检验生成模型在轨迹数据中的隐私风险,发现其仍存泄露隐患。
Privacy Evaluation of Generative Models for Trajectory Generation
- 通过成员推断攻击评估生成轨迹模型的隐私保护能力
- 实证发现生成模型仍可被攻破,隐私风险显著
- 为轨迹生成模型提供可操作的隐私评估方法,适合安全研究者
轨迹数据是现代城市智能的基础,但其敏感性带来重大隐私担忧。生成模型如生成对抗网络(GAN)、变分自编码器(VAE)和扩散模型,通过捕捉时空分布与出行模式生成逼真合成轨迹数据。尽管这些模型因生成特性常被认为能保护隐私,但该假设未必成立。本文研究生成轨迹建模与隐私评估的交叉问题,识别适用于轨迹生成任务的实证隐私评估方法,揭示当前对生成轨迹模型隐私评估的重大空白。基于此,我们对代表性模型实施成员推断攻击,验证了此类实证方法的可行性,并表明生成模型的生成特性无法消除隐私风险。
原文摘要 · Abstract (English)
Trajectory data is fundamental to modern urban intelligence, yet its sensitivity raises significant privacy concerns. Generative models such as Generative Adversarial Networks, Variational Autoencoders, and Diffusion Models have been developed to generate realistic synthetic trajectory data by capturing underlying spatiotemporal distributions and mobility patterns. Although these models are often assumed to preserve privacy due to their generative nature, this assumption does not necessarily hold. In this work, we investigate the intersection of generative trajectory modeling and privacy evaluation. By identifying applicable empirical methods for assessing privacy preservation in trajectory generation tasks, we demonstrate a significant gap in the evaluation of privacy for generative trajectory models. Motivated by this gap, we implement Membership Inference Attacks against representative models, demonstrating the feasibility of using such empirical privacy evaluation methods and showing that their generative nature does not eliminate privacy risks.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。