Personalized track privacy protection method based on map matching and differential privacy

By combining differential privacy and map matching techniques, the noise radius and candidate region are adaptively adjusted to optimize the perturbation of trajectory points and the selection of candidate points. This addresses the shortcomings of existing trajectory privacy protection methods in terms of data usability and consistency, and achieves more efficient privacy protection and data utilization.

CN120846356APending Publication Date: 2025-10-28ANHUI NORMAL UNIV
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510957549.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-07-11
Publication Date
2025-10-28

AI Technical Summary

Technical Problem

Existing trajectory privacy protection methods, while protecting user privacy, fail to effectively consider the practicality and consistency of trajectory data, especially when the user's location changes dynamically, leading to a decrease in the practicality of location analysis.

Method used

By combining differential privacy and map matching techniques, the noise input is dynamically adjusted by adaptively adjusting the noise radius and candidate region. The starting and ending trajectory points are perturbed, and the candidate point selection of intermediate trajectory points is optimized by using the A* algorithm. A multi-attribute decision model is constructed to filter candidate points, ensuring the privacy protection of the trajectory and the usability of the data.

Benefits of technology

While protecting user privacy, it improves the usability and matching accuracy of trajectory data, reduces the risk of user trajectory leakage, and enhances the availability of data in traffic research and applications.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120846356A_ABST
    Figure CN120846356A_ABST
Patent Text Reader

Abstract

The invention discloses a personalized track privacy protection method based on map matching and differential privacy, and the method comprises the steps: carrying out the disturbance of a starting track point and a stopping track point through differential privacy, and obtaining a disturbed starting track point and a disturbed stopping track point; and finding a candidate point set for disturbance of the middle track points based on map matching, and finding a privacy track from a starting point to an ending point from the candidate point set of the middle track points through an A * algorithm by taking the disturbed starting track point as the starting point and the disturbed ending track point as the target point. After differential privacy and map matching are combined, a more real track is generated based on a road structure, noise interference of a non-road position is reduced, essentially, through deep fusion of a privacy protection technology and a traffic data processing flow, the risk of user track privacy leakage is reduced, and meanwhile the availability of data to traffic research and application is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention belongs to the field of privacy protection technology. More specifically, this invention relates to a personalized trajectory privacy protection method based on map matching and differential privacy. Background Technology

[0002] With the rapid development of intelligent transportation systems, the Internet of Things (IoT), and Global Positioning System (GPS) technologies, location-based services (LBS) have been widely applied, such as mobile users navigating to their destinations and enjoying online ride-hailing services. These LBS services not only provide users with real-time information about their surroundings but also offer a higher quality of life. Trajectory data can provide valuable information for traffic management, intelligent transportation systems, and urban planning. However, the collection and dissemination of trajectory data may lead to the leakage of user privacy information. In scenarios such as e-commerce, social networks, and advertising, the release of trajectory data exacerbates privacy issues. Therefore, how to effectively utilize trajectory data while protecting user privacy is a key challenge.

[0003] Differential privacy methods (DP) are widely used in privacy protection schemes. Andrés et al. established a geographic indistinguishability framework, which involves adding noise to the real location to ensure indistinguishability from neighboring candidate locations within a certain radius. They also proposed a planar Laplace mechanism that satisfies geographic indistinguishability through rigorous mathematical derivation, extending the Laplace mechanism from one-dimensional to two-dimensional. Yuan et al. proposed an R-tree-based differential privacy trajectory data protection model, using the DP method to construct a DPTS tree structure and adding noise to the statistics of mobile users in the nodes to resist attacks based on arbitrary background knowledge. However, this scheme does not consider the consistency problem of R-trees. Yang et al. proposed a trajectory data perturbation scheme based on quadtree indexing based on local differential privacy technology. This scheme protects the user's trajectory privacy while considering the correlation between adjacent spatiotemporal nodes of the trajectory. Yan et al. proposed a grid clustering privacy protection model, which constructs grid cells for data statistics and uses discrete wavelet transform to perform density clustering on the grid, injecting Laplace noise into the clustering results. However, the above scheme does not consider the dynamic changes of user location, and all locations are protected based on the same privacy radius, which reduces the practicality of the queried locations in location analysis. Summary of the Invention

[0004] This invention provides a personalized trajectory privacy protection method based on map matching and differential privacy, aiming to improve at least one of the above-mentioned problems.

[0005] The present invention is implemented as follows. A personalized trajectory privacy protection method based on map matching and differential privacy is as follows:

[0006] (1) Perturb the starting trajectory point and the ending trajectory point through differential privacy to obtain the perturbed starting trajectory point and the perturbed ending trajectory point;

[0007] (2) Based on map matching, find a candidate point set for perturbing the intermediate trajectory points. Starting from the perturbed starting trajectory point and using the perturbed ending trajectory point as the target point, find the privacy trajectory from the starting point to the ending point from the candidate point sets of each intermediate trajectory point through the A* algorithm.

[0008] Furthermore, the perturbation method for the starting trajectory point is as follows:

[0009] (11) Form a candidate area centered on the starting trajectory point with a candidate radius r;

[0010] (12) Extract all the roads within the candidate area and all the roads with the same road type as the starting trajectory point, and put them into the set RoadSet and the set RoadSetFC respectively;

[0011] (13) If the number of roads in the set RoadSet, RoadSet.size ≥ h, and the number of roads in the set RoadSetFC, RoadSetFC.size ≥ h f , then calculate the noise radius R in the Laplace noise function based on the current candidate radius r, R = 0.5r, and perform noise input on the starting trajectory point and the ending trajectory point based on the noise function to form the perturbed starting trajectory point and the perturbed ending trajectory point, where h is the threshold of the total number of roads, and h f is the threshold of the number of roads of the same road type.

[0012] Furthermore, if the number of roads in the set RoadSet, RoadSet.size < h, or the number of roads in the set RoadSetFC, RoadSetFC.size < h f , then expand the current candidate radius r until it satisfies RoadSet.size ≥ h and RoadSetFC.size ≥ h f .

[0013] Furthermore, the method for expanding the candidate radius r is as follows:

[0014] (131) Calculate the difference between the corresponding road threshold and the number of roads RoadSet.size and the number of roads RoadSetFC.size, and take the largest difference as the difference in the number of roads in the current candidate area Δ;

[0015] (132) Calculate the adaptive magnification factor α based on the difference in the number of roads in the current candidate area Δ, calculate the expansion step size StepNow based on the adaptive magnification factor α, update the current candidate radius r based on the expansion step size StepNow, r←r+StepNow, and return to step (11).

[0016] Furthermore, the formula for calculating the adaptive amplification factor α is as follows:

[0017] α = 1 + β·Δ·γ;

[0018] Where γ is the privacy sensitivity set by the user, γ∈[0,1], and β is the amplification factor.

[0019] Furthermore, the specific formula for calculating the increased step size StepNow is as follows:

[0020] StepNow=min(max(StepNow·α,StepMin),StepMax);

[0021] StepMin and StepMax represent the minimum and maximum values ​​of the step size, respectively.

[0022] Furthermore, a candidate region is constructed for each intermediate trajectory point, and the trajectory points of other trajectories located on each road segment within the candidate region are used as the candidate point set for the corresponding intermediate trajectory point.

[0023] Furthermore, the method for determining the candidate region of intermediate trajectory points is as follows:

[0024] (21) A candidate region is formed with the corresponding intermediate trajectory point as the center and the candidate radius r as the radius;

[0025] (22) Extract all road segments within the candidate area and put them into the RoadSet set;

[0026] (23) If the number of road segments in the RoadSet is RoadSet.size≥h, then the currently formed candidate region will be used as the candidate region for the corresponding intermediate trajectory point.

[0027] Furthermore, if the number of roads, RoadSet.size, is less than h, then the current candidate radius is updated, and the update method is as follows:

[0028] (231) Calculate the difference Δ1 between the road threshold and the number of roads RoadSet.size, and use the difference Δ1 as the difference Δ of the number of roads in the current candidate area;

[0029] (232) Calculate the adaptive magnification factor α based on the difference in the number of roads in the current candidate area Δ, calculate the expansion step size StepNow based on the adaptive magnification factor α, update the current candidate radius r based on the expansion step size StepNow, r←r+StepNow, and return to step (21).

[0030] Furthermore, the method also includes:

[0031] The benefit value of each candidate point is calculated based on the distance of each candidate point from the corresponding intermediate trajectory point, the consistency of the direction between the candidate point and the intermediate trajectory point, and the consistency of the road type between the candidate point and the intermediate trajectory point. Candidate points with high benefit values ​​are retained in the candidate point set.

[0032] This invention combines differential privacy with map matching primarily to protect user movement trajectory privacy while ensuring the data's usability in traffic research and applications. Because the combination of differential privacy and map matching generates more realistic trajectories based on road structures and reduces noise interference from "non-road locations," it essentially reduces the risk of user trajectory privacy leakage while improving the data's usability for traffic research and applications through the deep integration of privacy protection technology and traffic data processing procedures. Attached Figure Description

[0033] Figure 1 A flowchart of a personalized trajectory privacy protection method based on map matching and differential privacy provided in an embodiment of the present invention;

[0034] Figure 2 This is a schematic diagram illustrating how the obfuscation quality of different algorithms varies with privacy budget, as provided in embodiments of the present invention.

[0035] Figure 3 A schematic diagram illustrating the variation of root mean square error with privacy budget for different algorithms provided in embodiments of the present invention;

[0036] Figure 4 This is a schematic diagram illustrating the variation of matching accuracy with the number of trajectories provided in an embodiment of the present invention. Detailed Implementation

[0037] The specific embodiments of the present invention will be further described in detail below with reference to the accompanying drawings, so as to help those skilled in the art to have a more complete, accurate and in-depth understanding of the inventive concept and technical solution of the present invention.

[0038] This invention presents a personalized trajectory privacy protection method based on map matching and differential privacy (MMDP-PTPP). At the start and end node stages of the disturbed trajectory, the method dynamically adjusts the candidate link region based on user privacy sensitivity and local road density to adjust the noise radius and injects planar Laplace noise to protect the privacy of the trajectory start and end points. Secondly, at the intermediate node stage of the candidate trajectory, a multi-attribute decision model is established to optimize candidate node selection, considering factors such as distance, trajectory direction consistency, and functional classification consistency. Each candidate node is scored, and quantile threshold filtering is used to ensure matching accuracy while enhancing privacy protection.

[0039] Figure 1 The flowchart of the personalized trajectory privacy protection method based on map matching and differential privacy provided in this embodiment of the invention is as follows:

[0040] (1) Perturb the starting trajectory point and the ending trajectory point by differential privacy to obtain the perturbed starting trajectory point and the perturbed ending trajectory point.

[0041] In this embodiment of the invention, the method for perturbing the starting trajectory point is as follows:

[0042] (11) A candidate region is formed with the starting trajectory point as the center and the candidate radius r as the radius;

[0043] (12) Extract all roads within the candidate area and all roads of the same type as the starting trajectory point, and put them into the set RoadSet and the set RoadSetFC respectively;

[0044] The RoadSet contains the road identifiers of all roads within the candidate region, while the RoadSetFC contains the road identifiers of roads within the candidate region that have the same road type as the starting trajectory point.

[0045] (13) If the number of roads in the set RoadSet is RoadSet.size≥h, and the number of roads in the set RoadSetFC is RoadSetFC.size≥h f Then, based on the current candidate radius r, the noise radius R in the Laplace noise function is calculated, R = 0.5r. Noise input is applied to the starting and ending trajectory points based on the noise function to form the perturbed starting and ending trajectory points. If the number of roads in the set RoadSet.size < h, or the number of roads in the set RoadSetFC.size < h, then... fThen update the current candidate radius r until the number of roads RoadSet.size ≥ h is satisfied, and the number of roads in set RoadSetFC.size ≥ h is also satisfied. f Where h is the threshold for the total number of roads, h f h is the threshold for the number of roads of the same road type. f Both h are set values.

[0046] In this embodiment of the invention, the method for updating the candidate radius r is as follows:

[0047] (131) Calculate the difference between the corresponding road threshold and the number of roads RoadSet.size and the number of roads RoadSetFC.size, and take the largest difference as the difference in the number of roads in the current candidate area Δ;

[0048] In this embodiment of the invention, the difference Δ1 between the threshold h and the number of roads RoadSet.size is calculated, where Δ1 = max(h - RoadSet.size, 0); and the threshold h... f The difference between the number of roads and RoadSetFC.size is Δ2, where Δ2 = max(h f -RoadSetFC.size,0), the difference in the number of roads within the current candidate region, Δ=max(Δ1,Δ2),

[0049] (132) Calculate the adaptive magnification factor α based on the difference in the number of roads in the current candidate area Δ, calculate the expansion step size StepNow based on the adaptive magnification factor α, update the current candidate radius r based on the expansion step size StepNow, r←r+StepNow, and return to step (11).

[0050] In this embodiment of the invention, the adaptive amplification factor α is used to set the step size of the candidate radius step size adjustment. Its calculation formula is: α=1+β·Δ·γ, where γ is the privacy sensitivity set by the user, γ∈[0,1], and β is the amplification coefficient.

[0051] The formula for calculating the step size StepNow of the current candidate radius r is as follows:

[0052] StepNow=min(max(StepNow·α,StepMin),StepMax)

[0053] StepMin and StepMax represent the minimum and maximum values ​​of the expansion step, respectively. By setting the minimum and maximum values ​​of the expansion step, abnormal expansion speed can be avoided.

[0054] Starting from an initial candidate radius r0, candidate regions that meet preset conditions are found through iterative expansion. During the expansion process, both the total number of roads (h) and the number of roads of the same type within the candidate region are considered. f To balance computational efficiency and result accuracy, a dynamic step size adjustment mechanism was designed: In each iteration, the difference Δ between the RoadSet of all roads in the current candidate region and the RoadSetFC of all roads of the same type as the starting point and the corresponding threshold is calculated. This difference is then combined with the user privacy sensitivity parameter γ (a larger γ indicates higher user privacy requirements, while a smaller γ indicates a greater preference for preserving location accuracy) to construct an adaptive amplification factor α(Δ,γ). This factor is used to dynamically adjust the expansion step size of the candidate region. When the number of roads and the number of roads with the same function in the candidate region reach thresholds h and h' respectively... f At this point, the noise radius R of the Laplace noise function L(ε,R) is calculated based on the candidate radius r, where R = 0.5r and ε is the privacy budget. Noise is injected into the starting point of the trajectory based on the noise function L(ε,R), generating a perturbed starting trajectory point. The perturbation method for the ending trajectory point is the same as that for the starting trajectory point, and will not be elaborated further here. This algorithm effectively balances computational efficiency and privacy protection through an adaptive mechanism, while simultaneously meeting the personalized privacy needs of different users.

[0055] (2) Based on map matching, find a set of candidate points for perturbation of intermediate trajectory points. Take the perturbed starting trajectory point as the starting point and the perturbed ending trajectory point as the target point. Use the A* algorithm to find the privacy trajectory from the starting point to the end point from the candidate point set of each intermediate trajectory point.

[0056] In this embodiment of the invention, the starting point of the trajectory is called the starting trajectory point, the ending point of the trajectory is called the ending trajectory point, and the trajectory points located between the starting trajectory point and the ending trajectory point are called intermediate trajectory points. This invention constructs a candidate region for each intermediate trajectory point and uses the trajectory points of other trajectories on each road segment within the candidate region as the candidate point set of the corresponding intermediate trajectory points.

[0057] In this embodiment of the invention, the method for determining the candidate region of intermediate trajectory points is as follows:

[0058] (21) A candidate region is formed with the corresponding intermediate trajectory point as the center and the candidate radius r as the radius;

[0059] (22) Extract all road segments within the candidate area and put them into the RoadSet set;

[0060] (23) If the number of road segments in the RoadSet is RoadSet.size≥h, then the currently formed candidate region is used as the candidate region of the corresponding intermediate trajectory point. If the number of roads is RoadSet.size<h, then the current candidate radius is updated.

[0061] In this embodiment of the invention, the method for updating the candidate radius r is as follows:

[0062] (231) Calculate the difference Δ1 between the road threshold and the number of roads RoadSet.size, and use the difference Δ1 as the difference Δ of the number of roads in the current candidate area;

[0063] In this embodiment of the invention, the difference Δ1 between the threshold h and the number of roads RoadSet.size is: Δ1 = max(h - RoadSet.size, 0).

[0064] (232) Calculate the adaptive magnification factor α based on the difference in the number of roads in the current candidate area Δ, calculate the expansion step size StepNow based on the adaptive magnification factor α, update the current candidate radius r based on the expansion step size StepNow, r←r+StepNow, and return to step (21).

[0065] In this embodiment of the invention, the adaptive amplification factor α is used to set the step size of the candidate radius adjustment, and its calculation formula is: α=1+β·Δ·γ, where γ is the privacy sensitivity set by the user, γ∈[0,1], β is the amplification coefficient, and the calculation formula of the current candidate radius r increase stepNow is as follows:

[0066] StepNow=min(max(StepNow·α,StepMin),StepMax)

[0067] StepMin and StepMax represent the minimum and maximum values ​​of the step size, respectively.

[0068] (24) Calculate the benefit value of each candidate point based on the distance of each candidate point from the corresponding intermediate trajectory point, the consistency of the direction between the candidate point and the intermediate trajectory point, and the consistency of the road type between the candidate point and the intermediate trajectory point, and retain the candidate points with high benefit values ​​in the candidate point set.

[0069] The selection of candidate points in the candidate point set depends on three key attributes: the distance of the candidate point from the intermediate trajectory point, the directional consistency between the candidate point and the intermediate trajectory point, and the consistency of the road function between the candidate point and the intermediate trajectory point. A multi-attribute decision model is established to describe the utility impact of candidate points. The smaller the distance between the candidate point and the intermediate trajectory point, the greater the distance benefit value d. iThe larger the value, the smaller the angle between the heading angle of the intermediate trajectory point and the direction of the road segment where the candidate point is located; the higher the directional consistency, and the greater the directional consistency benefit value s. i The higher the value, the higher the heading angle of the current intermediate trajectory point. When the road type of the road segment where the current intermediate trajectory point is located is consistent with the road type of the candidate point's road segment, the higher the road type consistency benefit value f. i The value is 1, indicating inconsistency. The benefit value f corresponding to consistency in road type is... i The value is 0. Among them, road types include: expressways, urban roads (including residential roads, urban roads, motor vehicle roads, non-motor vehicle roads and pedestrian paths), commercial roads and rural roads, etc.

[0070] The candidate set of intermediate trajectory points is CandidateSet = c1, c2, ..., c n Each candidate point c i The feature score includes the benefit value d of distance. i Benefit value of directional consistency s i Benefit value f of consistency with road type i This forms an n×3 multi-attribute decision matrix, expressed as follows:

[0071]

[0072] In a multi-attribute decision matrix, the meanings and dimensions of each attribute are different and incommensurable. However, the benefit value corresponding to each attribute will affect the final decision. To ensure that the final result of the decision matrix better meets the personalized needs of users, a standardization method is used to eliminate the differences between the attributes. The standardization method for the benefit values ​​of the three attributes is as follows:

[0073]

[0074] Where, d i This represents the distance benefit value of the i-th candidate point in the candidate point set. The standardized distance benefit value d i d i ∈[d1,d n ],max{d1,d2,...,d n}、min{d1,d2,...,d n} represent the maximum and minimum distance benefit values ​​of all candidate points in the candidate point set, respectively.

[0075]

[0076] Among them, s i This represents the directional consistency benefit value of the i-th candidate point in the candidate point set. The standardized directional consistency benefit value s i ,max{s1,s2,...,s n}、min{s1,s2,...,s n} represent the maximum and minimum values ​​of the directional consistency benefit value of all candidate points in the candidate point set, respectively;

[0077]

[0078] Among them, f i This represents the road type consistency benefit value of the i-th candidate point in the candidate point set. The standardized road type consistency benefit value f represents the value of the road type consistency benefit. i .

[0079] The benefit value of each candidate point is formed based on the multi-attribute benefit values ​​of each candidate point, and the specific calculation formula is as follows:

[0080]

[0081] Among them, z i This represents the benefit value of the i-th candidate point in the candidate point set. Let w1, w2, and w3 represent the standardized distance benefit value, direction consistency benefit value, and road type consistency benefit value of the i-th candidate point in the candidate point set, respectively. w1, w2, and w3 are weights, satisfying w1 + w2 + w3 = 1. We set w1 = 0.5, w2 = 0.3, and w3 = 0.2. After determining the weights of each attribute, the benefit value of each candidate point can be calculated. After calculating the benefit value of each candidate point in the candidate set based on the above method, a quantile filtering strategy is adopted to further screen the candidate points. Here, a 50% quantile filtering strategy is used, sorting all candidate point benefit values ​​by size and taking the median, retaining only candidate points with benefit values ​​greater than or equal to the median.

[0082] Map matching, as a key spatial data processing technology, can accurately map the collected raw trajectory points onto the road network structure, correct trajectory deviations caused by positioning errors, and generate more accurate trajectory data that conforms to the real road network. This invention combines a differential privacy mechanism to add appropriate noise during the trajectory data publishing or sharing process, effectively interfering with attackers' identification of individual trajectories and achieving efficient protection of user trajectory privacy.

[0083] For the starting and ending trajectory points, a personalized adaptive noise selection method is proposed—dynamically adjusting the candidate link region based on user privacy sensitivity and road density to adjust the noise radius; a planar Laplace mechanism is used to apply noise interference to the starting and ending trajectory points to achieve privacy protection; for intermediate trajectory points, a multi-attribute decision model is constructed by fusing multiple dimensions such as distance constraints, trajectory direction offset, and functional classification matching degree, and a multi-level candidate node screening method is proposed. The method quantifies the candidate node fit value based on a comprehensive evaluation index and uses quantile threshold filtering to achieve a dynamic balance between matching accuracy and privacy protection strength. In the privacy path construction stage, candidate paths are first generated based on the candidate point set, and the candidate paths are randomly selected through an exponential dynamic programming (DP) mechanism. While ensuring ∈-DP, shorter paths are selected with a higher probability, balancing privacy and practicality.

[0084] This invention utilizes open-source road network data from OpenStreetMap covering open streets in Beijing, China. This data encompasses comprehensive information on the urban transportation system, including all levels of road types. Specifically, the data includes various road forms such as residential roads, urban roads, motor vehicle roads, non-motor vehicle roads, and pedestrian paths, providing detailed road network information support for the experiments. Test data comes from the Geolife public dataset from Microsoft Research, selecting 80 vehicle trajectories for testing, with an average sampling interval of 2 seconds between consecutive GPS trajectory points.

[0085] Matching accuracy refers to the ratio between the number of trajectory points successfully matched to the road network and the total number of trajectory points. It reflects the accuracy of the map matching algorithm in mapping trajectory points to the road network. The formula is as follows:

[0086]

[0087] Obfuscation quality is an important metric for evaluating the performance of MMDP-PTPP. The greater the distance between the perturbed trajectory points and the original trajectory points, the higher the quality of data obfuscation. Therefore, the distance between the original trajectory points and the perturbed trajectory points is used to quantify obfuscation quality:

[0088]

[0089] Where: s′ represents the noisy trajectory, s represents the original trajectory, and p′ represents the i-th trajectory point p in the original trajectory s. i The corresponding perturbation points. Since the current location privacy protection mechanism causes certain data quality issues while protecting location privacy, the root mean square error (RMSE) is used to measure the data loss before and after the perturbation.

[0090]

[0091] To verify the effectiveness of MMDP-PTPP, TLDP, GeoInd, and PTPP were selected as baseline mechanisms and compared in terms of obfuscation quality and data quality. TLDP protects user location information by adding Laplace noise to cluster locations; GeoInd adds Laplace noise to the original GPS points; PTPP controls the privacy budget based on geographic indistinguishability and the strength of relationships between users—all trajectory privacy protection algorithms. Finally, the matching accuracy of the map matching algorithm presented in this paper was compared with that of DMM, HMM, and trendHMM algorithms.

[0092] Figure 2 The figure presents the trends in obfuscation quality and RMSE of MMDP-PTPP as the privacy budget ε increases. As can be seen from the figure, the obfuscation quality of all algorithms decreases with increasing ε. This is because a larger privacy budget reduces the amount of added perturbation noise, leading to a lower level of obfuscation. Further observation reveals that GeoInd's obfuscation effect is relatively poor. Because the obfuscated GPS points in GeoInd are mainly concentrated around the original stop points, the distance between the obfuscated stop points and the original stop points is too close, resulting in an unsatisfactory obfuscation effect. In contrast, TLDP and PTPP show improved obfuscation quality, but MMDP-PTPP performs the best, with a 46% improvement in obfuscation quality across all baseline comparisons in this experiment.

[0093] from Figure 3 As can be seen, the RMSE of all algorithms decreases with the increase of the privacy budget ε. This indicates that as the privacy budget increases, the added noise decreases, and the average error between the true location and the perturbed location also decreases. Experimental data shows that the RMSE of MMDP-PTPP is significantly lower than that of other algorithms. Specifically, when ε = 0.2, the RMSEs of PTPP and TLDP algorithms are 7.2 and 7.6, respectively, while the RMSE of MMDP-PTPP is only 6.8; when ε = 1, the RMSEs of PTPP and TLDP drop to 5.4 and 5.7, respectively, and the RMSE of MMDP-PTPP further drops to 4.4. This shows that when the privacy budget is low, although PTPP and TLDP algorithms can achieve privacy protection through perturbed locations, the excessive added noise leads to reduced data availability. Compared with GeoInd, PTPP, and TLDP, the RMSE of MMDP-PTPP is reduced by 15%–29.03%, 5.65%–18.52%, and 10.53%–22.81%, respectively. During the experiment, the RMSE of MMDP-PTPP decreased by an average of 23.45%, significantly improving data quality.

[0094] The MMDP-PTPP, DMM, HMM, and trendHMM algorithms were applied to the above datasets, respectively. Figure 4 As can be seen, the matching accuracy of the four algorithms generally increases with the increase in the number of trajectories. When the number of trajectories reaches 80, the MMDP-PTPP algorithm has the highest matching accuracy, reaching 94.7%, followed by the trendHMM algorithm at 91.6%. The DMM and HMM algorithms have relatively lower matching accuracies, at 75.2% and 83.6%, respectively.

[0095] The reason for this difference lies in the fact that MMDP-PTPP prioritizes candidate points based on their distance from the target point, consistency of trajectory direction, and consistency of functional classification during the candidate point selection stage, calculates a comprehensive score, and finally filters and selects high-quality candidate points based on their quantile values. During the trajectory construction stage, the generated candidate paths take into account the path length to ensure the accuracy of map matching. In contrast, the DMM algorithm directly matches based on the shortest distance from the location point to the road segment, while HMM considers the geometric fit between the GPS point and the candidate road segment and measures the probability of moving from one road segment to another. TrendHMM is an improvement on the HMM algorithm, adding dependency modeling over a larger time span to capture trajectory trend information, thus outperforming the HMM algorithm in terms of performance.

[0096] The present invention has been described by way of example. Obviously, the specific implementation of the present invention is not limited to the above-described manner. Any non-substantial improvements made using the inventive concept and technical solution of the present invention, or the direct application of the inventive concept and technical solution of the present invention to other occasions without modification, are all within the protection scope of the present invention.

Claims

1. A personalized trajectory privacy protection method based on map matching and differential privacy, characterized in that, The method is as follows: (1) Perturb the starting trajectory point and the ending trajectory point by differential privacy to obtain the perturbed starting trajectory point and the perturbed ending trajectory point. (2) Based on map matching, find a set of candidate points for perturbation of intermediate trajectory points. Take the perturbed starting trajectory point as the starting point and the perturbed ending trajectory point as the target point. Use the A* algorithm to find the privacy trajectory from the starting point to the end point from the candidate point set of each intermediate trajectory point.

2. The personalized trajectory privacy protection method based on map matching and differential privacy as described in claim 1, characterized in that, The specific method for perturbing the starting trajectory point is as follows: (11) A candidate region is formed with the starting trajectory point as the center and the candidate radius r as the radius; (12) Extract all roads within the candidate area and all roads of the same type as the starting trajectory point, and put them into the set RoadSet and the set RoadSetFC respectively; (13) If the number of roads in the set RoadSet is RoadSet.size≥h, and the number of roads in the set RoadSetFC is RoadSetFC.size≥h f Then, based on the current candidate radius r, the noise radius R in the Laplace noise function is calculated, R = 0.5r. Based on the noise function, noise is input to the starting trajectory point and the ending trajectory point to form the perturbed starting trajectory point and the perturbed ending trajectory point. Where h is the threshold for the total number of roads, h f This is the threshold for the number of roads of the same road type.

3. The personalized trajectory privacy protection method based on map matching and differential privacy as described in claim 2, characterized in that, If the number of roads in the set RoadSet is less than h, or the number of roads in the set RoadSetFC is less than h. f Then expand the current candidate radius r until the number of roads RoadSet.size ≥ h is satisfied, and the number of roads in set RoadSetFC.size ≥ h is also satisfied. f .

4. The personalized trajectory privacy protection method based on map matching and differential privacy as described in claim 3, characterized in that, The specific method for increasing the candidate radius r is as follows: (131) Calculate the difference between the corresponding road threshold and the number of roads RoadSet.size and the number of roads RoadSetFC.size, and take the largest difference as the difference in the number of roads in the current candidate area Δ; (132) Calculate the adaptive magnification factor α based on the difference in the number of roads in the current candidate area Δ, calculate the expansion step size StepNow based on the adaptive magnification factor α, update the current candidate radius r based on the expansion step size StepNow, r←r+StepNow, and return to step (11).

5. The personalized trajectory privacy protection method based on map matching and differential privacy as described in claim 4, characterized in that, The formula for calculating the adaptive amplification factor α is: α = 1 + β·Δ·γ; Where γ is the privacy sensitivity set by the user, γ∈[0,1], and β is the amplification factor.

6. The personalized trajectory privacy protection method based on map matching and differential privacy as described in claim 5, characterized in that, The specific formula for calculating the increased step size StepNow is as follows: StepNow=min(max(StepNow·α,StepMin),StepMax); StepMin and StepMax represent the minimum and maximum values ​​of the step size, respectively.

7. The personalized trajectory privacy protection method based on map matching and differential privacy as described in claim 5, characterized in that, For each intermediate trajectory point, a candidate region is constructed, and the trajectory points of other trajectories located on each road segment within the candidate region are used as the candidate point set for the corresponding intermediate trajectory point.

8. The personalized trajectory privacy protection method based on map matching and differential privacy as described in claim 7, characterized in that, The specific method for determining the candidate region of intermediate trajectory points is as follows: (21) A candidate region is formed with the corresponding intermediate trajectory point as the center and the candidate radius r as the radius; (22) Extract all road segments within the candidate area and put them into the RoadSet set; (23) If the number of road segments in the RoadSet is RoadSet.size≥h, then the currently formed candidate region will be used as the candidate region for the corresponding intermediate trajectory point.

9. The personalized trajectory privacy protection method based on map matching and differential privacy as described in claim 8, characterized in that, If the number of roads (RoadSet.size) is less than h, then the current candidate radius is updated. The update method is as follows: (231) Calculate the difference Δ1 between the road threshold and the number of roads RoadSet.size, and use the difference Δ1 as the difference Δ of the number of roads in the current candidate area; (232) Calculate the adaptive magnification factor α based on the difference in the number of roads in the current candidate area Δ, calculate the expansion step size StepNow based on the adaptive magnification factor α, update the current candidate radius r based on the expansion step size StepNow, r←r+StepNow, and return to step (21).

10. The personalized trajectory privacy protection method based on map matching and differential privacy as described in claim 1, characterized in that, The method further includes: The benefit value of each candidate point is calculated based on the distance of each candidate point from the corresponding intermediate trajectory point, the consistency of the direction between the candidate point and the intermediate trajectory point, and the consistency of the road type between the candidate point and the intermediate trajectory point. Candidate points with high benefit values ​​are retained in the candidate point set.