A location protection method based on a dynamic privacy budget mechanism
Patent Information
- Application Number
- CN202310849279.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-07-11
- Publication Date
- 2026-09-22
- Estimated Expiration
- 2043-07-11
AI Technical Summary
[0003]本发明要解决的技术问题是针对上述现有技术的不足,提供一种基于动态隐私预算机制的位置保护方法A Location Protection Method Based on Dynamic PrivacyBudget Mechanism,即LP-DPBM,其目的是为解决非敏感区域中的位置点存在重要语义信息导致隐私泄露以及发布数据可用性低等问题
与现有技术相比,本发明方法提出将待保护位置点的语义信息融入动态打分函数的方法,根据用户提供的待保护位置点的重要系数的不同,可以对待保护位置点提供不同程度的位置隐私保护;本发明方法通过构建动态打分函数来判断待保护位置点的敏感程度,缩短了对待保护位置点进行隐私保护所耗费的时间,与现有方法相比,对单个待保护位置点进行隐私保护所耗费的时间可节省0.04-0.82秒,有效提高了发布数据可用性。
Smart Images

Figure CN116761165B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the fields of computers and communications, and more specifically to a location protection method based on a dynamic privacy budget mechanism. Background Technology
[0002] With the continuous development of mobile communication and BeiDou navigation and positioning technologies, location-based services (LBS) devices are emerging in large numbers, such as in-vehicle navigation systems, BeiDou smartphones, and smartwatches. LBS is constantly changing people's lifestyles, bringing great convenience, but also introducing new security risks—location privacy leaks. Currently, the main methods for location privacy protection include fake location methods, suppression methods, generalization methods, and differential privacy methods. Differential privacy is widely used in the field of privacy protection because it does not concern itself with the attacker's background knowledge and does not require special attack assumptions. Traditional differential privacy methods, such as indiscriminate random noise addition, achieve privacy protection by adding perturbations that conform to differential privacy to location points. This method easily leads to insufficient protection of important location points and low availability of subsequently published data. Consequently, differential privacy methods based on clustering or geographical indistinguishability have emerged, such as the k-menas method and the KD-Tree method. The k-menas method first clusters the user's historical location points, then calculates and publishes the cluster center point of the location point to be protected, in order to achieve privacy protection for the location point to be protected; the KD-Tree method uses differential privacy based on the kd-tree data structure to protect location privacy. Although it improves the availability of published data, it does not disturb location information, and both methods ignore the problem of insufficient privacy protection caused by the semantic information of location points in non-sensitive areas, and there is still a risk of privacy leakage. Summary of the Invention
[0003] The technical problem to be solved by the present invention is to address the shortcomings of the prior art by providing a location protection method based on dynamic privacy budget mechanism, namely LP-DPBM. Its purpose is to solve the problems of privacy leakage caused by the presence of important semantic information in location points in non-sensitive areas and the low availability of published data.
[0004] To solve the above-mentioned technical problems, the technical solution adopted by the present invention includes the following process: Step 1: Divide the area based on the user's historical location information to determine the area block where the location point to be protected is located; Step 2: Determine whether the area block containing the location point to be protected is a sensitive area, and construct different dynamic scoring functions for the location point to be protected based on the determination result; Step 3: Based on the normalized probability output of the location to be protected according to the dynamic scoring function of the location to be protected, determine the sensitivity of the location to be protected, and construct a dynamic privacy budget allocation function for the location to be protected according to the sensitivity. Step 4: Add perturbations to the latitude and longitude data of the locations to be protected according to the allocated privacy budget, and then publish the perturbated latitude and longitude data of the locations to be protected.
[0005] Furthermore, step 1 includes: Step 1.1: Obtain the user's historical location information, including the longitude, latitude, date, and time of the historical location points, and construct a historical location dataset. ; Step 1.2: Query the maximum longitude in the historical location dataset. Minimum longitude Maximum latitude Minimum latitude And calculate the corresponding longitude difference. and latitude difference ; Step 1.3: Based on the size of the divided area blocks and formula (3), calculate the maximum longitude in the historical location dataset. Minimum longitude Maximum latitude Minimum latitude Update the system, and update the corresponding longitude difference as well. and latitude difference ; (3) in, The length of the divided region block; The width of the divided region block; This represents the distance between two points on the same meridian that differ by 1°. This represents the distance between two points on the same latitude circle that differ by 1°. Step 1.4: Divide the region bounded by the updated maximum longitude, minimum longitude, maximum latitude, and minimum latitude from Step 1.3 to generate... Each region block uses a matrix. Store the number of historical location points contained in each region block; (5) in, Represents a region block The number of historical location points included; Furthermore, step 2 includes: Step 2.1: Determine the threshold based on the sensitive area Determine whether the area block containing the location point to be protected is a sensitive area; (7) in, The region block containing the longitude of the location to be protected is in the matrix. The corresponding row in the middle; The region block containing the latitude of the location to be protected in the matrix The corresponding column; The longitude of the location to be protected; The latitude of the location to be protected; It is the floor function; This represents the number of historical location points within the block containing the location point to be protected. This represents the maximum number of historical location points within the block containing the location point to be protected. Number of empty regions; Step 2.2: Based on whether the area block containing the location to be protected is a sensitive area, construct a dynamic scoring function for the location to be protected. If the area block where the location point to be protected is located is a sensitive area, proceed to step 2.2.1; if the area block where the location point to be protected is located is a non-sensitive area, proceed to step 2.2.2. Step 2.2.1: When the location to be protected... When the area block is a sensitive area, determine the coordinates of the center point within that area block. A dynamic region scoring function is constructed by using the distance from the protected location point to the center point as the criterion for judging the sensitivity of the protected location point. And construct a dynamic position scoring function. As a dynamic scoring function for the location points to be protected; Step 2.2.2: When the location to be protected... When the area block is a non-sensitive area, the geographic semantic information corresponding to the location points in the historical location dataset is obtained and stored in the semantic dictionary. S In this process, the importance of the location points to be protected is determined, and a dynamic semantic scoring function is constructed as the dynamic scoring function for the location points to be protected. Step 2.3: Process the historical location dataset Semantic dictionary S ,matrix and the coordinates of the center point of the area block where the location to be protected is located. Update; Furthermore, the method for determining whether the area block containing the location point to be protected is a sensitive area in step 2.1 is as follows: If , And the area block where the location to be protected is located. Number of historical location points within If the condition is met, the area block where the location to be protected is located is determined to be a sensitive area; otherwise, the area block where the location to be protected is located is determined to be a non-sensitive area. Furthermore, the construction of the dynamic region scoring function in step 2.2.1... and dynamic position scoring function The method is as follows: based on the coordinates of the center point within the area block where the location to be protected is located. Determine the maximum Euclidean distance from all points within the region to the center point. and minimum Euclidean distance The Euclidean distance from the location to be protected to the center of the block is calculated according to formula (10), and a dynamic area scoring function is constructed according to formula (11). A dynamic position scoring function is constructed based on formula (12). ; (10) (11) (12) in, The Euclidean distance from the location point to be protected to the center point of its block area; It is the Euclidean distance function; Furthermore, the method for constructing the dynamic semantic scoring function in step 2.2.2 is as follows: by calling the data from the reverse geospatial service engine to perform reverse geocoding, the semantic information corresponding to historical location points in the historical location dataset is obtained and stored in the semantic dictionary. S In the same way, the semantic information of the location point to be protected is obtained, and it is determined whether the semantic information corresponding to the location point to be protected appears in the semantic dictionary. S If not, the user shall provide the importance coefficient of the location to be protected based on its importance to the user. Alternatively, settings can be manually configured based on the semantic information of the locations to be protected. If it exists, the access frequency of the location to be protected is calculated according to formula (13). Combined with user-provided The importance of the location to be protected is calculated according to formula (14). Thus, the amount of information contained in the location point to be protected is determined according to formula (15). Therefore, formula (16) is constructed as a dynamic semantic scoring function. ; (13) (14) (15) (16) in, Importance coefficient of the location point to be protected The weight, Access frequency of the location to be protected The weight, , , ; The number of visits to the location to be protected; This represents the number of historical location points in the historical location dataset. Semantic information of the location points to be protected; Furthermore, step 3 includes: Step 3.1: Calculate the output probability of the protected location point based on the exponential mechanism and the dynamic scoring function of the location point to be protected. Furthermore, the output probability is normalized. Step 3.2: Based on the varying sensitivity of the locations to be protected, construct a dynamic privacy budget allocation function, and set the total privacy budget allocated in the dynamic privacy budget allocation function to be... When the location to be protected If the area block is a sensitive area, proceed to step 3.2.1; otherwise, proceed to step 3.2.2. Step 3.2.1: When the location to be protected... When the area block is a sensitive area, the dynamic area scoring function is applied. Determine the sensitivity of the location points to be protected, and construct a dynamic privacy budget allocation function for the location points to be protected in the sensitive area; Step 3.2.2: When the location to be protected... When the area block is a non-sensitive area, the output probability of the location to be protected is used as the basis. Determine the sensitivity of the location points to be protected, and construct a dynamic privacy budget allocation function for the location points to be protected in non-sensitive areas; Furthermore, the method for constructing the dynamic privacy budget allocation function for the protected location points in the sensitive area in step 3.2.1 is as follows: the maximum value of the dynamic area scoring function is calculated using formula (18). Minimum value of the dynamic region scoring function When the dynamic region scoring function satisfy At the same time, construct a dynamic privacy budget allocation function for the locations to be protected in sensitive areas. As shown in formula (19); if or Construct a dynamic privacy budget allocation function for protected locations in sensitive areas. As shown in formula (20); (18) (19) (20) in, Location points to be protected Allocated privacy budget; Furthermore, the method for constructing the dynamic privacy budget allocation function for the protected location points in the non-sensitive area in step 3.2.2 is as follows: the importance threshold of the protected location points in the non-sensitive area is calculated using formula (21). The sensitivity of the protected location is determined based on its output probability. Construct a dynamic privacy budget allocation function for protected location points in non-sensitive areas. As shown in formula (22); if the output probability of the location to be protected is... Construct a dynamic privacy budget allocation function for protected location points in non-sensitive areas. As shown in formula (23); (twenty one) (twenty two) (twenty three).
[0006] The beneficial effects of adopting the above technical solution are as follows: Compared with existing technologies, the present invention proposes a method to integrate the semantic information of the location point to be protected into a dynamic scoring function. Based on the different importance coefficients of the location point to be protected provided by the user, different levels of location privacy protection can be provided for the location point to be protected. The present invention's method determines the sensitivity of the location point to be protected by constructing a dynamic scoring function, which shortens the time spent on privacy protection of the location point to be protected. Compared with existing methods, the time spent on privacy protection of a single location point to be protected can be reduced by 0.04-0.82 seconds, effectively improving the availability of published data.
[0007] The method of this invention can be applied to location privacy protection in anonymous servers and discrete request query services, and is especially suitable for LBS request services with low access frequency of location points but important semantic information. Attached Figure Description
[0008] Figure 1 This embodiment of the location protection method using a dynamic privacy budget mechanism is illustrated in the following flowchart; Figure 2 This embodiment is a schematic diagram showing the location point to be protected in a sensitive area; Figure 3 This embodiment presents a comparison chart of data availability for different datasets, where Figure (a) is a comparison chart of data availability for the Geolife dataset; and Figure (b) is a comparison chart of data availability for the T-Drive dataset. Detailed Implementation
[0009] The specific embodiments of the present invention will be described in further detail below with reference to the accompanying drawings and embodiments. These embodiments are used to illustrate the present invention, but are not intended to limit the scope of the invention.
[0010] The core idea of this invention is as follows: First, the region is divided based on the user's historical location information. Then, it is determined whether the region block where the location point to be protected is located is a sensitive region. If it is a sensitive region, a dynamic distance scoring function is constructed as the basis for judging the sensitivity of the location point to be protected; otherwise, a dynamic semantic scoring function is constructed as the basis for judging the sensitivity of the location point to be protected. Second, the probability output of the location point to be protected is normalized based on the exponential mechanism. Then, a dynamic privacy budget allocation function is constructed according to the different regions where the location point to be protected is located. Finally, the location point is noisily added before publication using the Laplace mechanism to disrupt the real location information and achieve the purpose of location data privacy protection. This method can effectively improve the availability of published data, solve the problem of privacy leakage caused by semantic information in non-sensitive areas, and meet the user's privacy protection needs.
[0011] In this embodiment, such as Figure 1 As shown, the specific steps of a location protection method based on a dynamic privacy budget mechanism include: Step 1: Divide the area based on the user's historical location information to determine the area block where the location point to be protected is located; Step 1.1: Obtain the user's historical location information, including the longitude, latitude, date, and time of the historical location points, and construct a historical location dataset. ; In this embodiment, for those with For each user with a historical location, their historical location information is collected to construct a historical location dataset. U Represented as ,in, Indicates the first A dataset of location points, ;No. The dataset of location points includes longitude. ,latitude ,date And detailed time information ,Right now ; Step 1.2: Query the maximum longitude in the historical location dataset. Minimum longitude Maximum latitude Minimum latitude And calculate the corresponding longitude difference. and latitude difference ; In this implementation, the historical location dataset is queried. U Central Longitude Minimum longitude Maximum latitude Minimum latitude ,in, , It is a function with maximum value. It is a minimum value function; the corresponding longitude difference is calculated using formula (1). and latitude difference : (1) Step 1.3: Based on the size of the divided area blocks and formula (3), calculate the maximum longitude in the historical location dataset. Minimum longitude Maximum latitude Minimum latitude Update the system, and update the corresponding longitude difference as well. and latitude difference ; In this embodiment, the length of the divided region block is set to be... Width The size of the structure is The region blocks; since edge location points may be lost during the region division process, causing some interference to subsequent work, the unit conversion formula (2) of latitude and longitude to meters is used to update the maximum longitude, minimum longitude, maximum latitude and minimum latitude in the historical location dataset, as shown in formula (3): (2) (3) in, This represents the distance between two points on the same meridian that differ by 1°. The radius of the Earth; This represents the distance between two points on the same latitude circle that differ by 1°. This refers to the latitude corresponding to the same latitude circle; The updated maximum longitude, minimum longitude, maximum latitude, and minimum latitude are used to calculate the longitude difference using formula (1). and latitude difference Update; Step 1.4: Divide the region bounded by the updated maximum longitude, minimum longitude, maximum latitude, and minimum latitude from Step 1.3 to generate... Each region block uses a matrix. Store the number of historical location points contained in each region block; In this embodiment, the region bounded by the updated maximum longitude, minimum longitude, maximum latitude, and minimum latitude from step 1.3 is divided into regional blocks using formula (4) to generate... Each region block uses a matrix. Stores the number of historical location points contained in each region block in a matrix. As shown in formula (5): (4) (5) in, t This indicates the number of regions divided within the latitudinal range covered by the updated historical location dataset; n This indicates the number of regions divided within the longitude range covered by the updated historical location dataset; Represents a region block The number of historical location points included.
[0012] Step 2: Determine whether the area block containing the location point to be protected is a sensitive area, and construct different dynamic scoring functions for the location point to be protected based on the determination result; Step 2.1: Determine the threshold based on the sensitive area Determine whether the area block containing the location point to be protected is a sensitive area; The location point to be protected is represented as... The location to be protected is calculated using formula (6). The area block it is located in is Formula (7) is constructed to determine the decision threshold for sensitive areas. T ; (6) (7) in, The region block containing the longitude of the location to be protected is in the matrix. The corresponding row in the middle; The region block containing the latitude of the location to be protected in the matrix The corresponding column; The longitude of the location to be protected; The dimension of the location point to be protected; It is the floor function; This represents the number of historical location points within the block containing the location point to be protected. This represents the maximum number of historical location points within the block containing the location point to be protected. Number of empty regions; like , And the area block where the location to be protected is located. Number of historical location points within If the condition is met, the area block where the location to be protected is located is determined to be a sensitive area; otherwise, the area block where the location to be protected is located is determined to be a non-sensitive area. Step 2.2: Based on whether the area block containing the location to be protected is a sensitive area, construct a dynamic scoring function for the location to be protected. If the area block where the location point to be protected is located is a sensitive area, proceed to step 2.2.1; if the area block where the location point to be protected is located is a non-sensitive area, proceed to step 2.2.2. Step 2.2.1: When the location to be protected... When the area block is a sensitive area, determine the coordinates of the center point within that area block. A dynamic region scoring function is constructed by using the distance from the protected location point to the center point as the criterion for judging the sensitivity of the protected location point. And construct a dynamic position scoring function. As a dynamic scoring function for the location points to be protected; In this embodiment, if the region block The set of location points is The number of historical location points within the region is ,in If the area containing the location to be protected is determined to be a sensitive area, then the distance from the location to be protected to the center point is used as the criterion for judging the sensitivity of the location to be protected, and a dynamic area scoring function is constructed; for example... Figure 2 As shown, when At this time , The number of historical location points in this region block ; The coordinates of the center point within the region are calculated using formula (8) based on the historical location points within the region. The Euclidean distance from all points within the region to the center point is calculated using formula (9), and the maximum Euclidean distance is determined. and minimum Euclidean distance : (8) (9) in, The coordinates of the center point of the historical location within the region block; Location point in the region block k Position coordinates; It is the Euclidean distance function; The location to be protected is calculated using formula (10). To the center point of the block Euclidean distance A dynamic region scoring function is constructed based on formula (11). A dynamic position scoring function is constructed based on formula (12). ; (10) (11) (12) Step 2.2.2: When the location to be protected... When the area block is a non-sensitive area, the geographic semantic information corresponding to the location points in the historical location dataset is obtained and stored in the semantic dictionary. S In this process, the importance of the location points to be protected is determined, and a dynamic semantic scoring function is constructed as the dynamic scoring function for the location points to be protected. To prevent situations where individual location points appear infrequently in the historical location dataset but possess relatively important semantic information, a method is proposed to incorporate the semantic information of historical location points into the historical location dataset, such as "school" or "shopping mall". This is because the historical location dataset constructed in step 1.1... U The dataset does not contain semantic information about historical location points. Therefore, by calling the data from the reverse geospatial service engine to perform reverse geocoding, the semantic information corresponding to historical location points in the historical location dataset is obtained and stored in the semantic dictionary. S In this embodiment, reverse geocoding is performed by calling the Gaode Map API interface to obtain the semantic information corresponding to historical location points in the historical location dataset, and then stored in the semantic dictionary. S middle; Since users may arrive at locations not in the historical location dataset during their movement, it's impossible to query the user's protected location in this situation, meaning it's impossible to obtain the frequency of the protected location appearing in the historical location dataset. Therefore, it's necessary to determine whether the protected location appears in the semantic dictionary. S In the same way, the semantic information of the location point to be protected is obtained. If the location point to be protected is not in the semantic dictionary S, the user provides the importance coefficient of the location point based on its importance to the user. Alternatively, settings can be manually configured based on the semantic information of the locations to be protected. The higher the importance of the location point to be protected to the user, the better. exist The larger the value of the innermost element, the worse it is. exist The smaller the value, the better; if the location point to be protected exists in the semantic dictionary S, then the access frequency of the location point to be protected is calculated according to formula (13). Combined with user-provided The importance of the location to be protected is calculated according to formula (14). ; (13) (14) in, Importance coefficient of the location point to be protected The weight, Access frequency of the location to be protected The weight, , , ; The number of visits to the location to be protected; N This represents the number of historical location points in the historical location dataset. Semantic information of the location points to be protected; The information content of the location point to be protected is calculated using formula (15). Formula (16) is constructed as a dynamic semantic scoring function based on the user's location preference needs, that is, the importance of the location to the user. ; (15) (16) Step 2.3: Process the historical location dataset Semantic dictionary S ,matrix and the coordinates of the center point of the area block where the location to be protected is located. Update; In this embodiment, historical location dataset The update method involves adding the location information of the location to be protected to the historical location dataset. The data includes the longitude, latitude, date, and time information of the location to be protected; a semantic dictionary. S The update method involves calling the data from the reverse geospatial service engine for reverse geocoding, specifically by calling the Gaode Map API interface to perform reverse geocoding, obtaining the geographic semantic information corresponding to the location point to be protected, and adding it to the semantic dictionary. S In the middle; update the partition matrixP The method involves incrementing the number of location points in the block containing the location point to be protected by one; and updating the coordinates of the center point of the block containing the location point to be protected. The method is based on the updated historical location dataset. and partition matrix P Calculate the coordinates of the center point of the area block containing the location to be protected. .
[0013] Step 3: Based on the normalized probability output of the location to be protected according to the dynamic scoring function of the location to be protected, determine the sensitivity of the location to be protected, and construct a dynamic privacy budget allocation function for the location to be protected according to the sensitivity. Step 3.1: Calculate the output probability of the protected location point based on the exponential mechanism and the dynamic scoring function of the location point to be protected. Furthermore, the output probability is normalized. In this embodiment, a dynamic scoring function is calculated based on the properties of the index mechanism. The sensitivity is The privacy budget allocated in the index mechanism is set as follows: The exponential mechanism is used to output the probability of the location point to be protected, and the output probability is normalized as shown in formula (17); where the dynamic scoring function The larger the value, the higher the output probability, indicating that the protected location point contains more information; (17) in, The output probability of the location point to be protected; This is a dynamic scoring function for the location point to be protected. When the location point to be protected is located in a sensitive area, When the location to be protected is located in a non-sensitive area, ; Location point within the block containing the location point to be protected The dynamic scoring function; During this process, the true latitude and longitude information of the location points to be protected is not disturbed. Directly publishing the data at this point would seriously lead to the leakage of user privacy. Therefore, this implementation method uses the Laplace mechanism to add noise to the location data, disturbing its true latitude and longitude, thereby achieving the purpose of location privacy protection. Since the sensitivity of the location points to be protected varies, a dynamic privacy budget allocation function is constructed before adding the perturbation.
[0014] Step 3.2: Based on the varying sensitivity of the locations to be protected, construct a dynamic privacy budget allocation function, and set the total privacy budget allocated in the dynamic privacy budget allocation function to be... When the location to be protected If the area block is a sensitive area, proceed to step 3.2.1; otherwise, proceed to step 3.2.2. Step 3.2.1: When the location to be protected... When the area block is a sensitive area, the dynamic area scoring function is applied. Determine the sensitivity of the location points to be protected, and construct a dynamic privacy budget allocation function for the location points to be protected in the sensitive area; The sensitivity of the location to be protected is determined by the dynamic area scoring function of the location to be protected, and the maximum value of the dynamic area scoring function is calculated by formula (18). Minimum value of dynamic region scoring function When the dynamic region scoring function satisfy At times, such as Figure 2 As shown in the central region of the concentric circles, a dynamic privacy budget allocation function is constructed for the protected location points in the sensitive region. As shown in formula (19); when or At times, such as Figure 2 As shown in the diagram excluding the concentric circles, a dynamic privacy budget allocation function is constructed for the protected location points within the sensitive region. As shown in formula (20); (18) (19) (20) in, Location points to be protected Allocated privacy budget; Step 3.2.2: When the location to be protected... When the area block is a non-sensitive area, the output probability of the location to be protected is used as the basis. Determine the sensitivity of the location points to be protected, and construct a dynamic privacy budget allocation function for the location points to be protected in non-sensitive areas; The importance threshold of the protected location points in the non-sensitive area is calculated using formula (21). The sensitivity of the protected location is determined based on its output probability. Construct a dynamic privacy budget allocation function for protected location points in non-sensitive areas. As shown in formula (22); if the output probability of the location to be protected is... Construct a dynamic privacy budget allocation function for protected location points in non-sensitive areas. As shown in formula (23); (twenty one) (twenty two) (twenty three) Step 4: Add perturbations to the latitude and longitude data of the locations to be protected according to the allocated privacy budget, and then publish the perturbated latitude and longitude data of the locations to be protected. In this embodiment, the Laplace mechanism is used to add noise to the latitude and longitude data of the location to be protected, and a Laplace perturbation is added to the latitude and longitude data of the location to be protected according to the allocated privacy budget; as shown in formula (24), the perturbed latitude and longitude of the location to be protected is... Release data: (twenty four) Where Y represents the perturbation information added to the latitude and longitude data of the location point to be protected; It follows a Laplace distribution; For global sensitivity; This indicates that the data with added perturbation follows a Laplace distribution; By perturbing the location points using the Laplace mechanism, the user's location information is disrupted, thereby achieving the goal of protecting the user's location privacy.
[0015] To verify the technical effectiveness of the method of the present invention, the following tests were conducted on this embodiment: LP-DPBM simulation experiments were conducted on a Windows 11 operating system with an Intel(R) Xeon(R) Gold 6226R CPU @ 2.90GHz and 2.89GHz processor. The experimental code was written in Python 3.9 and run on PyCharm. The simulation experiments were conducted on the Geolife Trajectory and T-Drive datasets. The Geolife Trajectory dataset contains 24,876,978 location data points from 182 users from April 2007 to August 2012, and the T-Drive dataset contains GPS data from 10,357 taxis in Beijing from February 2nd to February 8th, 2008. The following sections will test the privacy protection and data availability aspects of LP-DPBM.
[0016] (1) Degree of privacy protection To verify the protection of important semantic information of location points in non-sensitive areas, test analysis was conducted. A location point to be protected was selected. The size of the divided area is 1000. Furthermore, the area block containing the location to be protected is a non-sensitive area block. The number of historical location points in the region block is 0, and semantic privacy is used as the criterion for judging the sensitivity of the location point to be protected; the root mean square error is used as the criterion. As a basis for judging the degree of privacy protection, The larger the value, the more disruptive information is added, and the higher the level of privacy protection; conversely, a smaller value indicates a higher level of privacy protection. The smaller the value, the less disruptive information is added, and the lower the level of privacy protection; its formula is shown in (25). This is the actual location information. To add perturbation to the location information.
[0017] (25) Provide semantic importance coefficients for the locations to be protected. The privacy budgets are 0.01, 0.1, 0.2, 0.3, 0.4, 0.5, 0.6, 0.7, 0.8, 0.9, and 1, respectively. as well as Since only one non-sensitive location point is selected for protection, the privacy protection level of the k-means and KD-Tree algorithms is the same as that of RandomNoise with indiscriminate random noise. Therefore, LP-DPBM and RandomNoise with indiscriminate random noise are compared and analyzed. The comparison results are shown in Table 1.
[0018] Table 1. LD-DPBM and RandomNoise in Non-Sensitive Areas contrast
[0019] As shown in Table 1, the proposed LP-DPBM method can be based on The size is perturbed to varying degrees. and At that time, with The increase It also continues to increase, meaning the level of privacy protection increases with... It gradually increases with the increase of [something]. Since indiscriminate random noise addition does not consider the semantic information of the location point to be protected, therefore... and The changes are unrelated, meaning the level of privacy protection is unrelated to... It is irrelevant. Therefore, the proposed LP-DPBM method can effectively solve the problem of privacy leakage caused by the semantic information of location points in non-sensitive areas.
[0020] (2) Usability Analysis To verify the usability of the data published by the proposed method, relative error was used for testing and analysis, and the relative error is shown in formula (27). From the definition of relative error, it can be seen that... The smaller the value, the closer the query results after the data is published are to the actual query results, and the better the data usability; conversely, The larger the value, the more the published data query results deviate from the actual query results, and the lower the data availability.
[0021] (26) (27) in, RE The error between the original data and the processed data; For the range of queries; The query results are processed with algorithm protection. This represents unprotected query results; η is the parameter threshold, let... This is mainly to avoid the possibility of the denominator being zero; This represents the total number of historical location points in the historical location dataset.
[0022] The relative error of the LP-DPBM method is compared with that of KD-Tree, k-means, and traditional differential privacy algorithms in terms of privacy budget. , , , , , A comparative analysis was conducted. The selected query range was the entire region. 20% of The relative error comparison chart using different datasets is shown below. Figure 3 As shown.
[0023] Depend on Figure 3 As can be seen, the simulation results obtained on both datasets demonstrate that the LP-DPBM method proposed in this invention, with respect to privacy budget, exhibits positive results. The increase, The noise gradually decreases, and it is similar to indiscriminate random noise addition methods and k-means methods. Lower by 0.054-1.223; compared with the KDTree method, The value can be as low as 0.052-0.731. Therefore, the proposed LP-DPBM method has higher data availability after data release.
[0024] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, and not to limit them; although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some or all of the technical features therein; therefore, these modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the scope defined by the claims of the present invention.
Claims
1. A location protection method based on a dynamic privacy budget mechanism, characterized in that, The steps include the following: Step 1: Divide the area based on the user's historical location information to determine the area block where the location point to be protected is located; Step 2: Determine whether the area block containing the location point to be protected is a sensitive area, and construct different dynamic scoring functions for the location point to be protected based on the determination result; Step 2.1: Determine the threshold based on the sensitive area Determine whether the area block containing the location point to be protected is a sensitive area; (7); in, The region block containing the longitude of the location to be protected is in the matrix. The corresponding row in the middle; The region block containing the latitude of the location to be protected in the matrix The corresponding column; The longitude of the location to be protected; The latitude of the location to be protected; It is the floor function; This represents the number of historical location points within the block containing the location point to be protected. This represents the maximum number of historical location points within the block containing the location point to be protected. Number of empty regions; This indicates the number of regions divided within the latitudinal range covered by the updated historical location dataset; This indicates the number of regions divided within the longitude range covered by the updated historical location dataset; Step 2.2: Based on whether the area block containing the location to be protected is a sensitive area, construct a dynamic scoring function for the location to be protected. If the area block where the location point to be protected is located is a sensitive area, proceed to step 2.2.1; if the area block where the location point to be protected is located is a non-sensitive area, proceed to step 2.2.
2. Step 2.2.1: When the location to be protected... When the area block is a sensitive area, determine the coordinates of the center point within that area block. A dynamic region scoring function is constructed by using the distance from the protected location point to the center point as the criterion for judging the sensitivity of the protected location point. And construct a dynamic position scoring function. As a dynamic scoring function for the location points to be protected; Step 2.2.2: When the location to be protected... When the area block is a non-sensitive area, the geographic semantic information corresponding to the location points in the historical location dataset is obtained and stored in the semantic dictionary. S In this process, the importance of the location points to be protected is determined, and a dynamic semantic scoring function is constructed as the dynamic scoring function for the location points to be protected. Step 2.3: Process the historical location dataset Semantic dictionary S ,matrix and the coordinates of the center point of the area block where the location to be protected is located. Update; Step 3: Based on the normalized probability output of the location to be protected according to the dynamic scoring function of the location to be protected, determine the sensitivity of the location to be protected, and construct a dynamic privacy budget allocation function for the location to be protected according to the sensitivity. Step 4: Add perturbations to the latitude and longitude data of the locations to be protected according to the allocated privacy budget, and then publish the perturbated latitude and longitude data of the locations to be protected.
2. The location protection method based on a dynamic privacy budget mechanism according to claim 1, characterized in that, Step 1 includes: Step 1.1: Obtain the user's historical location information, including the longitude, latitude, date, and time of the historical location points, and construct a historical location dataset. ; Step 1.2: Query the maximum longitude in the historical location dataset. Minimum longitude Maximum latitude Minimum latitude And calculate the corresponding longitude difference. and latitude difference ; Step 1.3: Based on the size of the divided area blocks and formula (3), calculate the maximum longitude in the historical location dataset. Minimum longitude Maximum latitude Minimum latitude Update the system, and update the corresponding longitude difference as well. and latitude difference ; (3); in, The length of the divided region block; The width of the divided region block; This represents the distance between two points on the same meridian that differ by 1°. This represents the distance between two points on the same latitude circle that differ by 1°. Step 1.4: Divide the region bounded by the updated maximum longitude, minimum longitude, maximum latitude, and minimum latitude from Step 1.3 to generate... Each region block uses a matrix. Store the number of historical location points contained in each region block; (5); in, Represents a region block The number of historical location points included.
3. The location protection method based on a dynamic privacy budget mechanism according to claim 2, characterized in that, The method for determining whether the area block containing the location point to be protected is a sensitive area in step 2.1 is as follows: If , And the area block where the location to be protected is located. Number of historical location points within If so, the area block where the location to be protected is located is determined to be a sensitive area; Otherwise, the area block where the location to be protected is located is determined to be a non-sensitive area.
4. The location protection method based on a dynamic privacy budget mechanism according to claim 2, characterized in that, The construction of the dynamic region scoring function in step 2.2.1 and dynamic position scoring function The method is as follows: based on the coordinates of the center point within the area block where the location to be protected is located. Determine the maximum Euclidean distance from all points within the region to the center point. and minimum Euclidean distance The Euclidean distance from the location to be protected to the center of the block is calculated according to formula (10), and a dynamic area scoring function is constructed according to formula (11). A dynamic position scoring function is constructed based on formula (12). ; (10); (11); (12); in, The Euclidean distance from the location point to be protected to the center point of its block area; It is the Euclidean distance function.
5. The location protection method based on a dynamic privacy budget mechanism according to claim 2, characterized in that, The method for constructing the dynamic semantic scoring function in step 2.2.2 is as follows: by calling the data from the reverse geospatial service engine to perform reverse geocoding, the semantic information corresponding to historical location points in the historical location dataset is obtained and stored in the semantic dictionary. middle; The semantic information of the location point to be protected is obtained using the same method, and it is then determined whether the semantic information corresponding to the location point to be protected appears in the semantic dictionary. If not, the user shall provide the importance coefficient of the location to be protected based on its importance to the user. Alternatively, settings can be manually configured based on the semantic information of the locations to be protected. ; If it exists, the access frequency of the location to be protected is calculated according to formula (13). Combined with user-provided The importance of the location to be protected is calculated according to formula (14). Thus, the amount of information contained in the location point to be protected is determined according to formula (15). Therefore, formula (16) is constructed as a dynamic semantic scoring function. ; (13); (14); (15); (16); in, Importance coefficient of the location point to be protected The weight, Access frequency of the location to be protected The weight, , , ; The number of visits to the location to be protected; This represents the number of historical location points in the historical location dataset. This refers to the semantic information of the location points to be protected.
6. The location protection method based on a dynamic privacy budget mechanism according to claim 1, characterized in that, Step 3 includes: Step 3.1: Calculate the output probability of the protected location point based on the exponential mechanism and the dynamic scoring function of the location point to be protected. Furthermore, the output probability is normalized. Step 3.2: Based on the varying sensitivity of the locations to be protected, construct a dynamic privacy budget allocation function, and set the total privacy budget allocated in the dynamic privacy budget allocation function to be... When the location to be protected If the area block is a sensitive area, proceed to step 3.2.1; otherwise, proceed to step 3.2.
2. Step 3.2.1: When the location to be protected... When the area block is a sensitive area, the dynamic area scoring function is applied. Determine the sensitivity of the location points to be protected, and construct a dynamic privacy budget allocation function for the location points to be protected in the sensitive area; Step 3.2.2: When the location to be protected... When the area block is a non-sensitive area, the output probability of the location to be protected is used as the basis. Determine the sensitivity of the location points to be protected, and construct a dynamic privacy budget allocation function for the location points to be protected in non-sensitive areas.
7. The location protection method based on a dynamic privacy budget mechanism according to claim 6, characterized in that, The method for constructing the dynamic privacy budget allocation function for the protected location points in the sensitive area in step 3.2.1 is as follows: the maximum value of the dynamic area scoring function is calculated using formula (18). Minimum value of the dynamic region scoring function ; When the dynamic region scoring function satisfy At the same time, construct a dynamic privacy budget allocation function for the locations to be protected in sensitive areas. As shown in formula (19); if or Construct a dynamic privacy budget allocation function for protected locations in sensitive areas. As shown in formula (20); (18); (19); (20); in, Location points to be protected The allocated privacy budget.
8. The location protection method based on a dynamic privacy budget mechanism according to claim 6, characterized in that, The method for constructing the dynamic privacy budget allocation function for the protected location points in the non-sensitive area in step 3.2.2 is as follows: the importance threshold of the protected location points in the non-sensitive area is calculated using formula (21). The sensitivity of the protected location is determined based on its output probability. Construct a dynamic privacy budget allocation function for protected location points in non-sensitive areas. As shown in formula (22); If the output probability of the location to be protected Construct a dynamic privacy budget allocation function for protected location points in non-sensitive areas. As shown in formula (23); (21); (22); (23)。
Citation Information
Patent Citations
Location privacy protection system and method based on differential privacy noise addition selection
CN109617877A