A data publishing method for location privacy protection facing third-party data requests
By setting the trajectory sales ratio and simulated annealing algorithm to select suppression points, and combining the service provider to sell some trajectory points, the rationality problem of suppressing location information in trajectory privacy protection is solved, and efficient privacy protection and data availability balance is achieved.
Patent Information
- Application Number
- CN202210008929.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-01-06
- Publication Date
- 2025-08-01
- Estimated Expiration
- 2042-01-06
AI Technical Summary
In the prior art, in the track privacy protection, how to reasonably suppress location information to balance data availability and privacy protection effect is an important issue. Too much suppression will lead to poor data availability, and too little suppression will lead to poor privacy protection effect.
By setting the trajectory sale ratio p, the trajectory estimate error covariance is calculated based on the posterior Kramero lower boundary, and the suppression points that maximize the estimation error are selected using a simulated annealing algorithm, and some trajectory points are sold in conjunction with the service provider to achieve privacy protection.
While ensuring data availability, it significantly improves the user's location privacy protection level and effectively prevents trajectory information from being abused by third parties.
Smart Images

Figure CN114386099B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of trajectory privacy protection, and specifically relates to a location privacy protection method based on differential privacy and trajectory suppression, which is applied to the problem of user action trajectory leakage in location-based services. Background Art
[0002] In recent years, with the popularization and application of location-based services (LBS) that revolve around geographical location data, cases of location privacy security have begun to occur frequently. This means that LBS services are a double-edged sword for users. Location-based services not only bring users convenient and efficient services, but also bring inevitable risks to the leakage of user location privacy.
[0003] Currently, the protection problems in the field of location privacy are mainly divided into two categories: single-point location privacy protection and trajectory privacy protection. When a user requests an LBS service, usually to protect location privacy, a pseudo-location is generated through the design of a single-point location privacy protection mechanism and uploaded to the service provider. When the user uploads pseudo-locations multiple times to obtain corresponding LBS services, the service provider will collect multiple pseudo-location points of this user, and based on spatio-temporal correlation, the trajectory information of this user can be obtained. And third-party units will purchase the trajectory data information of users from some service provider platforms, etc. for academic research or data exchange, and then conduct data analysis, statistics and mining. If the trajectory information of a user is purchased and collected by a malicious attacker, it will cause the leakage of the user's privacy information, and sensitive information such as the user's home address and workplace may be inferred by the attacker, thus threatening the user's security. And it is very difficult for users to ensure whether the service provider will sell their trajectory information to third-party data buyers for profit-making purposes. Trajectory privacy protection is achieved on the basis of single-point location privacy protection. The trajectory suppression method is a commonly used method, which protects the user's original trajectory by hiding sensitive location points and frequently visited location points in the trajectory, and reduces the risk of sensitive locations being identified.
[0004] However, when using the trajectory suppression method, how to reasonably suppress location information is an important problem currently faced. If too many location points are suppressed, the data availability will be poor; if too few location points are suppressed, the privacy protection effect will be poor, and it is easy to leak the user's privacy information. Summary of the Invention
[0005] The purpose of the present invention is to provide a data publishing method for location privacy protection for third-party data requests in view of the deficiencies of the prior art, authorize the service provider to sell some of the trajectory data uploaded by the user, and maximize the privacy protection intensity of the target by publishing the optimal user trajectory points to third-party data buyers.
[0006] The object of the present invention is achieved by the following technical solutions: A data publishing method for location privacy protection facing third-party data requests, comprising the following steps:
[0007] (1) The user sets the trajectory selling ratio p according to the requirements of the third party;
[0008] (2) Calculate the trajectory estimation error covariance with spatio-temporal correlation based on the Posterior Cramer-Rao Lower Bound (PCRLB), and use it as a measure of privacy protection strength;
[0009] (3) Select n - m suppression points with the largest estimation error covariance at the trajectory selling ratio p based on the simulated annealing algorithm;
[0010] (4) Determine the trajectory S sold by the service provider according to the selected suppression points b .
[0011] Further, the method for calculating the trajectory estimation error covariance with spatio-temporal correlation based on the posterior Cramer-Rao lower bound in step (2) specifically includes:
[0012] (2.1) Determine the objective function based on PCRLB, and its formula analysis is as follows:
[0013] f i (s) = Tr(PCRLB(s i )) i = 1,...,n (1)
[0014] Let the state of the user's true position point be where [x n ,y n T and respectively represent the position component and velocity component of the nth position point. The system state equation can be written as:
[0015] s n = Fs n-1 + v n (2)
[0016] where F is the state transition matrix, and v n is the process noise. Assuming that the user motion model is a uniform motion model, v n is Gaussian white noise with zero mean and covariance matrix Q, then
[0017]
[0018] where \(t\) is the time interval between adjacent position points in the user's trajectory, and \(q\) is the parameter of the process noise.
[0019] The observation equation for the user's uploaded position can be written as:
[0020] \(z\) n = A * s n + ω n (3)
[0021] where ω n is the noise that follows a Laplace distribution, and A is the observation matrix.
[0022] According to the Markov property of state transition, the joint probability distribution function can be expressed as:
[0023] \(p(S\) n+1 ,Z\) n+1 ) = \(p(S\) n ,Z\) n ) · \(p(s\) n+1 |s\) n ) · \(p(z\) n+1 |s\) n+1 )
[0024] where \(S\) n+1 = [s1, …, s n+1 T is the set of the user's \(n + 1\) true position points, and \(Z\) n+1 = [z1, …, z n+1 T is the set of the user's \(n + 1\) pseudo position points uploaded.
[0025] (2.2) The lower bound of the unbiased estimation variance of the user's \((n + 1)\)th position point has the following form:
[0026]
[0027] where \(J\) n+1 is the Fisher Information Matrix, and its recursive calculation method is:
[0028]
[0029] [[ID=7#]]where
[0030]
[0031] The initial Fisher information matrix \(J_0\) can be calculated from the prior probability density function \(p(S\) 0 ,Z\) 0 ), that is
[0032]
[0033] (2.3) According to the user state model, the observation model, and the Fisher information matrix, the following results can be calculated:
[0034]
[0035] Calculate iteratively as above, so as to calculate the lower bound of the unbiased estimation variance of each user's uploaded location.
[0036] In step (3) above, the method of selecting suppression points based on the simulated annealing algorithm is as follows:
[0037] (3.1) For the user, the goal is to select the location point with the relatively smallest total estimation error under a certain number as the selling point, that is, the estimation error of the suppression point is the largest, after setting the determined value of the trajectory selling ratio, and establish an optimization model:
[0038]
[0039] The objective function represents maximizing the estimated position error of the trajectory suppression point; the constraint condition is the constraint of the selling trajectory position point, indicating that the service provider sells the trajectory S b must be a partial position point sequence in the user-uploaded trajectory S p and is its subset, where S p represents the noisy path formed by the combination of the pseudo-position points uploaded by this user collected by the service provider, that is, S p ={z1,···,z n}, S b represents the local noisy path formed by the combination of partial pseudo-position points in the user-uploaded trajectory S p , that is, S b ={z′1,···,z′ m}, m ≤ n.
[0040] (3.2) Selecting the trajectory suppression point with the largest estimation error covariance is essentially similar to solving the location problem. Regarding the location problem, it can be analogized to the traveling salesman problem: starting from a certain city A among N cities, traversing the remaining N - 1 cities uniquely, and finally returning to city A, and making the path distance the minimum among all paths. It can be found that the essence of the problem of selecting the optimal selling trajectory point is the same as that of the traveling salesman problem.
[0041] The requirement of the traveling salesman is to select the path with the minimum path distance among all paths, while in the present invention, the service provider sells the trajectory S bThe requirement is to select m single-point positions with the minimum sum of estimated errors in the trajectory. The simulated annealing method is a commonly used optimization method for solving the traveling salesman problem. It accepts a solution worse than the current solution with a certain probability to jump out of the local optimal solution and obtain the global optimal solution. Therefore, the present invention selects the simulated annealing method as the optimization method to solve the objective function.
[0042] A data publishing method for location privacy protection facing third-party data requests proposed by the present invention has the following advantages compared with the prior art:
[0043] 1. The present invention calculates the trajectory estimation error covariance with spatio-temporal correlation through the posterior Cramer-Rao lower bound, combines the theoretical lower bound of the unbiased estimation error covariance derived from the prior information of the target state, and uses it as a measure of the trajectory privacy protection strength.
[0044] 2. By analogy with the traveling salesman problem, the present invention uses the simulated annealing algorithm to achieve optimization and selects the trajectory suppression points that maximize the estimation error covariance.
[0045] 3. The present invention authorizes the service provider to sell the trajectory data information uploaded by the user, and only sells the limited user trajectory points to the third-party data purchaser to ensure the security of the user's privacy information. BRIEF DESCRIPTION OF THE DRAWINGS
[0046] Figure 1 is the flowchart of the method of the present invention;
[0047] Figure 2 is the comparison chart of trajectory estimation errors under the given parameters of the present invention;
[0048] Figure 3 is the comparison chart of trajectory estimation errors under different trajectory selling ratios of the present invention, Figure 3 Part (a) of which is the comparison chart of the trajectory estimation errors sold by users under different service qualities of the present invention;
[0049] Figure 3 Part (b) of which is the comparison chart of the trajectory estimation errors sold by users under different privacy protections of the present invention. DETAILED DESCRIPTION OF THE INVENTION
[0050] The present invention will be further described in detail below with reference to the drawings and embodiments.
[0051] Refer to Figures 1 to 3 , a data publishing method for location privacy protection facing third-party data requests, including the following steps:
[0052] (1) The user sets the trajectory selling ratio p according to the requirements of the third party;
[0053] (2) Calculate the trajectory estimation error covariance with spatio-temporal correlation based on the posterior Cramér-Rao lower bound, and use it as a measure of privacy protection strength;
[0054] Calculating the trajectory estimation error covariance with spatio-temporal correlation based on the posterior Cramér-Rao lower bound specifically includes:
[0055] (2.1) Determine the objective function based on PCRLB, and its formula analysis is as follows:
[0056] f i (s) = Tr(PCRLB(s i )) i = 1,...,n (1)
[0057] Let the state of the user's true position point be where [x n ,y n T and represent the position component and velocity component of the nth position point respectively. The system state equation can be written as:
[0058] s n = Fs n-1 + v n (2)
[0059] where F is the state transition matrix and v n is the process noise. Assuming that the user motion model is a uniform motion model and v n is Gaussian white noise with zero mean and covariance matrix Q, then
[0060]
[0061] where t is the time interval between adjacent position points in the user's trajectory and q is the parameter of the process noise.
[0062] The observation equation of the user's uploaded position can be written as:
[0063] z n = A*s n + ω n (3)
[0064] where ω n is noise obeying the Laplace distribution, A is the observation matrix,
[0065] According to the Markov property of state transition, the joint probability distribution function can be expressed as:
[0066] p(S n+1 ,Z n+1 ) = p(S n ,Zn )·p(s n+1 |s n )·p(z n+1 |s n+1 )
[0067] Among them, S n+1 =[s1,…,s n+1 T is the set of n+1 true location points of the user, and Z n+1 =[z1,…,z n+1 T is the set of n+1 pseudo location points uploaded by the user.
[0068] (2.2) The lower bound of the unbiased estimation variance of the user's (n+1)-th location point has the following form:
[0069]
[0070] Among them, J n+1 is the Fisher Information Matrix, and its recursive calculation method is:
[0071]
[0072] Among them
[0073]
[0074] The initial Fisher information matrix J0 can be calculated from the prior probability density function p(S 0 ,Z 0 ), that is
[0075]
[0076] (2.3) According to the user state model, observation model and Fisher information matrix, the following results can be calculated:
[0077]
[0078] Calculate iteratively as above, so as to calculate the lower bound of the unbiased estimation variance of each location uploaded by the user.
[0079] (3) Select n-m suppression points with the largest estimated error covariance under the trajectory selling ratio p based on the simulated annealing algorithm;
[0080] Select suppression points based on the simulated annealing algorithm, specifically including:
[0081] (3.1) For users, their goal is to select the position point with the relatively smallest total estimation error under a certain quantity as the selling point after determining the set trajectory selling ratio value, that is, to suppress the largest point estimation error and establish an optimization model:
[0082]
[0083] The objective function represents maximizing the position error of the trajectory suppression point estimate; the constraint condition is the constraint of the selling trajectory position point, indicating that the service provider sells the trajectory S b must be a partial position point sequence in the user-uploaded trajectory S p and is its subset, where S p represents the noisy path formed by the combined pseudo-position points uploaded by this user collected by the service provider, that is, S p ={z1,···,z n}, S b represents the local noisy path formed by a partial combination of pseudo-position points in the user-uploaded trajectory S p that is, S b ={z′1,···,z′ m}, m ≤ n.
[0084] (3.2) Selecting the trajectory suppression point with the largest estimation error covariance is essentially similar to solving a location problem. Regarding the location problem, it can be analogized to the traveling salesman problem: starting from a certain city A among N cities, uniquely traversing the remaining N - 1 cities, and finally returning to city A, and making the path distance the minimum among all paths. It can be found that the essence of the problem of selecting the optimal selling trajectory point is the same as that of the traveling salesman problem.
[0085] The requirement of the traveling salesman is to select the path with the minimum path distance among all paths, while the requirement of the service provider selling the trajectory S b in the present invention is to select m single-point positions with a small total estimation error in the trajectory. The simulated annealing method is a commonly used optimization method for solving the traveling salesman problem, which accepts a solution worse than the current solution with a certain probability to achieve the purpose of jumping out of the local optimal solution and obtaining the global optimal solution. Therefore, the present invention selects the simulated annealing method as the optimization method to solve the objective function.
[0086] (4) Determine the trajectory S b sold by the service provider according to the selected suppression point.
[0087] Example: The Geolife GPS trajectory dataset is adopted. The GPS trajectories in this dataset are represented by a sequence of timestamp points, each of which contains latitude, longitude, and altitude information.
[0088] Figure 2It is a comparison chart of the trajectory estimation error under given parameters. Under the single-point location protection with the given parameter hidden service quality value d Q = 1500 m and the privacy protection value d P = 500 m, the optimal selling point trajectory of the present invention is compared with the selling point trajectory under a fixed frequency. It can be seen that under the same privacy budget, reducing the user's location reporting frequency can improve the user's privacy protection level, and from Figure 2 it can be seen that the optimal selling 10% trajectory error under this mechanism algorithm is higher than the fixed frequency selling 5% trajectory error. This shows that based on the single-point location privacy protection mechanism, this mechanism can not only meet the user's requirements for LBS service location privacy to a certain extent, but also effectively and personalized improve the user's location privacy protection level while facing third-party data publishing.
[0089] Figure 3 It is a comparison chart of the trajectory estimation error under different trajectory selling ratios. The influence of the user trajectory selling ratio on the user trajectory privacy protection level is analyzed on two data sets under different initial setting values. Figure 3 Part (a) of is a comparison chart of the user selling trajectory estimation error under different service qualities. In the figure, the experimental data results of five groups of bar charts are compared and analyzed respectively. The first to fifth group privacy protection setting values d P and service quality setting values d Q are respectively: the first group d P = 500, d Q = 1500, the second group d P = 500, d Q = 1650, the third group d P = 500, d Q = 1800, the fourth group d P = 500, d Q = 1950, and the fifth group d P = 500, d Q = 2100. When the trajectory selling ratio drops from 100% of the original trajectory to 10%, it can be seen that under the deployment of this mechanism, the trajectory estimation error of the user under each parameter value has been significantly improved, verifying the rationality of the algorithm of the present invention. Figure 3 Part (b) of is a comparison chart of the user selling trajectory estimation error under different privacy protections. Under the fixed service quality setting value d Q and different privacy protection setting values d P (d P = 300, d Q = 1500, d P = 400, d Q = 1500, and d P = 500, d QWhen the trajectory selling ratio decreases from 100% of the original trajectory to 10% under the condition of , it can be clearly seen that the trajectory estimation errors of users under each group of parameter values have increased significantly, which verifies the algorithm performance of this mechanism again, indicating that users can achieve the protection of location privacy security under the data publishing method for location privacy protection facing third-party data requests.
Claims
1. A data publishing method for location privacy protection facing third-party data requests, characterized in that Including the following steps; (1) The user sets the trajectory selling ratio p according to the requirements of a third party; (2) Calculate the trajectory estimation error covariance with spatio-temporal correlation based on the posterior Cramér-Rao lower bound, and use it as a measure of privacy protection strength; (3) Select n - m suppression points with the largest estimation error covariance at the trajectory selling ratio p based on the simulated annealing algorithm; (4) Determine the service provider's selling trajectory S based on the selected suppression points b ; The method for calculating the trajectory estimation error covariance with spatio-temporal correlation based on the posterior Cramér-Rao lower bound in step (2) specifically includes: (2.1) Determine the objective function based on PCRLB, and its formula analysis is as shown in (1): f i (s) = Tr(PCRLB(s i )) i = 1,..., n (1) Set the state of the user's true position point as where [x n , y n T and represent the position component and velocity component of the nth position point respectively; the user state equation is written as: s n = Fs n-1 + v n (2) where F is the state transition matrix, and v n is the process noise; assuming that the user motion model is a constant velocity motion model, v n is Gaussian white noise with zero mean and covariance matrix Q, then where t is the time interval between adjacent position points in the user's trajectory, and q is the parameter of the process noise; The observation equation of the user's uploaded position is written as: z n = A * s n + ω n (3) where ω n is noise following a Laplace distribution, and A is an observation matrix, According to the Markov property of state transition, the joint probability distribution function is expressed as: p(S n+1 ,Z n+1 ) = p(S n ,Z n ) · p(s n+1 |s n ) · p(z n+1 |s n+1 ) Among them, S n+1 = [s1, …, s n+1 T is the set of n + 1 real location points of the user, and Z n+1 = [z1, …, z n+1 T is the set of n + 1 pseudo-location points uploaded by the user; (2.2) The unbiased estimation variance lower bound of the user's (n + 1)-th position point has the following form: Where J n+1 is the Fisher Information Matrix, and its recursive calculation method is as follows: where The initial Fisher information matrix J0 is calculated from the prior probability density function p(S 0 ,Z 0 ), that is (2.3) Calculate the following results based on the user's state equation, observation equation, and Fisher information matrix: Calculate iteratively as above, so as to calculate the unbiased estimation variance lower bound of each user's uploaded position.
2. The data publishing method for location privacy protection for third-party data requests according to claim 1, characterized in that (3) The method for selecting suppression points based on the simulated annealing algorithm in step (3) specifically includes: (3.1) For the user, the goal is to select the position points with the relatively smallest total estimation error under a certain number after setting the determined value of the trajectory selling ratio as the selling points, that is, the suppression points have the largest estimation error, and establish an optimization model: The objective function represents maximizing the estimated position error of the trajectory suppression point; the constraint condition is the constraint of the sold trajectory position points, indicating that the service provider sells the trajectory S b must be a partial position point sequence in the user-uploaded trajectory S p and is a subset of it, where S p represents the noisy path formed by the combination of the pseudo-position points uploaded by the user collected by the service provider, that is, S p ={z1,···,z n}, S b represents the local noisy path formed by the combination of partial pseudo-position points in the user-uploaded trajectory S p and is, that is, S b ={z1′,···,z′ m}, m ≤ n; (3.2) Selecting the trajectory suppression points with the largest estimation error covariance is essentially similar to solving the site selection problem; Select the simulated annealing method as the optimization method to solve the objective function.
Citation Information
Patent Citations
System and method for track restraining data publishing privacy protection based on frequency
CN103914659A
Quantification of privacy risk in location trajectories
US20210019425A1