No Video Left Behind: A Utility-Preserving Obfuscation Approach for YouTube Recommendations

No Video Left Behind: A Utility-Preserving Obfuscation Approach for YouTube Recommendations
复制标题

DOI:
10.48550/arxiv.2210.08136
复制
发表时间:
2022
期刊:
ArXiv
影响因子:
--
通讯作者:
Jiang Zhang;Hadi Askari;Konstantinos Psounis;Zubair Shafiq
Jiang Zhang;Hadi Askari;Konstantinos Psounis;Zubair Shafiq
中科院分区:
其他
文献类型:
--
作者:
Jiang Zhang;Hadi Askari;Konstantinos Psounis;Zubair Shafiq

文献摘要

相似文献

在线内容平台通过向用户提供个性化推荐来优化参与度。这些推荐系统跟踪和分析用户,以预测用户可能感兴趣的相关内容。虽然个性化推荐为用户提供了实用性,但使其能够实现的跟踪和分析带来了隐私问题,因为平台可能会推断出潜在的敏感用户兴趣。人们对构建不依赖于在线内容平台的合作的隐私增强混淆方法越来越感兴趣。然而,现有的混淆方法主要集中在增强隐私,但同时它们降低了效用,因为混淆引入了不相关的推荐。我们设计并实现了D E -H ARPO,一种用于YouTube推荐系统的混淆方法,不仅混淆用户的视频观看历史以保护隐私,而且还对YouTube的视频推荐进行去噪以保留其实用性。与现有的混淆方法相比,DE-H ARPO添加了利用“秘密”输入的去噪器(即,用户的实际观看历史)以及也可用于对抗性推荐系统的信息(即,混淆的观看历史和对应的“嘈杂”推荐)。我们对D E-H ARPO的大规模评估表明,它在保持相同隐私水平的效用方面优于最先进的2倍,同时保持隐蔽性和去混淆的鲁棒性。
Online content platforms optimize engagement by providing personalized recommendations to their users. These recommendation systems track and profile users to predict relevant content a user is likely interested in. While the personalized recommendations provide utility to users, the tracking and profiling that enables them poses a privacy issue because the platform might infer potentially sensitive user interests. There is increasing interest in building privacy-enhancing obfuscation approaches that do not rely on cooperation from online content platforms. However, existing obfuscation approaches primarily focus on enhancing privacy but at the same time they degrade the utility because obfuscation introduces unrelated recommendations. We design and implement D E -H ARPO , an obfuscation approach for YouTube’s recommendation system that not only obfuscates a user’s video watch history to protect privacy but then also denoises the video recommendations by YouTube to preserve their utility. In contrast to prior obfus-cation approaches, D E -H ARPO adds a denoiser that makes use of a “secret” input (i.e., a user’s actual watch history) as well as information that is also available to the adversarial recommendation system (i.e., obfuscated watch history and corresponding “noisy" recommendations). Our large-scale evaluation of D E -H ARPO shows that it outperforms the state-of-the-art by a factor of 2 × in terms of preserving utility for the same level of privacy, while maintaining stealthiness and robustness to de-obfuscation.