackelberg贝叶斯博弈的框架。在这种情况下,我们开发了两个线性规划,输出最佳的LPPM策略和相应的最佳推理攻击。我们的最佳以用户为中心的LPPM可以很容易地集成到用户用于访问LBS的移动的设备中。我们验证了我们的博弈论方法对真实的位置痕迹的有效性。我们的评估证实,最佳的LPPM策略是上级一个简单的混淆方法,和最佳的本地化攻击相比,贝叶斯推理攻击表现更好。
The mainstream approach to protecting the location-privacy of mobile users in location-based services (LBSs) is to alter the users' actual locations in order to reduce the location information exposed to the service provider. The location obfuscation algorithm behind an effective location-privacy preserving mechanism (LPPM) must consider three fundamental elements: the privacy requirements of the users, the adversary's knowledge and capabilities, and the maximal tolerated service quality degradation stemming from the obfuscation of true locations. We propose the first methodology, to the best of our knowledge, that enables a designer to find the optimal LPPM for a LBS given each user's service quality constraints against an adversary implementing the optimal inference algorithm. Such LPPM is the one that maximizes the expected distortion (error) that the optimal adversary incurs in reconstructing the actual location of a user, while fulfilling the user's service-quality requirement. We formalize the mutual optimization of user-adversary objectives (location privacy vs. correctness of localization) by using the framework of Stackelberg Bayesian games. In such setting, we develop two linear programs that output the best LPPM strategy and its corresponding optimal inference attack. Our optimal user-centric LPPM can be easily integrated in the users' mobile devices they use to access LBSs. We validate the efficacy of our game theoretic method against real location traces. Our evaluation confirms that the optimal LPPM strategy is superior to a straightforward obfuscation method, and that the optimal localization attack performs better compared to a Bayesian inference attack.