Matching Anonymized and Obfuscated Time Series to Users’ Profiles

Matching Anonymized and Obfuscated Time Series to Users’ Profiles
复制标题

DOI:
10.1109/tit.2018.2873134
复制
发表时间:
2017-09
影响因子:
2.5
通讯作者:
Nazanin Takbiri;Amir Houmansadr;D. Goeckel;H. Pishro-Nik
Nazanin Takbiri;Amir Houmansadr;D. Goeckel;H. Pishro-Nik
中科院分区:
计算机科学2区
文献类型:
--
作者:
Nazanin Takbiri;Amir Houmansadr;D. Goeckel;H. Pishro-Nik

文献摘要

被引文献

相似文献

许多流行的应用程序使用用户数据跟踪来为用户提供各种服务。然而,即使对用户数据进行了匿名化和模糊化处理,通过使用将用户跟踪与先前的用户行为相匹配的统计匹配技术,用户的隐私也可能受到损害。在本文中,我们推导了在这种情况下用户隐私的理论界限。我们以最近在位置隐私领域的研究为基础,在该研究中,我们为基于匿名的位置隐私保护机制引入了位置隐私的正式概念。在这里,我们推导出当匿名化和基于混淆的保护机制应用于用户的时间序列数据时,用户隐私的基本限制。我们研究了这些机制对隐私保护和用户效用之间权衡的影响。我们首先研究了用户时间序列由独立和同分布(i.i.d)过程控制的情况下的可实现性结果。对于i.i.d情况以及更一般的马尔可夫链模型,证明了相反的结果。我们证明,随着网络中用户数量的增长,模糊匿名化平面可以分为两个区域:在第一个区域,所有用户都具有完美的隐私;在第二个区域,用户没有隐私。
Many popular applications use traces of user data to offer various services to their users. However, even if user data are anonymized and obfuscated, a user’s privacy can be compromised through the use of statistical matching techniques that match a user trace to prior user behavior. In this paper, we derive the theoretical bounds on the privacy of users in such a scenario. We build on our recent study in the area of location privacy, in which we introduced formal notions of location privacy for anonymization-based location privacy-protection mechanisms. Here, we derive the fundamental limits of user privacy when both anonymization and obfuscation-based protection mechanisms are applied to users’ time series of data. We investigate the impact of such mechanisms on the tradeoff between privacy protection and user utility. We first study achievability results for the case where the time-series of users are governed by an independent and identically distributed (i.i.d.) process. The converse results are proved both for the i.i.d. case as well as the more general Markov chain model. We demonstrate that as the number of users in the network grows, the obfuscation-anonymization plane can be divided into two regions: in the first region, all users have perfect privacy; and, in the second region, no user has privacy.