Dynamic Differential Location Privacy with Personalized Error Bounds

نویسندگان

  • Lei Yu
  • Ling Liu
  • Calton Pu
چکیده

Location privacy continues to attract significant attentions in recent years, fueled by the rapid growth of locationbased services (LBSs) and smart mobile devices. Location obfuscation has been the dominating location privacy preserving approach, which transforms the exact location of a mobile user to a perturbed location before its public release. The notion of location privacy has evolved from user-defined location kanonymity to two statistical quantification based privacy notions: geo-indistinguishability and expected inference error. The former promotes differential location privacy but does not protect location against inference attacks of Bayesian adversary with using prior information, whereas the latter promotes the background inference resilient location privacy but does not guarantee differential location privacy with respect to geo-indistinguishability. In this paper we argue that geo-indistinguishability and expected inference error are two complementary notions for location privacy. We formally study the relationship between two privacy notions. By leveraging this relationship and a personalized error bound, we can effectively combine the two privacy notions. We develop PIVE, a two-phase dynamic differential location privacy framework. In Phase I, we take into account the user-defined inference error threshold and the prior knowledge about the user’s location to determine a subset of locations as the protection location set for protecting the actual location by increasing adversary’s expected location inference error. In Phase II, we generate pseudo-locations (i.e., perturbed locations) in the way that achieves differential privacy over the protection location set. This two-phase location obfuscation is constructed dynamically by leveraging the relationship between two privacy notions based on adversary’s current prior information and user-specific privacy requirements on different locations and at different times. Experiments with real-world datasets demonstrate that our PIVE approach effectively guarantees the two privacy notions simultaneously and outperforms the existing mechanisms in terms of adaptive privacy protection in presence of skewed locations and computation efficiency.

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

Personalized Social Recommendations - Accurate or Private?

With the recent surge of social networks such as Facebook, new forms of recommendations have become possible – recommendations that rely on one’s social connections in order to make personalized recommendations of ads, content, products, and people. Since recommendations may use sensitive information, it is speculated that these recommendations are associated with privacy risks. The main contri...

متن کامل

A Privacy-Preserving Framework for Personalized, Social Recommendations

We consider the problem of producing item recommendations that are personalized based on a user’s social network, while simultaneously preventing the disclosure of sensitive user-item preferences (e.g., product purchases, ad clicks, web browsing history, etc.). Our main contribution is a privacypreserving framework for a class of social recommendation algorithms that provides strong, formal pri...

متن کامل

A Privacy Policy for Continuous Query Processing through Location Based Services

With recent technological advancements in mobile devices, such as smart phones and tablets, Location-Based Services (LBSs) have surfaced as prominent applications in mobile networks. An important challenge in the wide deployment of location-based services (LBSs) is the privacyaware management of location information, providing safeguards for location privacy of mobile clients against vulnerabil...

متن کامل

On the (Im)possibility of Preserving Utility and Privacy in Personalized Social Recommendations

With the recent surge of social networks like Facebook, new forms of recommendations have become possible – personalized recommendations of ads, content, and even new social and product connections based on one’s social interactions. In this paper, we study whether “social recommendations”, or recommendations that utilize a user’s social network, can be made without disclosing sensitive links b...

متن کامل

Design of Policy-Aware Differentially Private Algorithms

Recent work has proposed a privacy framework, calledBlowfish, that generalizes differential privacy in order togenerate principled relaxations. Blowfish privacy defini-tions take as input an additional parameter called a policygraph, which specifies which properties about individualsshould be hidden from an adversary. An open question isto characterize when Blowfish priv...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

عنوان ژورنال:

دوره   شماره 

صفحات  -

تاریخ انتشار 2017