提出新框架评估生成轨迹的隐私与实用平衡,发现看似安全的模型仍存泄露风险。
A Dual Perspective on Synthetic Trajectory Generators: Utility Framework and Privacy Vulnerabilities

- 构建双视角评估框架,同时衡量生成轨迹的实用性和隐私风险。
- 实验证明,即使抗链接攻击的生成模型仍可能被新攻击方式破解。
- 强调需用对抗测试评估隐私,符合欧盟现行法规要求。
人类移动数据广泛应用于公共卫生、城市规划等领域,但其敏感性极高,可能暴露宗教信仰、政治立场等信息。传统隐私保护方法如聚合、扰动或加噪虽有效,却严重损害数据实用性。近年来,生成模型技术为缓解隐私-效用矛盾提供了新路径。本文首次提出一套新的效用评估框架,并揭示隐私评估仍面临巨大挑战,应依据当前欧盟法规通过对抗性测试来实现。我们针对一类被认为具备隐私保护能力的生成模型(因其抵抗轨迹用户链接攻击),提出了新型成员推理攻击,证实其仍存在隐私泄露风险。
原文摘要 · Abstract (English)
Human mobility data are used in numerous applications, ranging from public health to urban planning. Human mobility is inherently sensitive, as it can contain information such as religious beliefs and political affiliations. Historically, it has been proposed to modify the information using techniques such as aggregation, obfuscation, or noise addition, to adequately protect privacy and eliminate concerns. As these methods come at a great cost in utility, new methods leveraging development in generative models, were introduced. The extent to which such methods answer the privacy-utility trade-off remains an open problem. In this paper, we introduced a first step towards solving it, by the introduction and application of a new framework for utility evaluation. Furthermore, we provide evidence that privacy evaluation remains a great challenge to consider and that it should be tackled through adversarial evaluation in accordance with the current EU regulation. We propose a new membership inference attack against a subcategory of generative models, even though this subcategory was deemed private due to its resistance over the trajectory user-linking problem.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。