On the limitations of existing notions of location privacy

On the limitations of existing notions of location privacy
复制标题

DOI:
10.1016/j.future.2017.05.045
复制
发表时间:
2017-07
期刊:
Future Gener. Comput. Syst.
影响因子:
--
通讯作者:
K. Dong;Taolin Guo;Haibo Ye;Xuansong Li;Zhen Ling
K. Dong;Taolin Guo;Haibo Ye;Xuansong Li;Zhen Ling
中科院分区:
其他
文献类型:
--
作者:
K. Dong;Taolin Guo;Haibo Ye;Xuansong Li;Zhen Ling

文献摘要

被引文献

相似文献

在单一位置信息报告的背景下,现有研究通过对手的不确定性、不准确性或估计的不正确来定义位置隐私,或者通过地理不可分辨来定义位置隐私,地理不可区分性是差异隐私的推广。这些现有的概念中的每一个在一些特定的场景中都有问题。在本文中,我们通过构建这样的场景来说明现有概念的局限性,并通过量化可能位置上的先验分布和后验分布之间的距离来引入位置隐私的形式化定义。此外,我们还展示了如何通过求解一个优化问题来构造一个接近最优的混淆机制。我们使用我们提出的隐私度量和基于估计距离误差的传统度量,将我们提出的机制与基于拉普拉斯噪声的地理不可区分机制和Shokri的最优混淆机制进行了比较。结果表明,我们提出的度量更好地描述了位置隐私,并且在隐私和效用之间取得了更好的折衷。
In the context of a single report of location information, existing researches define location privacy by adversary’s uncertainty, inaccuracy, or incorrectness of the estimation, or by geo-indistinguishability which is a generalization of differential privacy. Each of these existing notions has problems in some specific scenarios. In this paper we illustrate the limitations of existing notions by constructing such scenarios, and introduce a formal definition on location privacy by quantifying the distance between the prior and posterior distribution over the possible locations. Further more, we show how to construct a near-optimal obfuscation mechanism by solving an optimization problem. We compare our proposed mechanism with the Laplace noise based geo-indistinguishable mechanism, and Shokri’s optimal obfuscation mechanism, using both our proposed privacy metric and the traditional metric based on the estimated distance errors. The results show that our proposed metric better describes location privacy and our proposed mechanism makes a better tradeoff between privacy and utility.