Knock Knock, Who’s There? Membership Inference on Aggregate Location Data∗
Apostolos Pyrgelis University College London Carmela Troncoso IMDEA Software Institute Emiliano De Cristofaro University College London
Abstract
Aggregate location data is often used to support smart services and applications, e.g., generating live traffic maps or predicting visits to businesses. In this paper, we present the first study on the feasibility of membership inference attacks on aggregate location time-series. We introduce a game-based definition of the adversarial task, and cast it as a classification problem where machine learning can be used to distinguish whether or not a target user is part of the aggregates.
中文速览
用于生成实时交通地图或预测商家到访人数的位置数据聚合统计,长期被视为保护个人隐私的有效手段,但其实聚合结果仍可能暴露参与者的身份信息。这篇论文首次系统研究了针对聚合位置时间序列(aggregate location time-series)的成员推断攻击(membership inference attack)——即攻击者试图判断某个目标用户的位置数据是否被纳入了某次聚合统计中——将其建模为一个可区分性博弈,并用机器学习分类器来实施攻击。在两个真实出行数据集上的实验表明,攻击效果相当显著:当攻击者掌握少量用户的历史位置时,分类器AUC可达0.83,而在更强先验知识条件下甚至接近1.0;差分隐私(differential privacy)防御机制虽能降低攻击成效,但代价是较大的数据可用性损失,且"策略性攻击者"通过模拟噪声机制重新训练分类器后,可将防护效果削减高达83%。这项工作揭示了聚合位置数据远比人们通常认为的更易泄露个人隐私,为数据发布前的隐私质量评估和监管合规检测提供了切实可用的方法论工具。
原文 arXiv:1708.06145;中英对照 + 大白话阅读 https://aha.fim.ai/paper/1708.06145v2