Privacy-Preserving Aggregate Mobility Data Release: An Information-Theoretic Deep Reinforcement Learning Approach

Privacy-Preserving Aggregate Mobility Data Release: An Information-Theoretic Deep Reinforcement Learning Approach
复制标题

DOI:
10.1109/tifs.2022.3152361
复制
发表时间:
2022
影响因子:
6.8
通讯作者:
Wenjing Zhang;Bo Jiang;Ming Li;Xiaodong Lin
Wenjing Zhang;Bo Jiang;Ming Li;Xiaodong Lin
中科院分区:
计算机科学1区
文献类型:
--
作者:
Wenjing Zhang;Bo Jiang;Ming Li;Xiaodong Lin

文献摘要

相似文献

在各种实际应用中,保护用户的位置轨迹免受对从多个用户收集的聚合移动数据的推断攻击至关重要。现有的聚合移动数据的工作大多集中在推理攻击,而不是设计隐私保护的释放机制,和一些差分私人释放机制遭受穷人的效用隐私权衡。在本文中,我们提出了最佳的集中式隐私保护聚合移动数据发布机制(PAMDRM),从信息理论的角度来看,通过释放原始聚合位置的扰动版本,最大限度地减少泄漏。具体来说,我们使用互信息来衡量用户级和聚合级的隐私泄漏分别,并制定泄漏效用约束下的最小化问题。由于直接求解优化问题会产生指数复杂度w.r.t.用户的踪迹长度,我们把它们转化为信念状态马尔可夫决策过程(MDP),重点是MDP制定的用户级隐私问题。我们建立强化学习(RL)模型,并利用高效的异步优势演员-评论家RL算法来获得MDP的解决方案作为我们的最佳PAMDRM。我们比较他们与两个国家的最先进的隐私保护机制PDPR(上下文感知的本地设计)和DMLM(上下文无关的集中式设计)的相互信息泄漏和对手的攻击成功(评估她的预期估计误差和詹森-香农分歧为基础的错误)。在合成数据集和真实数据集上的大量实验结果表明,由于其上下文感知属性和集中式设计,用户级PAMDRM在这两种措施上表现最好。尽管聚合级PAMDRM比其他两种实现了更好的隐私-效用权衡,但它在对抗成功方面并不总是比它们表现得更好,这突出了从不同角度考虑隐私措施的必要性,以避免高估提供给用户的隐私水平。最后,我们讨论了一种替代的、完全数据驱动的方法,通过在有限的数据样本上利用对抗性训练来获得最佳的PAMDRM。
It is crucial to protect users’ location traces against inference attacks on aggregate mobility data collected from multiple users in various real-world applications. Most of the existing works on aggregate mobility data are focusing on inference attacks rather than designing privacy-preserving release mechanisms, and a few differential private release mechanisms suffer from poor utility-privacy tradeoffs. In this paper, we propose optimal centralized privacy-preserving aggregate mobility data release mechanisms (PAMDRMs) that minimize the leakage from an information-theoretic perspective by releasing perturbed versions of the raw aggregate location. Specifically, we use mutual information to measure user-level and aggregate-level privacy leakage separately, and formulate leakage minimization problems under utility constraints. As directly solving the optimization problems incur exponential complexity w.r.t. users’ trace length, we transform them into belief state Markov Decision Processes (MDPs), with a focus on the MDP formulation for the user-level privacy problem. We build reinforcement learning (RL) models and leverage the efficient Asynchronous Advantage Actor-Critic RL algorithm to derive the solutions to the MDPs as our optimal PAMDRMs. We compare them with two state-of-the-art privacy protection mechanisms PDPR (context-aware local design) and DMLM (context-free centralized design) in terms of mutual information leakage and adversary’s attack success (evaluated by her expected estimation error and Jensen-Shannon Divergence-based error). Extensive experimental results on both synthetic and real-world datasets demonstrate that the user-level PAMDRM performs the best on both measures thanks to its context-aware property and centralized design. Even though the aggregate-level PAMDRM achieves better privacy-utility tradeoff than the other two, it does not always perform better than them on adversarial success, highlighting the necessity of considering privacy measures from different perspectives to avoid overestimating the level of privacy offered to users. Lastly, we discuss an alternative, fully data-driven approach to derive the optimal PAMDRM by leveraging adversarial training on limited data samples.