Designing a Location Trace Anonymization Contest

Designing a Location Trace Anonymization Contest
复制标题

DOI:
10.56553/popets-2023-0014
复制
发表时间:
2021-07
期刊:
Proc. Priv. Enhancing Technol.
影响因子:
--
通讯作者:
Takao Murakami;Hiromi Arai;Koki Hamada;Takuma Hatano;M. Iguchi;Hiroaki Kikuchi;Atsushi Kuromasa;Hiroshi Nakagawa;Yuichi Nakamura;Kenshiro Nishiyama;R. Nojima;Hidenobu Oguri;Chiemi Watanabe;A. Yamada;Takayasu Yamaguchi;Yuji Yamaoka
Takao Murakami;Hiromi Arai;Koki Hamada;Takuma Hatano;M. Iguchi;Hiroaki Kikuchi;Atsushi Kuromasa;Hiroshi Nakagawa;Yuichi Nakamura;Kenshiro Nishiyama;R. Nojima;Hidenobu Oguri;Chiemi Watanabe;A. Yamada;Takayasu Yamaguchi;Yuji Yamaoka
中科院分区:
其他
文献类型:
--
作者:
Takao Murakami;Hiromi Arai;Koki Hamada;Takuma Hatano;M. Iguchi;Hiroaki Kikuchi;Atsushi Kuromasa;Hiroshi Nakagawa;Yuichi Nakamura;Kenshiro Nishiyama;R. Nojima;Hidenobu Oguri;Chiemi Watanabe;A. Yamada;Takayasu Yamaguchi;Yuji Yamaoka

文献摘要

相似文献

为了更好地理解位置跟踪的匿名化方法,我们设计并举办了一场位置跟踪匿名化竞赛,该竞赛涉及长跟踪(每个用户400个事件)和细粒度位置(1024个区域)。在我们的比赛中,每个团队匿名化她的原始轨迹,然后其他团队对匿名化的轨迹进行隐私攻击。换句话说,防守和进攻都在一起竞争,这与真实的生活中发生的情况很接近。在我们的比赛之前,我们表明,重新识别本身是不足以作为一个隐私风险,痕迹推断应被添加为一个额外的风险。具体来说,我们展示了一个匿名化的例子,它对重新识别是完全安全的,但对跟踪推断是不安全的。在此基础上,我们的比赛评估了重新识别风险和痕迹推断风险,并分析了它们之间的关系。通过我们的比赛,我们展示了几个发现的情况下,防御和攻击竞争在一起。特别是,我们表明,匿名化方法安全的痕迹推断也是安全的,对重新识别下存在适当的匿名化。我们还报告了获得第一名的防御和攻击算法,并分析了团队在POI推荐和地理数据分析等各种应用中提交的匿名跟踪的实用性。
For a better understanding of anonymization methods for location traces, we have designed and held a location trace anonymization contest that deals with a long trace (400 events per user) and fine-grained locations (1024 regions). In our contest, each team anonymizes her original traces, and then the other teams perform privacy attacks against the anonymized traces. In other words, both defense and attack compete together, which is close to what happens in real life. Prior to our contest, we show that re-identification alone is insufficient as a privacy risk and that trace inference should be added as an additional risk. Specifically, we show an example of anonymization that is perfectly secure against re-identification and is not secure against trace inference. Based on this, our contest evaluates both the re-identification risk and trace inference risk and analyzes their relationship. Through our contest, we show several findings in a situation where both defense and attack compete together. In particular, we show that an anonymization method secure against trace inference is also secure against re-identification under the presence of appropriate pseudonymization. We also report defense and attack algorithms that won first place, and analyze the utility of anonymized traces submitted by teams in various applications such as POI recommendation and geo-data analysis.