A Personalized Location Data Collection Method Based on Local Differential Privacy
By introducing the design of Φ-LAGI privacy model and linear planning model in local differential privacy technology, the excessive privacy protection problem under the personalized privacy budget of different locations is solved, and efficient privacy protection and minimize quality losses for personalized location data collection are achieved.
Patent Information
- Application Number
- CN202310058125.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-01-18
- Publication Date
- 2025-06-03
- Estimated Expiration
- 2043-01-18
AI Technical Summary
When existing local differential privacy technologies deal with personalized privacy budgets in different locations, it is difficult to achieve personalized privacy protection, resulting in excessive privacy protection for locations with large privacy budgets, resulting in unnecessary quality losses.
A personalized location data collection method based on local differential privacy is proposed. By defining the Φ-Location Aware Geo-Indistinguishability (Φ-LAGI) privacy model, each location has a personalized privacy budget, and designing the optimal perturbation mechanism by constructing a linear planning model to reduce quality loss.
In the personalized privacy budget scenario, the degree of privacy protection of each location depends only on the distance between the personalized privacy budget and other locations, reducing unnecessary quality losses, and effectively applying them to location services.
Smart Images

Figure CN116431744B_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the field of information security technology and relates to a personalized location data collection method based on local differential privacy. Background Art
[0002] In the big data era, the applications such as intelligent devices, mobile terminals and cloud computing have been gradually popularized, making the collection, storage, exchange, analysis and interpretation of massive data more common. At the same time, data security and personal privacy issues have become hot issues of common concern to people, and how to avoid leaking sensitive privacy information during data publishing and analysis has become the key.
[0003] Data privacy protection models are mainly divided into the following three categories: centralized, distributed and local privacy protection models. All of these three models play a certain role in privacy protection. However, the centralized privacy protection model requires a trusted third party, and the distributed privacy protection model has a large computational cost. While local differential privacy has high operation efficiency, strong portability and does not require a trusted center compared with other privacy protection technologies.
[0004] The core idea of the existing location privacy protection solutions is to make it difficult for attackers to infer users' sensitive information from the obtained information, which can be mainly divided into cryptography-based solutions, anonymity-based solutions and perturbation-based solutions. Local differential privacy is the application of differential privacy technology in the local scenario, which does not require a trusted third party. The user independently perturbs his own data locally and then submits it to the service provider. Local differential privacy has been widely studied at present and is used to estimate the distribution of privacy data and so on. Geometric indistinguishability is the application of local differential privacy in location protection. This definition combines the characteristics of location data, and the privacy level depends on the perturbation radius r. Since geometric indistinguishability can not only achieve the privacy protection effect, but also ensure the effectiveness of location information to a certain extent, it is used in many location privacy studies.
[0005] However, in real-world scenarios, the privacy levels at different locations may vary. For example, users have a relatively low willingness to protect the location information when they appear in public places such as shopping malls, while they have a strong willingness to protect the location information of places such as their home addresses and hospitals. Under the definitions of local differential privacy and geometric indistinguishability, the same privacy budget is used for all data. At this time, in order to meet the privacy protection requirements, the smallest privacy budget among them is selected to protect all data. For locations with a relatively large privacy budget, this is an excessive privacy protection and will cause unnecessary quality loss. Murakami et al. studied the situation of different data privacy protection requirements, classified the data into sensitive and non-sensitive categories, and proposed the concept of Utility-Optimized Local Differential Privacy (ULDP), which provides local differential privacy protection only for sensitive data. Summary of the Invention
[0006] Object of the Invention: The present invention provides a personalized location data collection method based on local differential privacy, extends local differential privacy to the scenario of location data collection with personalized privacy budgets, and provides a perturbation method for reducing quality loss, which can be effectively applied to location services.
[0007] To achieve the above object of the invention, the technical solutions provided by the present invention are as follows.
[0008] A personalized location data collection method based on local differential privacy, comprising the following steps:
[0009] S1. Set the input and output domains and personalized privacy budgets:
[0010] The input domain and the output domain are the same set of locations V = {v 1 , v 2 , …, v m}, where each location v has a personalized privacy budget ∈ v ≥ 0;
[0011] S2. Define a personalized location privacy protection model:
[0012] Each user needs to report their perturbed location data to the service provider. The protection of the real location data should meet the personalized privacy budget of that location. There are the following definitions:
[0013] If for any v, v' ∈ V, and any z ∈ V, the perturbation mechanism M satisfies the following inequality:
[0014]
[0015] Then \(M\) satisfies the privacy definition of \(\varPhi\)-Location Aware Geo-Indistinguishability (\(\varPhi\)-LAGI); where \(\varPhi=\in\). v} v∈V is the set of privacy budgets for all locations, \(\mu(\in\). v , \(\in\). v' ) is the smaller value between two privacy budgets, and \(d(v, v')\) is the distance between two locations;
[0016] For the location set \(V = \{v\). 1 , \(v\). 2 , \(\cdots\), \(v\). m}\), each location \(v\) has a personalized privacy budget \(\in\). v \(\geq0\), and the privacy protection requirements for different locations may vary; under the privacy definition \(\varPhi\)-LAGI, the probability ratio of any two input locations resulting in the same output after perturbation depends on the product of the smaller privacy budget among the two locations and the distance between them; \(\varPhi\)-LAGI does not use a unified privacy budget for all locations, and there are personalized privacy constraints between each pair of locations, providing stronger privacy protection for locations with smaller privacy budgets and weaker privacy protection for locations with larger privacy budgets, thus meeting the personalized location privacy protection requirements;
[0017] S3. Set the optimal perturbation mechanism:
[0018] Construct the following linear programming model to obtain the optimal solution of the objective function and the matrix \(M\):
[0019]
[0020]
[0021]
[0022]
[0023] In the objective function, \(\pi\). v represents the prior distribution of all locations, \(M\). vz represents the probability that the true location \(v\) outputs the location \(z\) through the perturbation mechanism \(M\), \(L\) is a standard for measuring quality loss, and \(L(v, z)\) represents the quality loss caused by the true location \(v\) outputting the location \(z\) through the perturbation mechanism. The prior distribution \(\pi\) reflects the frequency of users appearing at each location. For locations where users appear frequently, the quality loss after perturbation has a great impact on the data analysis results, while for locations where almost no users appear, the quality loss of the perturbation result can be almost ignored. Under the given prior distribution and quality loss metric, the quality loss caused by the perturbation mechanism \(M\) can be represented by the objective function, and the minimum value can be obtained by minimizing the objective function;
[0024] In the constraint conditions, the elements in the probability matrix M need to satisfy the following conditions: the ratio of any two elements in each column of the matrix should satisfy the definition of the Φ-LAGI privacy model; the sum of the elements in each row of the matrix is 1; each element in the matrix is greater than or equal to 0;
[0025] According to the objective function and the constraint conditions, the optimal solution of the objective function and the matrix M are obtained. The matrix M is the perturbation scheme for obtaining the optimal solution. The user perturbs his / her true location according to the probability of the matrix M and submits the result to the service provider;
[0026] S4. The user submits the location data perturbed in step S3 to the service provider, and the service provider analyzes and applies it to the location service.
[0027] Beneficial effects: Under the personalized privacy budget Φ-LAGI of the present invention, the service provider constructs a linear programming model according to the personalized privacy budget of the location data, and designs an optimal perturbation mechanism in combination with the prior distribution and the quality loss. The present invention ensures that in this model, the degree of privacy protection for each location only depends on the personalized privacy budget and the distance to other locations, and the data utility of the perturbation result of the present invention reaches the minimum quality loss. The present invention provides a personalized location data collection method based on local differential privacy, extends local differential privacy to the location data collection scenario with a personalized privacy budget, and provides a perturbation method for reducing quality loss, which can be effectively applied to location services. Brief Description of the Drawings
[0028] Figure 1 is the overall flowchart of the present invention;
[0029] Figure 2 is the privacy constraint diagram of the present invention. Detailed Embodiment
[0030] To illustrate in detail the technical solution disclosed by the present invention, the following further elaboration is made in combination with the specification drawings and specific examples.
[0031] First, in combination with the deficiency that personalized privacy protection cannot be achieved for location data in terms of geometric indistinguishability, the present invention defines a location privacy protection model in the personalized privacy scenario. Secondly, an optimal perturbation mechanism for achieving the minimum quality loss is designed according to the defined model. Using the method described in the present invention to collect location data can be used in applications based on location services.
[0032] In the method of the present invention, each user needs to report a two-dimensional coordinate to the service provider to represent their location information. Different locations have different privacy protection requirements. The service provider calculates the perturbation probability matrix in advance and sends it to the user. The user uses this perturbation probability matrix to perturb their true location locally and submits the perturbed result to the service provider. After the service provider collects the perturbed data of the users, it analyzes and statistically processes the data.
[0033] Specifically, in combination with Figure 1 , a personalized location data collection method based on local differential privacy is as follows:
[0034] (1) The steps that the service provider needs to perform are as follows:
[0035] (1.1) The location set V = {v 1 , v 2 , …, v m}, where each location v has a personalized privacy budget ∈ v ≥ 0. Without loss of generality, assume the location set V = {a, b, c, f}, and the specific information of each location is shown in Table 1.
[0036] Table 1 Location Information
[0037] Position Coordinate Privacy budget a (1,4) 0.6 b (5,4) 0.2 c (1,1) 0.4 f (5,1) 0.6
[0038] For the known location data, the service provider can obtain the privacy constraints between any two locations through calculation. As Figure 2 shown, the weight of any edge w(v, v') represents the privacy constraint μ(∈ v , ∈ v' ) d(v, v').
[0039] (1.2) According to the calculated weights, the service provider further combines the prior distribution and the quality loss metric to construct the following linear programming model:
[0040]
[0041]
[0042]
[0043]
[0044] According to the objective function and the constraint conditions, use the solver to obtain the optimal solution of the objective function and the matrix M. The matrix M is the perturbation probability matrix that makes the objective function take the minimum value.
[0045]
[0046] (1.3) The service provider sends matrix M to all users and waits for users to upload perturbed data for data analysis.
[0047] (2) The steps that users need to perform are as follows:
[0048] (2.1) Users obtain the perturbed probability matrix M sent by the service provider.
[0049] (2.2) Users perturb their true location v using M to obtain the perturbed result
[0050] (2.3) Users submit the perturbed result to the service provider.
[0051] Based on the above calculation and processing process, the experimental results of the present invention are as follows.
[0052] In the experiment, the T-Drive Taxi Trajectories dataset was used, which contains 17,662,885 instances. In the experiment, the data input domain was divided into 10 grids of the same size, and all locations used the central coordinates within their respective grids. The experiment set 6 privacy budget levels {0.2∈, 0.35∈, 0.5∈, 0.65∈, 0.8∈, 1.0∈}, and the corresponding distributions were {10%, 10%, 10%, 10%, 10%, 50%}, where ∈ takes values of 0.2, 0.4, 0.6, 0.8, 1.0, 1.2. In the experiment, the quality loss was used as the measurement criterion, and the quality loss between the true location and the perturbed location was finally obtained as shown in Table 2. According to the experimental results, as the privacy budget increases, the degree of protection decreases, and the quality loss caused by the perturbation mechanism also continuously shrinks and gradually approaches 0.
[0053] Table 2 Quality Loss
[0054] ∈ value range Quality loss ∈=0.2 0.25336892868308725 ∈=0.4 0.03885744873659411 ∈=0.6 0.004155577941174988 ∈=0.8 0.0009911844485948093 ∈=1.0 0.00010579072477770221 ∈=1.2 1.55768592778847e-05
[0055] Finally, it should be noted that the existing solutions for collecting location data cannot achieve personalized budgets for different locations. The present invention proposes a location privacy model Φ-LAGI in a personalized scenario, extending local differential privacy to the location data collection scenario with personalized privacy budgets. An optimal perturbation mechanism is further designed. The service provider constructs a linear programming model based on the personalized privacy budget of the location data, and designs and solves the perturbed probability matrix by combining the prior distribution and the quality loss. The present invention realizes that the degree of privacy protection for each location only depends on the personalized privacy budget and the distance to other locations, and the data utility of the perturbed result of the present invention reaches the minimum quality loss, which can be effectively applied to location services.
[0056] The above are only the preferred embodiments of the present invention and are not intended to limit the present invention. For those skilled in the art, the present invention may have various modifications and variations. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present invention shall be included within the protection scope of the present invention.
Claims
1. A personalized location data collection method based on local differential privacy, characterized in that, it includes the following steps: S1. Set the input and output domains and the personalized privacy budget: The input domain and the output domain are the same set of positions \(V = \{v 1 , v 2 , \ldots, v m \}\), where each position \(v\) has a personalized privacy budget \(\in v \geq0\); S2. Define the personalized location privacy protection model: Each user needs to report their perturbed location data to the service provider. The protection of the real location data should meet the personalized privacy budget of this location, which is defined as follows: If for any v, v′ ∈ V, and any z ∈ V, the perturbation mechanism M satisfies the following inequality: Then M satisfies the privacy definition of Φ-LAGI, where Φ = {∈ v} v∈V is the set of privacy budgets for all locations, μ(∈ v , ∈ v′ ) is the smaller value of the two privacy budgets, and d(v, v′) is the distance between two locations; S3. Set the optimal perturbation mechanism: Construct the following linear programming model to obtain the optimal solution of the objective function and the matrix M: Minimize: In the objective function, π v represents the prior distribution of all positions, and M vz represents the probability that the true position v outputs the position z through the perturbation mechanism M. L is a criterion for measuring the quality loss, and L(v, z) represents the quality loss caused by the true position v outputting the position z through the perturbation mechanism. Given the prior distribution and the quality loss metric, the quality loss caused by the perturbation mechanism M can be represented by the objective function, and the minimum value can be obtained by minimizing the objective function; In the constraint conditions, the elements in the probability matrix M need to meet the following conditions: the ratio of any two elements in each column of the matrix should meet the definition of the Φ-LAGI privacy model; the sum of the elements in each row of the matrix is 1; each element in the matrix is greater than or equal to 0; According to the objective function and the constraint conditions, obtain the optimal solution of the objective function and the matrix M. The matrix M is the perturbation scheme for obtaining the optimal solution. The user perturbs their real location according to the probability of the matrix M and submits the result to the service provider; S4. The user submits the location data perturbed in step S3 to the service provider, and the service provider analyzes and applies it to the location service.
2. The personalized location data collection method based on local differential privacy according to claim 1, characterized in that: In the personalized location privacy protection model defined in step S2, in the location set V = {v 1 , v 2 ,..., v m}, each location v has a personalized privacy budget ∈ v ≥0, and the privacy protection requirements for different locations can be the same or different.
3. The personalized location data collection method based on local differential privacy according to claim 2, characterized in that: Under the privacy definition Φ-LAGI, the probability ratio of any two input locations obtaining a certain same output after perturbation depends on the product of the smaller privacy budget among these two locations and the distance between them.
4. The personalized location data collection method based on local differential privacy according to claim 3, characterized in that: Φ-LAGI does not use a unified privacy budget for all locations. There are personalized privacy constraints between each pair of locations, which can provide stronger privacy protection for locations with smaller privacy budgets and weaker privacy protection for locations with larger privacy budgets, so as to meet the personalized location privacy protection requirements.
5. The personalized location data collection method based on local differential privacy according to claim 1, characterized in that: In step S3, a target function is set in the design of the perturbation mechanism considering the prior distribution of locations. By solving the perturbation probability matrix that minimizes the quality loss, where the prior distribution π reflects the frequency of the user appearing at each location and is positively correlated with the quality loss.
Citation Information
Patent Citations
Logistic regression matrix decomposition recommendation algorithm based on differential privacy
CN115221399A
Privacy protection method for sensitive data of carrier in intelligent logistics platform
CN115618402A