On Function Computation With Privacy and Secrecy Constraints

On Function Computation With Privacy and Secrecy Constraints
复制标题

DOI:
10.1109/tit.2019.2922634
复制
发表时间:
2019-10-01
影响因子:
2.5
通讯作者:
Lai, Lifeng
Lai, Lifeng
中科院分区:
计算机科学2区
文献类型:
--
作者:
Tu, Wenwen;Lai, Lifeng

文献摘要

被引文献

相似文献

在本文中,考虑了具有隐私和保密约束的函数计算问题。所考虑的模型由三个合法节点组成(即两个发送方,爱丽丝和鲍勃,以及一个作为接收方的融合中心),它们观测相关信源,并通过无噪声公共信道相连,还有一个窃听者伊芙,她能完全访问公共信道,并且也有自己的信源观测值。融合中心希望在某一失真度量下,在预先设定的失真水平内计算分布式信源的一个函数。为了便于函数计算,爱丽丝和鲍勃将向融合中心发送消息。与函数计算中的现有设置不同,我们假设爱丽丝和鲍勃的信源存在隐私约束。特别是,爱丽丝和鲍勃希望融合中心能够计算函数,但同时,他们又不希望融合中心过多了解信源观测值的信息。我们引入一个量来精确度量向融合中心的隐私泄漏。除了这种隐私约束,我们对伊芙还有一个保密约束,并使用信源的疑义度来度量这个量。在这个模型下,我们研究消息速率、私有信息泄漏、疑义度和失真之间的权衡。我们首先考虑只有一个发送方的情况,即鲍勃处的信源为空,并完全以单字母形式刻画相应的区域。然后,我们考虑更一般的情况,并给出相应区域的外界和内界。
In this paper, the problem of function computation with privacy and secrecy constraints is considered. The considered model consists of three legitimate nodes (i.e., two transmitters, Alice and Bob, and a fusion center that acts as the receiver) that observe correlated sources and are connected by noiseless public channels, and an eavesdropper Eve who has full access to the public channels and also has its own source observations. The fusion center would like to compute a function of the distributed sources within a prefixed distortion level under a certain distortion metric. To facilitate the function computation, Alice and Bob will send messages to the fusion center. Different from the existing setups in function computation, we assume that there is a privacy constraint on the sources at Alice and Bob. In particular, Alice and Bob would like to enable the fusion center to compute the function, but at same time, they do not want the fusion center to learn too much information about the source observations. We introduce a quantity to precisely measure the privacy leakage to the fusion center. In addition to this privacy constraint, we also have a secrecy constraint to Eve and use equivocation of sources to measure this quantity. Under this model, we study the tradeoffs among message rates, private information leakage, equivocation, and distortion. We first consider a scenario that has only one transmitter, i.e., the source at Bob is empty, and fully singleletter characterize the corresponding regions. Then, we consider the more general case and provide both outer and inner bounds on the corresponding regions.