用真实轨迹风格的扰动数据,让他人无法预测用户下一个打卡地点。
Ghost: Plausible Yet Unlearnable Trajectories via On-Manifold Substitution for Next-POI Privacy

- 基于轨迹流形约束生成看似自然的轨迹扰动
- 在多个攻击场景下实现低于0.15的恢复准确率
- 适合隐私保护需求强的位置数据发布场景
发布用户的签到轨迹会无意中暴露其未来位置的强预测信号。为应对这一风险,本文提出生成不可学习的轨迹——即经过扰动的序列,在干净测试输入上使目标模型的下一个兴趣点(next-POI)预测准确率显著下降。直接沿用图像领域的不可学习样本方法存在两个问题:一是公开数据需保持地理与语义上的合理性,二是扰动必须抵抗利用随机化防御结构的净化攻击者。本文提出 Ghost 框架,通过冻结的轨迹语言模型将每个替换操作引导至真实轨迹流形上,使去噪桥攻击者无法逆向还原,上下文无关的频率表攻击者仅能恢复接近均匀分布的结果。在两个标准基准和四种攻击姿态下,Ghost 的保护差距与最强确定性基线(PGD)相当,且在双数据集上对二元组自适应净化攻击者的恢复准确率最低,同时位于保护-抗净化能力平面上的 PGD 一倍单元标准差范围内。消融实验表明,流形先验取代了先前随机防御中的熵底限调节机制,即使20%的配对泄露,频率表攻击者的存活差距仍小于0.04。
原文摘要 · Abstract (English)
A publisher who releases check-in trajectories inadvertently publishes a strong predictor of every user's future locations. We address this risk by generating unlearnable trajectories, perturbed sequences that yield victim models with degraded next-Point-of-Interest (next-POI) accuracy on clean test inputs. Direct ports of image-domain unlearnable examples fail on two counts. The published data must remain geographically and semantically plausible, and the perturbation must resist purification adversaries that exploit the structure of randomized defences. We propose Ghost, a manifold-aligned framework whose perturbations look like plausible human check-in sequences yet leave no learnable signal behind. Ghost steers each substitution onto the real-trajectory manifold through a frozen trajectory language model, so a denoising-bridge adversary has nothing to invert and a context-free frequency-table adversary recovers a near-uniform distribution. Across two standard benchmarks, and four attacker postures, Ghost achieves protection-gap competitive with the strongest deterministic baseline (PGD) while attaining the lowest restored accuracy under the bigram adaptive purification adversary on both datasets, and lies within one per-cell standard deviation of PGD on the protection-versus-purification-resistance plane. Ablations confirm the manifold prior subsumes the entropy-floor knob of prior randomized defences, with the frequency-table adversary's survival gap remaining within 0.04 even when twenty percent of the pairs are leaked.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。