Privacy-Preserving Crowd-Sourced Statistical Data Publishing with An Untrusted Server

Privacy-Preserving Crowd-Sourced Statistical Data Publishing with An Untrusted Server
复制标题

使用不受信任的服务器发布保护隐私的众包统计数据

DOI:
10.1109/tmc.2018.2861765
复制
发表时间:
2019-06-01
影响因子:
7.9
通讯作者:
Qi, Hairong
Qi, Hairong
中科院分区:
计算机科学2区
文献类型:
--
作者:
Wang, Zhibo;Pang, Xiaoyi;Qi, Hairong

文献摘要

被引文献

相似文献

不断向公众发布关于众包数据的汇总统计数据,使得许多数据挖掘应用成为可能(例如,实时交通分析)。现有系统通常依赖于可信服务器来聚合时空众源数据,然后在发布之前应用差异隐私机制对聚合统计数据进行扰动,从而提供强大的隐私保障。然而,一旦服务器遭到黑客攻击或无法信任,用户的隐私就会暴露出来。本文研究了非可信服务器下具有强隐私保护的实时众包统计数据发布问题。提出了一种新的基于分布式代理的隐私保护框架dADP,该框架在用户和不可信服务器之间引入了新的多代理。用户可以随机选择一个代理,通过匿名连接技术将签到信息上传到它,而不是直接将签到信息上传到不可信的服务器。每个代理聚合接收到的众包数据,并使用拉普拉斯机制在本地扰乱聚合的统计数据。来自所有代理的扰动统计数据被进一步组合在一起,形成用于发布的整个扰动统计数据。特别提出了分布式预算分配机制和基于代理的动态分组机制,以分布式方式实现全局$w$w-Event$\epsilon$ε-Differential隐私。证明了该协议能够为不可信服务器下的实时众包统计数据发布提供$w$w-Event$\epsilon$ε-Differential隐私保护。在真实数据集上的大量实验证明了dADP的有效性。
The continuous publication of aggregate statistics over crowd-sourced data to the public has enabled many data mining applications (e.g., real-time traffic analysis). Existing systems usually rely on a trusted server to aggregate the spatio-temporal crowd-sourced data and then apply differential privacy mechanism to perturb the aggregate statistics before publishing to provide strong privacy guarantee. However, the privacy of users will be exposed once the server is hacked or cannot be trusted. In this paper, we study the problem of real-time crowd-sourced statistical data publishing with strong privacy protection under an untrusted server. We propose a novel distributed agent-based privacy-preserving framework, called DADP, that introduces a new level of multiple agents between the users and the untrusted server. Instead of directly uploading the check-in information to the untrusted server, a user can randomly select one agent and upload the check-in information to it with the anonymous connection technology. Each agent aggregates the received crowd-sourced data and perturbs the aggregated statistics locally with Laplace mechanism. The perturbed statistics from all the agents are further combined together to form the entire perturbed statistics for publication. In particular, we propose a distributed budget allocation mechanism and an agent-based dynamic grouping mechanism to realize global $w$w-event $\epsilon$ε-differential privacy in a distributed way. We prove that DADP can provide $w$w-event $\epsilon$ε-differential privacy for real-time crowd-sourced statistical data publishing under the untrusted server. Extensive experiments on real-world datasets demonstrate the effectiveness of DADP.