Oblivious Statistic Collection With Local Differential Privacy in Mutual Distrust

Oblivious Statistic Collection With Local Differential Privacy in Mutual Distrust
复制标题

互不信任中局部差分隐私的遗忘统计集合

DOI:
10.1109/access.2023.3251560
复制
发表时间:
2023
期刊:
影响因子:
3.9
通讯作者:
Taisho Sasada;Yuzo Taenaka;Y. Kadobayashi
Taisho Sasada;Yuzo Taenaka;Y. Kadobayashi
中科院分区:
计算机科学3区
文献类型:
--
作者:
Taisho Sasada;Yuzo Taenaka;Y. Kadobayashi

文献摘要

相似文献

位置数据对于流行病学、自然灾害和城市规划等各种应用程序很有价值,但会导致从数据存储中收集的数据中暴露敏感信息,例如家庭或工作地点。基于本地差分隐私(LDP)的数据收集是一种很有前途的保护敏感信息的技术。移动设备修改数据以使每条数据无法与其他数据区分,但保持其在数据中的统计特征的内在价值。虽然LDP从根本上保护了数据存储的隐私暴露,但数据存储存在一个缺点:由于隐藏的原始数据,数据存储永远无法验证修改后的数据,这允许任何人篡改自己的数据或注入任意数量的数据,从而操纵数据存储中整个数据的统计,称为数据中毒攻击。由于设备不披露原始数据,并且数据存储无法与可能是这种相互不信任关系上的对手的设备协作来验证数据,因此数据收集需要能够避免数据中毒的影响。数据中毒的原因是数据量和统计数据之间的直接关系;设备发送的数据越多,数据存储区中合并的数据就会发生更多的统计变化。在本文中,我们提出在基于LDP的数据收集过程中将统计特征与数据量解耦,以最小化有毒数据对数据存储的影响。我们利用不经意传输(OT)协议来仅检索在数据存储处接收数据的统计特征。由于OT协议不可避免地加强了对基于LDP的数据采集的隐私保护,相应地丢弃了数据的统计特征,因此我们调整了LDP处理,使其与OT协议协同工作。所提出的调整方法使LDP的保护强度适应OT协议的行为,从而使数据存储接收到包含足够统计特征的数据。我们进行了定性和实验开销分析,表明我们的方法将统计特征与数据量之间的关系解耦。我们的实验结果也证明,在智能手机和物联网等设备上,该开销是可以接受的。
Location data is valuable for various applications such as epidemiology, natural disasters, and urban planning but causes exposure of sensitive information, e.g., home or work place, from collected data in a datastore. Local Differential Privacy (LDP)-based data collection is a promising technology to protect sensitive information. A mobile device modify data to make each piece of data indistinguishable from others but keep its intrinsic value for statistical characteristics in data. Although LDP fundamentally protects the privacy exposure from a data store, a datastore suffer a shortcomings on it; as a datastore can never validate the modified data due to concealed raw data, that allows anyone to tamper with one’s data or inject any amount of data, and thus manipulate the statistics of the whole data in a datastore, called data poisoning attack. As a device does not disclose raw data and a datastore cannot collaborate to validate data with a device who may be an adversary on this mutual distrust relationship, data collection needs an ability to avoid the effect of data poisoning.. The cause of data poisoning is the direct relationship between data volume and statistic; the more data a device sends gives more statistical changes on merged data in a datastore. In this paper, we propose to decouple statistical characteristics from data volumes on LDP-based data collection process to minimize the effect of poisoned data on a datastore. We utilize Oblivious Transfer (OT) protocol to retrieve only statistic characteristics of receiving data at a datastore. As OT protocol inevitably strengthen privacy protection on LDP-based data collection and accordingly drops statistic characteristics of data, We adjust LDP processing to collaboratively work with OT protocol. The proposed adjustment method adapts the protection strength of LDP to OT protocol behavior so that a data store receives data containing sufficient statistical characteristics. We conduct qualitative and experimental overhead analysis and show that our method decouples the relationship between statistical characteristics from data volume. Our experimental result also prove that the overhead can be acceptable on devices such as smartphones and IoT.