Introducing Differential Privacy Mechanisms for Mobile App Analytics of Dynamic Content

Introducing Differential Privacy Mechanisms for Mobile App Analytics of Dynamic Content
复制标题

DOI:
10.1109/icsme46990.2020.00034
复制
发表时间:
2020-09
期刊:
2020 IEEE International Conference on Software Maintenance and Evolution (ICSME)
影响因子:
--
通讯作者:
S. Latif;Yu Hao;Hailong Zhang;Raef Bassily;A. Rountev
S. Latif;Yu Hao;Hailong Zhang;Raef Bassily;A. Rountev
中科院分区:
其他
文献类型:
--
作者:
S. Latif;Yu Hao;Hailong Zhang;Raef Bassily;A. Rountev

文献摘要

相似文献

移动的应用分析收集数百万应用用户的详细数据。客户和政府都越来越担心这种数据收集对隐私的影响。因此,非常希望设计移动的应用分析的隐私保护版本。我们的目标是使用差分隐私来实现这一目标,差分隐私是一种用于隐私保护数据分析的领先算法设计框架。我们将差分隐私应用于从内容服务器检索并显示给应用用户的动态创建的内容。然后,用户与此内容的交互将报告给应用分析基础设施。与之前相关工作中考虑的问题不同,这种分析可以传达大量敏感信息例如,关于应用程序用户的政治信仰、饮食选择、健康状况或旅行兴趣。为了对这些信息提供严格的隐私保护,我们设计了一个用于此类数据收集的差异化隐私解决方案。由于现有的方法无法解决这个问题,我们开发了一种新的设计,以确定应用程序如何在运行时收集数据,以及如何随机化数据以实现差异隐私。我们的第二个贡献是使用Google Firebase的Android应用程序的这种设计的实例化。这种方法将隐私逻辑与应用程序代码分开,并使用代码重写来自动引入和演化隐私相关的代码。最后,我们开发了自动化设计空间表征技术。通过模拟不同的执行场景并描述其隐私/准确性权衡,我们的分析为应用程序开发人员提供了关键的部署前见解。
Mobile app analytics gathers detailed data about millions of app users. Both customers and governments are becoming increasingly concerned about the privacy implications of such data gathering. Thus, it is highly desirable to design privacy-preserving versions of mobile app analytics. We aim to achieve this goal using differential privacy, a leading algorithm design framework for privacy-preserving data analysis.We apply differential privacy to dynamically-created content that is retrieved from a content server and is displayed to the app user. User interactions with this content are then reported to the app analytics infrastructure. Unlike problems considered in related prior work, such analytics could convey a wealth of sensitive information—for example, about an app user’s political beliefs, dietary choices, health conditions, or travel interests. To provide rigorous privacy protections for this information, we design a differentially-private solution for such data gathering.Our first contribution is a conceptual design for data collection. Since existing approaches cannot be used to solve this problem, we develop a new design to determine how the app gathers data at run time and how it randomizes it to achieve differential privacy. Our second contribution is an instantiation of this design for Android apps that use Google Firebase. This approach keeps privacy logic separate from the app code, and uses code rewriting to automate the introduction and evolution of privacy-related code. Finally, we develop techniques for automated design space characterization. By simulating different execution scenarios and characterizing their privacy/accuracy trade-offs, our analysis provides critical pre-deployment insights to app developers.