Cross-city user trajectory privacy protection method facing dynamic adaptive attack

The cross-city user trajectory privacy protection model built through adversarial learning mechanism solves the problem of balancing service quality and user trajectory preferences in cross-city trajectory privacy protection, and achieves effective protection under dynamic adaptive attacks.

CN120915598AActive Publication Date: 2025-11-07JIANGSU POLICE INST
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202511416140.1
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-09-30
Publication Date
2025-11-07
Estimated Expiration
2045-09-30

AI Technical Summary

Technical Problem

Existing technologies struggle to balance the location service quality requirements of different cities with changes in user trajectory preferences in cross-city trajectory privacy protection, and are unable to effectively defend against dynamic adaptive attacks.

Method used

A cross-city user trajectory privacy protection model is built using an adversarial learning mechanism, including an encoder-decoder network, a protection module, and an attack module. Through a gating weighted fusion mechanism and adversarial learning optimization, a balance between trajectory privacy and service quality is achieved.

Benefits of technology

It achieves effective protection of cross-city user trajectories under dynamic adaptive attacks, taking into account the service quality needs and user trajectory preferences of different cities, and provides comprehensive privacy protection.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120915598A_ABST
    Figure CN120915598A_ABST
Patent Text Reader

Abstract

The invention belongs to the technical field of privacy protection, and discloses a cross-city user trajectory privacy protection method for dynamic adaptive attacks, which adopts a weight learnable gating weighted fusion mechanism to realize trajectory privacy feature fusion so as to support the construction of an attack module and a protection module. And different penalty functions are provided to respectively control the service quality of different cities, and effective balance modeling between the user track privacy and the service quality in the cross-city scene is finally realized. According to the method, the access preferences of the user in a local city and a remote city can be considered, and the vector representation of the access preferences of the user in a latent semantic space is obtained through weighted fusion of local and remote track privacy features. According to the method, more comprehensive track privacy protection can be provided for cross-city travel users on the basis of cross-city migration fusion track privacy features, and cross-city track inference is resisted while the search service quality is guaranteed.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The application belongs to the technical field of privacy protection, and particularly relates to a cross-city user trajectory privacy protection method facing dynamic adaptive attacks. BACKGROUND

[0002] With the rapid development of mobile Internet and positioning technology, a large amount of fine-grained aggregated data is generated in the process of cross-city travel of users, and once these data are leaked, personal travel habits and life privacy are extremely easy to be exposed. Cross-city trajectories often cover the user's residence, workplace and travel destination, and their sensitivity is much higher than that of single-city check-in data, so it is of more urgent practical significance to protect them. However, in the cross-city market scene, there is no research on trajectory privacy protection when facing dynamic adaptive attacks under the user preference migration mode, which may lead to the improper use of trajectory data.

[0003] Current research on cross-city user behavior mainly focuses on location recommendation tasks, which aims to migrate the access preferences of users from an information-rich source city to a target city, and then to alleviate the cold start problem. The core of this method is how to connect the user's access preferences in the local city and in the foreign city. In order to achieve the effect of preference migration, many existing methods assume that there is a connection between the access preferences of users in the source city and the target city, and all users share this connection.

[0004] Overall, cross-city user trajectory privacy protection faces two major challenges. First, the quality of location services required by users in different cities may be different. The quality of location services required in the familiar local city can be slightly worse, but the quality of location services required in the unfamiliar foreign city is often slightly higher. How to compatible the quality of location services required in different cities in the cross-city trajectory privacy protection mechanism is an important problem to be solved. Second, the trajectory preferences of users in different cities may change due to the influence of city customs and travel purposes and other aspects of privacy. How to take into account and integrate the trajectory preferences of users in different cities to better design the protection scheme is also a key problem to be solved. SUMMARY

[0005] The purpose of the application is to provide a cross-city user trajectory privacy protection method facing dynamic adaptive attacks. The method simulates attack and defense games through an adversarial learning mechanism to realize the alternating optimization of the attack strategy of the attack module and the protection strategy of the protection module, so as to obtain a cross-city user trajectory privacy protection model facing dynamic adaptive attacks which effectively takes into account the user trajectory privacy and the quality of services in multiple cities.

[0006] In order to achieve the above purpose, the application adopts the following technical scheme: A cross-city user trajectory privacy protection method facing dynamic adaptive attacks, comprising the following steps: Step 1. A cross-city user trajectory privacy protection model facing dynamic adaptive attacks is built, which comprises the following structures: A codec network for learning trajectory feature representation of users in different cities; A protection module comprising a pre-territorial trajectory feature fusion layer and an access record protection layer; The input of the pre-territorial trajectory feature fusion layer is the current access record and the protected cross-city historical trajectory, which is extracted by the codec network to obtain the pre-protected trajectory feature representation, and then based on the gating weighted fusion mechanism, the pre-protected regional trajectory fusion feature is obtained; The input of the access record protection layer is the pre-protected regional trajectory fusion feature, which is mapped based on the protection strategy to obtain the protected current access record; An attack module comprising a post-territorial trajectory feature fusion layer and a trajectory prediction layer; The input of the post-territorial trajectory feature fusion layer is the protected current access record and the protected cross-city historical trajectory, which is extracted by the codec network to obtain the post-protected trajectory feature representation, and then based on the gating weighted fusion mechanism, the post-protected regional trajectory fusion feature is obtained; The input of the trajectory prediction layer is the post-protected regional trajectory fusion feature, which is mapped based on the attack strategy to obtain the guessed trajectory; Step 2. An adversarial learning mechanism is introduced between the protection module and the attack module, and a trajectory privacy protection optimization objective function under the service quality limited cross-territorial search service is constructed by combining the trajectory privacy loss and the service quality loss, and the cross-city user trajectory privacy protection model facing dynamic adaptive attacks is trained; Step 3. The trained cross-city user trajectory privacy protection model facing dynamic adaptive attacks is used to protect the cross-city user trajectory privacy.

[0007] The present application has the following advantages: As described above, this invention discloses a method for protecting cross-city user trajectory privacy against dynamic adaptive attacks. The method constructs a cross-city user trajectory privacy protection model for dynamic adaptive attacks, the core of which includes a dynamic adaptive attack structure (attack module) and a protection module that balances trajectory privacy and service quality. The attack effect of the attack module is used to quantify the protection effect of the protection module on cross-city trajectory privacy, thus solving the quantification problem of cross-city user trajectory privacy. Simultaneously, this invention employs a learnable weighted gating weighted fusion mechanism to achieve trajectory privacy feature fusion, supporting the construction of the attack and protection modules and meeting the need for full mining of user privacy features in cross-city scenarios. Furthermore, this invention proposes different penalty functions to control the service quality of different cities separately, ultimately achieving an effective balance modeling between user trajectory privacy and service quality in cross-city scenarios. This invention can take into account users' access preferences in both local and remote cities, obtaining a vector representation of user access preferences in the latent semantic space through weighted fusion of local and remote trajectory privacy features. Based on the trajectory privacy features of cross-city migration fusion, this invention can provide more comprehensive trajectory privacy protection for users traveling across cities, while ensuring the quality of search services and resisting cross-city trajectory inference. Attached Figure Description

[0008] Figure 1 This is a flowchart of a cross-city user trajectory privacy protection method for dynamic adaptive attacks in an embodiment of the present invention.

[0009] Figure 2 This is a model architecture diagram of a cross-city user trajectory privacy protection model for dynamic adaptive attacks in an embodiment of the present invention.

[0010] Figure 3 for Figure 2 A magnified view of a portion of region II in the middle.

[0011] Figure 4 for Figure 2 A magnified view of a portion of region I.

[0012] Figure 5 This is a schematic diagram of the codec network structure in an embodiment of the present invention. Detailed Implementation

[0013] The present invention will be further described in detail below with reference to the accompanying drawings and specific embodiments: Example 1 The existing scheme has two difficulties in solving the cross-city user trajectory privacy protection, one is that the quality of location service required by the user in different cities may be different, and the quality of location service in different cities needs to be compatible; the second is that the trajectory preference of the user in different cities may change due to the influence of city customs and travel purposes and other privacy, how to consider and integrate the trajectory preference of the user in different cities to better design the protection scheme lacks appropriate solutions.

[0014] In view of the above problems, the present application designs a cross-city user trajectory privacy protection method for dynamic adaptive attack for location social network users in cross-city travel, so as to realize cross-city trajectory privacy embedding and cross-city trajectory privacy feature fusion.

[0015] The present application designs a cross-city unified protection mechanism based on the concept of confrontation, so as to realize the balance between trajectory privacy and different city service quality, and proposes a cross-city user trajectory privacy protection model for dynamic adaptive attack, which includes two components of protection module and attack module. First, the trajectory features of the user in different cities are extracted by using the protection module, a pre-regional trajectory feature fusion layer is designed based on the gate weighted fusion, the pre-regional trajectory fusion features are obtained to support the privacy protection of the current access record. Secondly, the protected current access record and the protected cross-city historical trajectory are spliced to obtain the protected cross-city trajectory of the user, and the attack module is used to analyze it. The attack module uses the post-regional trajectory feature fusion layer to obtain the post-regional trajectory fusion features of the user in different cities, and then reorganizes and restores the cross-city trajectory through the trajectory prediction layer, and outputs the guessed access record and the guessed trajectory. Finally, the confrontation learning mechanism is introduced between the protection module and the attack module to simulate the attack and defense game, and the attack strategy and the protection strategy are alternately optimized through the alternation of parameters, so as to obtain the cross-city user trajectory privacy protection model for dynamic adaptive attack which effectively considers the user trajectory privacy and the service quality of multiple cities.

[0016] Now the dynamic adaptive inference attack based on cross-city trajectory fusion will be introduced.

[0017] The attacker targeted by the present application can obtain the cross-city trajectory generated by the same user when using location services in different cities. At the same time, the attacker can train a dynamic adaptive attack model, i.e. a cross-city attack model, by using the public protection application.

[0018] Specifically, for the protection application , the attacker inputs the real user trajectory, i.e., the real cross-city trajectory, can obtain the corresponding protected cross-city trajectory, and a protected cross-city trajectory-real cross-city trajectory pair is formed to train the dynamic adaptive attack model. For the protected user cross-city trajectory, the attacker knows the access record information containing the blurred latitude and longitude.

[0019] In the training process, for the cross-city attack model , a preset user application is protected, and the protected cross-city trajectory segment is . The goal of the cross-city attack model is to improve the guessing ability by learning the mechanism and structure of the protected application , and the specific process is defined as follows: ).

[0020] Wherein, is the guessed trajectory output by the cross-city attack model , and and both contain access records. is the parameter set of the cross-city attack model , that is, the attack strategy of the cross-city attack model . is the process of the cross-city attack model generating a guessed trajectory.

[0021] Then the cross-city trajectory privacy protection framework based on the adversarial learning of the application is introduced.

[0022] In order to resist the dynamic adaptive attack facing the cross-city search trajectory privacy, the application proposes a user trajectory privacy protection framework based on the adversarial concept, and builds a cross-city user trajectory privacy protection model facing the dynamic adaptive attack. The protection framework is composed of a cross-city trajectory privacy protection module, referred to as a protection module and a cross-city trajectory inference attack module, referred to as an attack module . The protection application and potential attack in the protection and attack process are simulated through the protection module and the attack module. By introducing the dynamic adaptive attack module , the optimal protection module is obtained through dynamic adversarial training, so that the user can minimize the loss of trajectory privacy when facing the maximum attack, and ensure the controllability of the utility loss caused by location blurring, i.e. the service quality loss in the protection module .

[0023] The application defines the protection module as a function of the real access record and the protected access record The specific process is represented as: .

[0024] wherein, represents the cross-city user protected historical trajectory, i.e., the protected cross-city historical trajectory, contains access records. represents the real access information at the current time, i.e., the current access record, i.e., the protected current access record, represents the parameter setting of the protection module, i.e., the protection strategy.

[0025] The protection module outputs a fuzzy location , represents the protection module generating the fuzzy location.

[0026] Meanwhile, the attack module is defined as a fuzzy trajectory and a guessed trajectory and spliced together, and is represented as: .

[0027] wherein, represents the parameter setting of the attack module , i.e., the attack strategy. The guessed trajectory contains access records. represents the process of the attack module generating the guessed trajectory.

[0028] The cross-city user trajectory privacy protection method facing dynamic adaptive attacks will be specifically introduced below.

[0029] As shown in Figure 1 , the cross-city user trajectory privacy protection method facing dynamic adaptive attacks specifically includes the following steps: Step 1. Build a cross-city user trajectory privacy protection model facing dynamic adaptive attacks, which includes a codec network, a protection module and an attack module.

[0030] The codec network is used to learn the trajectory feature representation of the user in different cities.

[0031] The codec network is specifically as shown in Figure 5 ​As shown, the codec network includes a region discriminator, an A-region trajectory feature encoder, an A-region trajectory feature decoder, a B-region trajectory feature encoder, a B-region trajectory feature decoder, and a real or fake trajectory discriminator.

[0032] The region discriminator is used to determine the city to which the trajectory belongs, and the city to which the trajectory belongs includes the A-region and the B-region.

[0033] The A-region trajectory feature encoder is used to extract a cross-city user trajectory feature representation in the A-region from the user A-region check-in records.

[0034] The A-region trajectory feature decoder is used to decode the cross-city user trajectory feature representation in the A-region to obtain a restored trajectory of the cross-city user in the A-region, i.e., the restored A-region check-in records.

[0035] The B-region trajectory feature encoder is used to extract a cross-city user trajectory feature representation in the B-region from the user B-region check-in records.

[0036] The B-region trajectory feature decoder is used to decode the cross-city user trajectory feature representation in the B-region to obtain a restored trajectory of the cross-city user in the B-region, i.e., the restored B-region check-in records.

[0037] The real or fake trajectory discriminator is used to determine whether it is a restored trajectory.

[0038] The processing flow of the signal in the codec network is as follows: The input of the codec network is the access records , which include the user A-region check-in records and the user B-region check-in records.

[0039] The access records in the input codec network are processed as follows: According to the region identification bits of each position in the trajectory, the A-region trajectory matrix and the B-region trajectory matrix are extracted, respectively, and the missing bits in and are filled with 0, where , represents the length of the trajectory, represents the encoding length of the access records .

[0040] The A-region trajectory matrix is input into the A-region trajectory feature encoder to obtain a vector representation of the user trajectory privacy feature in a high-dimensional space , i.e., the cross-city user trajectory feature representation in the A-region: .

[0041] The cross-city user trajectory feature representation in the A-region is decoded by the A-region trajectory feature decoder Decode the data to obtain the recovery trajectory of cross-city users in location A.

[0042] The trajectory matrix at location B Input B location trajectory feature encoder This yields the vector representation of user trajectory privacy features in a high-dimensional space. That is, the trajectory characteristics of cross-city users in location B: .

[0043] Using the trajectory feature decoder at location B Decode the data to obtain the recovery trajectory of the cross-city user in location B.

[0044] The codec network is used to support cross-city trajectory privacy representation learning for protection and attack modules.

[0045] When the decoder network is used to support the learning of cross-city trajectory privacy representations for the protection module, the access records input to the codec network include the current access records and the protected cross-city historical trajectories. These are processed by the codec network for feature extraction, and its output is the pre-protection trajectory feature representation. Conversely, when the decoder network is used to support the learning of cross-city trajectory privacy representations for the attack module, the access records input to the codec network include the protected current access records and the protected cross-city historical trajectories. These are processed by the codec network for feature extraction, and its output is the post-protection trajectory feature representation.

[0046] Taking the protection module as an example, the method of this invention will record each access record. The data is vectorized based on inherent attributes such as latitude and longitude. On this basis, the actual access record, i.e., the current access record, is then... The encoding and the user's previous A protected historical trajectory is a cross-city historical trajectory that has been protected. Forming the input matrix Furthermore, based on the geographical identifier of each location in the trajectory, the trajectory matrices for locations A and B are extracted respectively. The trajectory matrix for location A in the protection module is denoted as... The trajectory matrix of location B in the protection module is denoted as ,in , Missing bits are padded with 0s. After input embedding, the method of this invention employs two independent, pre-trained encoder networks. and This is used to extract trajectory features, thereby obtaining the trajectory feature representation before protection.

[0047] When the decoder network supports the cross-city trajectory privacy representation learning of the attack module, the access records input into the encoder-decoder network include the protected current access records and the protected cross-city historical trajectories, and the A-city and B-city trajectory matrices also need to be extracted, the A-city trajectory matrix in the attack module is denoted as , the B-city trajectory matrix in the attack module is denoted as , wherein , , the missing values are filled with 0, and then the trajectory features are extracted through the encoder network and , and then the protected trajectory feature representation is obtained.

[0048] The encoder network and are neural networks trained together with the protection module and the attack module, and the automatic encoder-decoder is used to learn the trajectory feature representation of the user in different cities, and the encoding quality of the encoder network and is supervised through the region discriminator and the real-fake trajectory discriminator . Among them, the region discriminator is used to judge the city to which the trajectory belongs, and taking the extraction of the user trajectory features in two cities A and B as an example, the region discriminator judges whether the trajectory belongs to the A city or the B city. The real-fake trajectory discriminator is used to distinguish the real trajectory and the restored trajectory.

[0049] Specifically, the cross-city trajectory feature representation of the user in the A city output by the A-city trajectory feature encoder and the cross-city trajectory feature representation of the user in the B city output by the B-city trajectory feature encoder are input into the region discriminator , and the region discriminator outputs the judgment result of the city to which the trajectory belongs. In this embodiment, the region discriminator preferably adopts a two-layer multi-layer perception (MLP) to distinguish the city to which the trajectory belongs, and the output is the predicted city probability .

[0050] The A-city trajectory matrix and the B-city trajectory matrix extracted from the access records input into the encoder-decoder network , the restored trajectory of the cross-city user in the A city output by the A-city trajectory feature decoder, and the restored trajectory of the cross-city user in the B city output by the B-city trajectory feature decoder are input into the real-fake trajectory discriminator , and the real-fake trajectory discriminator outputs the judgment result of whether it is a restored trajectory. In this embodiment, the real-fake trajectory discriminator The two-layer multi-layer perception (MLP) is preferably used for distinguishing the real and false trajectories, and the output is the probability of predicting the real and false trajectories. .

[0051] The protection module includes a pre-regional trajectory feature fusion layer and an access record protection layer.

[0052] As shown in Figure 4 , the input of the protection module is the protected historical check-in trajectory and the real access record. The real access record is the current access record . The protected historical check-in trajectory is the protected cross-city historical trajectory , which includes the protected local check-in record and the protected out-of-town check-in record. The output of the protection module is the protected access record, which is the protected current access record .

[0053] The input of the pre-regional trajectory feature fusion layer is the current access record and the protected cross-city historical trajectory. The pre-trajectory feature representation is extracted through the encoder-decoder network, and then the pre-regional trajectory fusion feature is obtained based on the gating weighted fusion mechanism.

[0054] In this embodiment, the cross-city trajectory privacy feature fusion is realized based on the learnable weight gating weighted fusion mechanism. The gating weighted fusion mechanism will be described in detail below. The gating weighted fusion mechanism is specifically: Let be the trajectory privacy feature of the cross-city user in A place , and let be the trajectory privacy feature of the cross-city user in B place . Then the trajectory feature representation of the cross-city user in A place and B place is , wherein .

[0055] The trajectory privacy features and are fused by the weight-variable weighted fusion method to obtain the fused cross-city trajectory privacy feature, i.e., the regional trajectory fusion feature. Specifically, the feature fusion in the pre-regional trajectory feature fusion layer of the protection module obtains the pre-regional trajectory fusion feature, and the feature fusion in the post-regional trajectory feature fusion layer of the attack module obtains the post-regional trajectory fusion feature.

[0056] The variable weight is obtained by performing matrix transformation on the input trajectory matrix , and then outputting the normalized weight probability distribution through the softmax layer. The specific process is represented as: .

[0057] wherein, for indicating the city where the current record to be protected is located, , denotes the softmax layer, is a column vector of the trajectory matrix . denotes the learnable parameter vector, and the vector length is .

[0058] There are local and foreign trajectories for each city. Therefore, for each kind of privacy feature representation of the local and foreign trajectory matrix , there corresponds a learnable weight , which is weighted and fused, and the specific process of the variable-weighted fusion is represented as: .

[0059] wherein, denotes the regional trajectory fusion feature. The above process finally obtains the regional trajectory fusion feature, which can be used to further support the protection module to carry out protection.

[0060] The input of the access record protection layer of the protection module is the pre-protection regional trajectory fusion feature, which is mapped based on the protection strategy to obtain the protected current access record.

[0061] . .

[0062] wherein, denotes the protected current access record. denotes the access record protection layer network, and the core architecture thereof is a general time series decoding network, including but not limited to RNN, LSTM, GRU, and Transformer encoder.

[0063] is the pre-protection regional trajectory fusion feature, which is extracted by inputting the current access record and the protected cross-city historical trajectory into the encoder-decoder network to obtain the pre-protection trajectory feature representation , and based on the variable weight .

[0064] wherein, denotes the trajectory matrix input into the access record protection layer, and the variable weight is obtained by inputting the trajectory matrix​ The matrix is transformed, and a normalized weight probability distribution is output through a softmax layer.

[0065] The attack module includes a post-regional trajectory feature fusion layer and a trajectory prediction layer.

[0066] As shown in Figure 3 , the input of the attack module is the protected trajectory, which includes the protected current access record and the protected cross-city historical trajectory . The protected cross-city historical trajectory also includes the protected local check-in record and the protected out-of-town check-in record. The output of the attack module is the guessed trajectory, which contains the guessed access record.

[0067] The input of the post-regional trajectory feature fusion layer is the protected current access record and the protected cross-city historical trajectory, which extracts the protected trajectory feature representation through the encoder-decoder network, and then obtains the protected regional trajectory fusion feature based on the gating weighted fusion mechanism.

[0068] The input of the trajectory prediction layer is the protected regional trajectory fusion feature, which is mapped based on the attack strategy to obtain the guessed trajectory.

[0069] After obtaining the protected regional trajectory fusion feature, the attack module will guess the original trajectory information through the trajectory prediction layer network. The processing flow of the signal in the trajectory prediction layer of the attack module is represented as: .

[0070] wherein, represents the guessed trajectory. represents the trajectory prediction layer network, the core architecture of which is a general time series decoding network, including but not limited to RNN, LSTM, GRU, and Transformer encoder.

[0071] is the protected regional trajectory fusion feature, which is obtained by inputting the protected current access record and the protected cross-city historical trajectory into the encoder-decoder network to extract the protected trajectory feature representation , and based on the gating weighted fusion mechanism with variable weights.

[0072] wherein, represents the trajectory matrix input into the trajectory prediction layer, and the variable weight is obtained by processing the trajectory matrix ​The matrix is transformed, and a normalized weight probability distribution is output through a softmax layer.

[0073] Step 2. Introduce an adversarial learning mechanism between the protection module and the attack module, and combine trajectory privacy loss and service quality loss to construct a trajectory privacy protection optimization objective function under the service quality limited cross-regional search service, and train the cross-city user trajectory privacy protection model facing dynamic adaptive attacks.

[0074] The method designs trajectory privacy loss and service quality loss to quantitatively represent cross-city trajectory privacy and cross-city service quality, and the trajectory privacy loss and service quality loss are specifically: In the cross-city trajectory privacy protection framework, the protection module and the attack module are organized in a mutually antagonistic relationship to form a non-cooperative game about cross-city user trajectory privacy, the protection module and the attack module about the information gain of cross-city user trajectory privacy is zero, that is, the information protected by the protection module is also the information that the attack module fails to guess.

[0075] Therefore, the expected loss of the attack module is used to measure the trajectory privacy loss of the cross-city user after being protected by the protection module , that is . To define the expected loss of the attack module , from the perspective of the attacker, the ideal guessed trajectory should be as close as possible to the real trajectory of the user in the geographical space, therefore, the calculation formula of the expected loss of the attack module is: .

[0076] Wherein, represents the expected value, is the real trajectory of the cross-city user , and and both contain access records. represents the real trajectory and the guessed trajectory The physical distance between the real trajectory and the guessed trajectory. The physical distance between the real trajectory and the guessed trajectory.

[0077] To balance the trajectory privacy and the quality loss between different city search services, the local search service quality loss of A city and the local search service quality loss of B city are quantified respectively, and are expressed as: .

[0078] .

[0079] wherein, , represents the real position of the cross-city user, represents the fuzzy position output by the protection module, represents the physical distance between the real position and the fuzzy position. represents the service identification of the first protected access record. When =0, it is the access record of the A city search service, and when

[0080] =1, it is the access record of the B city search service. In the embodiment, a balance mechanism of cross-city trajectory privacy and multi-city service quality is also designed. The process of constructing the trajectory privacy protection optimization objective function under the cross-regional search service with limited service quality is specifically as follows: The method simultaneously learns the optimal cross-city trajectory privacy protection strategy and the cross-city trajectory inference attack strategy , and uses a loss function to control the strategy effect of

[0081] and .

[0082] The expected loss of the attack module is used to measure the attack effect of the attack module under the attack strategy . The expected loss of the attack module

[0083] is used to measure the attack effect of the attack module under the attack strategy . The expected loss of the attack module is used to measure the attack effect of the attack module

[0084] under the attack strategy . ​Protected trajectory privacy loss , A city local search service quality loss and B city local search service quality loss to the protection module under the protection strategy .

[0085] The optimization objective function of trajectory privacy protection under the cross-region search service with limited service quality is: .

[0086] .

[0087] .

[0088] wherein, the network parameters of the fixed attack module , that is, the attack strategy , the protection module is trained to minimize the trajectory privacy loss . the network parameters of the fixed protection module , that is, the protection strategy , the attack module is trained to maximize the trajectory privacy loss . represents the average maximum service quality loss that the user can tolerate in the A city search service, represents the average maximum service quality loss that the user can tolerate in the B city search service.

[0089] at the same time depends on the attack process and the protection process . The threshold values and are multiplied by the user trajectory length to limit the deviation of the protection result.

[0090] Step 2 of the embodiment also includes training of the region discriminator and the true and false trajectory discriminator .

[0091] The region discriminator is trained using a binary cross-entropy loss function , and its expression is: .

[0092] wherein, represents the actual city label and the difference between the predicted city probability .

[0093] to the real and fake trajectory discriminator is trained using a binary cross-entropy loss function, which is expressed as: .

[0094] wherein, represents the actual trajectory real and fake label and the predicted trajectory real and fake probability .

[0095] In this embodiment, the process of training the cross-city user trajectory privacy protection model for dynamic adaptive attack is specifically: By punishing and the part that exceeds the limit, the quality loss of the local search service of the user in different cities is controlled respectively, and the optimization objective function with constraints, i.e., the trajectory privacy protection optimization objective function under the limited cross-regional search service, is converted into an optimization objective function without constraints, which is expressed as: .

[0096] wherein, and are penalty weights.

[0097] For the optimization objective function without constraints, an adversarial learning mechanism is introduced. First, the network parameters of the protection module are fixed, and the network parameters of the attack module are updated. By minimizing the expected loss of the attack module , the trajectory privacy loss is maximized, and then the network parameters of the optimized attack module under the current protection are obtained.

[0098] Then, the network parameters of the attack module are fixed, and the network parameters of the protection module are updated, so that the trajectory privacy loss of the cross-city user after being protected by the protection module is minimized. Based on the adversarial idea, the optimization and update of the network parameters of the protection module and the attack module are alternately performed to ensure the convergence of the model.

[0099] Then, the regional discriminator​ And true / false trajectory discriminator Trajectory feature encoder at location A respectively and the trajectory feature encoder at location B Optimization was performed. The final trained encoder for location A was obtained. The encoder for city B is used to encode the user trajectory matrix of city A. This is used to encode the user trajectory matrix in city B, resulting in a vector representation of the user's access preferences in different regions.

[0100] This invention employs adaptive moment estimation based on gradient descent to update and optimize network parameters, particularly for the protection module. and attack modules The network parameters are updated using an adaptive moment estimation method based on gradient descent.

[0101] When the quality of local search services is lost and Each remains within the constraint range and Within this range, while simultaneously achieving privacy protection of the trajectory. When minimizing, it is considered that and The value of tends to be optimal.

[0102] The optimal attack model is finally obtained. and the optimal protection model The cross-city user trajectory privacy protection model proposed in this invention, which is designed to withstand dynamic adaptive attacks, can provide trajectory privacy protection for users traveling between cities A and B.

[0103] Step 3. Use the trained cross-city user trajectory privacy protection model for dynamic adaptive attacks to protect the privacy of cross-city user trajectories.

[0104] In this embodiment, step 3 specifically involves: For cross-city users who use local search services simultaneously in both location A and location B Pre-set potential dynamic adaptive attack model Cross-city users Protected trans-city historical trails Cross-city users At any moment The actual access record is the current access record. Users across cities Maximum acceptable search radius As The fuzzy radius is preset for cross-city users. The average maximum service quality loss that can be tolerated in the search service in city A is , and the preset cross-city user The average maximum service quality loss that can be tolerated in the search service in city B is .

[0105] Solving an optimal protection model , for a cross-city user using an LBS service, i.e., a location-based service Generating an optimal access record, i.e., a protected current access record , so that when the cross-city user uses the search service, the optimal protection model can output an optimal fuzzy location , so that the fuzzy location is within the search radius of the real location.

[0106] The protected current access record and the protected cross-city historical trajectory are combined to form a new trajectory, which can resist a dynamic adaptive attack based on cross-city trajectory fusion , and can control the local search service quality loss in city A and the local search service quality loss in city B within the range that can be accepted by the cross-city user .

[0107] The cross-city dynamic adaptive trajectory inference attack of the present application can obtain a location service trajectory of a cross-city user, then input a real user trajectory, i.e., a real cross-city trajectory, into a publicly available protection framework, i.e., a protection application, to obtain a protected cross-city user trajectory, i.e., a protected cross-city trajectory, and form a protected cross-city trajectory-real cross-city trajectory pair to train a dynamic adaptive cross-city trajectory inference attack model, i.e., a dynamic adaptive attack model.

[0108] To resist dynamic adaptive attacks, the method of the present application needs to ensure that the input-output pair, i.e., the real cross-city trajectory-protected cross-city trajectory pair, can be accessed by potential attackers, and still provide effective cross-city trajectory privacy protection. Based on the concept of confrontation, the present application alternately optimizes the attack module and the protection module, and then obtains the optimal attack strategy based on cross-city trajectory fusion and the optimal protection strategy that can effectively resist this attack. This dynamic confrontation learning process enables the final protection module to minimize user trajectory privacy loss while ensuring that the quality loss of different services caused by protection is within the range that can be accepted by users when facing the attack based on multi-source trajectory fusion.

[0109] ​​​The model of the cross-city user trajectory privacy protection model facing dynamic adaptive attacks of the embodiment is shown in Figure 2, and the core of the model includes two parts, one is the dynamic adaptive attack structure part, that is, the attack module, and the other is the protection part of balancing trajectory privacy and service quality, that is, the protection module.

[0110] The attack effect of the attack module will be used to quantify the cross-city trajectory privacy protection effect of the protection module, so as to solve the quantification problem of cross-city user trajectory privacy. Meanwhile, the trajectory privacy feature fusion method with learnable weights is adopted to support the construction of the attack module and the protection module, and meet the needs of fully mining user privacy features in the cross-city market scene. In addition, the method of the present application also proposes different penalty functions for the service quality of different cities for separate control, and finally realizes the effective balance modeling between user trajectory privacy and service quality in the cross-city market scene.

[0111] The method of the present application can take into account the true and false nature of the trajectory before and after protection, realize the fusion representation of the user's access preference in the local city and the foreign city, and obtain the vector representation of the user's access preference in the latent semantic space by taking into account the access preference of the user in the local city and the foreign city, and weighting and fusing the local and foreign trajectory privacy features. The method of the present application also realizes the simulation of the attack and defense process between cross-city trajectory inference and trajectory privacy protection through the modeling of the generative adversarial network, fully utilizes the access records of the user in different cities to protect the global trajectory privacy of the user, and provides more comprehensive trajectory privacy protection for the cross-city traveling user based on the cross-city migration fused trajectory privacy features, while ensuring the search service quality and resisting cross-city trajectory inference.

[0112] Of course, the above description is only for the preferred embodiment of the present application, and the present application is not limited to the above-mentioned embodiments. It should be noted that any skilled person in the art can make all equivalent substitutions, obvious modifications and the like under the teaching of the present application, which all fall within the scope of the present application, and should be protected by the present application.

Claims

1. A cross-city user trajectory privacy protection method for dynamic adaptive attacks, characterized in that, The method comprises the following steps: Step 1. Building a cross-city user trajectory privacy protection model facing dynamic adaptive attacks, which comprises the following structure: a codec network for learning trajectory feature representations of users in different cities; a protection module comprising a pre-territorial trajectory feature fusion layer and an access record protection layer; the input of the pre-territorial trajectory feature fusion layer is the current access record and the protected cross-city historical trajectory, which is extracted by the codec network to obtain the pre-protected regional trajectory fusion feature based on a gating weighted fusion mechanism; the input of the access record protection layer is the pre-protected regional trajectory fusion feature, which is mapped based on a protection strategy to obtain the protected current access record; an attack module comprising a post-territorial trajectory feature fusion layer and a trajectory prediction layer; the input of the post-territorial trajectory feature fusion layer is the protected current access record and the protected cross-city historical trajectory, which is extracted by the codec network to obtain the post-protected regional trajectory fusion feature based on a gating weighted fusion mechanism; the input of the trajectory prediction layer is the post-protected regional trajectory fusion feature, which is mapped based on an attack strategy to obtain a guessed trajectory; Step 2. Introducing an adversarial learning mechanism between the protection module and the attack module, and combining a trajectory privacy loss and a service quality loss to construct an optimization objective function of trajectory privacy protection under a cross-territorial search service with limited service quality, and training the cross-city user trajectory privacy protection model facing dynamic adaptive attacks; Step 3. Using the trained cross-city user trajectory privacy protection model facing dynamic adaptive attacks to protect the cross-city user trajectory.

2. The method of claim 1, wherein, In the step 1, the codec network comprises a territory discriminator, an A-territory trajectory feature encoder, an A-territory trajectory feature decoder, a B-territory trajectory feature encoder, a B-territory trajectory feature decoder, and a real or fake trajectory discriminator; the territory discriminator is used to determine the city to which the trajectory belongs, and the city includes A-territory and B-territory; the A-territory trajectory feature encoder is used to extract the trajectory feature representation of the cross-city user in A-territory; the A-territory trajectory feature decoder is used to decode the trajectory feature representation of the cross-city user in A-territory to obtain the recovered trajectory of the cross-city user in A-territory; the B-territory trajectory feature encoder is used to extract the trajectory feature representation of the cross-city user in B-territory; the B-territory trajectory feature decoder is used to decode the trajectory feature representation of the cross-city user in B-territory to obtain the recovered trajectory of the cross-city user in B-territory; the real or fake trajectory discriminator is used to determine whether it is a recovered trajectory.

3. The method of claim 2, wherein, In the step 1, the processing procedure of signals in the codec network is as follows: An input to the codec network is an access record which includes a user A check-in record and a user B check-in record; Access records in input codec networks According to the regional identification bits of each position in the trajectory, the A-place trajectory matrix and the B-place trajectory matrix are extracted respectively, and the missing bits in and are filled with 0, wherein , , denotes the length of the trajectory, denotes the encoding length of the access record . obtaining the trajectory matrix of the A place inputting the trajectory feature encoder of the A place obtaining the vector representation of the user trajectory privacy feature in the high-dimensional space that is, the trajectory feature representation of the cross-city user in the A place ; by the A place trajectory feature decoder to obtain the recovered trajectory of the cross-city user in the A place; B-land trajectory matrix input B-land trajectory feature encoder obtain the vector representation of the user trajectory privacy feature in the high-dimensional space that is, the trajectory feature representation of the cross-city user in B-land ; Using the trajectory feature decoder at location B Decode the data to obtain the recovery trajectory of the cross-city user in location B; input the trajectory feature representation of the cross-city user in A place output by the A place trajectory feature encoder and the trajectory feature representation of the cross-city user in B place output by the B place trajectory feature encoder into the region discriminator to output a judgment result of the city to which the trajectory belongs ​ Access records in an input codec network , the recovered trajectory of the cross-city user in A place output by the trajectory feature decoder of A place, and the recovered trajectory of the cross-city user in B place output by the trajectory feature decoder of B place are respectively input into a true-false trajectory discriminator , the true-false trajectory discriminator outputs a judgment result of whether it is a recovered trajectory .

4. The method of claim 3, wherein, In the step 1, the gating weighted fusion mechanism is specifically as follows: Let denote the trajectory privacy feature of a cross-city user at A , Let denote the trajectory privacy feature of a cross-city user at B ; then the trajectory feature of a cross-city user at A and B is denoted as where ; Trajectory privacy features And The fused cross-city trajectory privacy features, i.e., regional trajectory fusion features, are obtained by using a weighted fusion method with variable weights. Variable weights By performing a matrix transformation on the input trajectory matrix and outputting a normalized weight probability distribution through a softmax layer, the specific process is represented as: ; wherein, , denotes a softmax layer, is a column vector of the trajectory matrix ; denotes a learnable parameter vector of length ; The specific process of the weight-variable weighted fusion is as follows: ; wherein, denotes a regional trajectory fusion feature.

5. The cross-city user trajectory privacy protection method against dynamic adaptive attacks according to claim 4, characterized in that, In the step 1, the signal is processed in the access record protection layer of the protection module The processing flow is shown as follows. ; wherein, represents a protected current access record, represents an access record protection layer network; To protect the pre-region trajectory fusion feature, it is obtained by fusing the current access record and the protected cross-city historical trajectory The input codec network extracts the pre-protected trajectory feature representation , and based on the variable weight, the gating weighted fusion mechanism is obtained ; wherein, represents a track matrix inputting an access record protection layer, a variable weight by performing matrix transformation on the track matrix , and then outputting a normalized weight probability distribution through a softmax layer; The signal is processed in the trajectory prediction layer of the attack module The processing flow is represented as: ; wherein, represents a guess trajectory, represents a trajectory prediction layer network; To protect the post-regional trajectory fusion feature, it is obtained by fusing the protected current access record and the protected cross-city historical trajectory The input codec network extracts the protected post-trajectory feature representation , and based on the variable weight, the gating weighted fusion mechanism is obtained ; wherein, represents the trajectory matrix of the input trajectory prediction layer, the variable weight The trajectory matrix is transformed by a matrix transformation and the normalized weight probability distribution is output by a softmax layer.

6. The cross-city user trajectory privacy protection method against dynamic adaptive attacks according to claim 5, characterized in that, In the step 2, the trajectory privacy loss and the service quality loss are specifically as follows: protection module and attack module organized in a mutual antagonistic relationship, forming a non-cooperative game about cross-city user trajectory privacy, the protection module and attack module The sum of information gains about cross-city user trajectory privacy is zero; Adopting an attack module Expected loss of Cross-city users After protection module Loss of trajectory privacy after protection That is ; Attack module The expected loss The calculation formula is: ; wherein, denotes the expected value, is the real trajectory of a cross-city user , and both contain access records; denotes the physical distance between the real trajectory and the guessed trajectory , which is measured by the mean squared error; respectively, the quality loss of the local search service in A , the quality loss of the local search service in B is quantified as ; ; wherein, , represents a real location of a cross-city user , represents a blurred location output by a protection module , represents a physical distance between the real location and the blurred location . service identification indicating the protected access record; when =0, the access record is for A-land search services, and when =1, the access record is for B-land search services.

7. The cross-city user trajectory privacy protection method against dynamic adaptive attacks according to claim 6, characterized in that, In the step 2, the process of constructing the optimization objective function of trajectory privacy protection under the cross-territorial search service with limited service quality is specifically as follows: Adopting an attack module The expected loss of the attack module Measuring the attack effect under the attack strategy ​ adopting cross-city users passing through a protection module privacy loss of the protected trajectory local search service quality loss of A local search service quality loss of B to the protection module measure the protection effect under the protection strategy ​ The optimization objective function of trajectory privacy protection under the cross-territorial search service with limited service quality is as follows: ; ; ; wherein, denote the network parameters of the fixed attack module i.e. the attack strategy , train the protection module to minimize the trajectory privacy loss ; denote the network parameters of the fixed protection module i.e. the protection strategy , train the attack module to maximize the trajectory privacy loss ; denote the average maximum service quality loss that the user can tolerate in the A-city search service, denote the average maximum service quality loss that the user can tolerate in the B-city search service.

8. The method of claim 7, wherein, The step 2 further comprises training the region discriminator and the real-fake trajectory discriminator ​ Geographical discriminator Using binary cross-entropy loss function Training is performed, expressed as: ; wherein, represents the difference between the actual city label and the predicted city probability ; Discriminating real and fake trajectories The training is performed using a binary cross-entropy loss function, expressed as: ; wherein, represents the difference between the actual trajectory true-false label and the predicted trajectory true-false probability .

9. The cross-city user trajectory privacy protection method against dynamic adaptive attacks according to claim 8, characterized in that, The step 2 is specifically a process of training a cross-city user trajectory privacy protection model facing a dynamic adaptive attack, and specifically comprises the following steps: By penalizing and The part of the additional limit is controlled by the user in different cities, respectively, the local search service quality loss, the optimization objective function with constraints, that is, the trajectory privacy protection optimization objective function under the service quality limited cross-regional search service, is converted into the optimization objective function without constraints, and its expression is: ; wherein and is a penalty weight; For unconstrained optimization objective functions, an adversarial learning mechanism is introduced, first fixing the protection module. Network parameters and attack modules Network parameters Update by minimizing the attack module. Expected loss This leads to a loss of trajectory privacy. Maximize, and thus obtain the current Optimized attack module under protection Network parameters; Then fix the network parameters of the attack module , and update the network parameters of the protection module , so that the trajectory privacy loss of the cross-city user after being protected by the protection module is minimized . Then the region discriminator is used and the real and fake trajectory discriminator are optimized respectively for the A-region trajectory feature encoder and the B-region trajectory feature encoder . Network parameters of the protection module and of the attack module are updated in an adaptive matrix estimation way based on gradient descent. when the local search service quality loss and are kept within the constraint range and respectively, and at the same time the trajectory privacy loss is minimized, then the values of and tend to be optimal; An optimized attack model is finally obtained and an optimized protection model .

10. The method of claim 9, wherein, The step 3 is specifically a process of training a cross-city user trajectory privacy protection model facing a dynamic adaptive attack, and specifically comprises the following steps: For cross-city users using local search services in A and B at the same time , preset potential dynamic adaptive attack model , cross-city users Protected cross-city historical trajectory , cross-city users Real access record at time , current access record ; The cross-city user The maximum search radius that can be accepted As The fuzzy radius of the cross-city user The average maximum service quality loss that can be tolerated in the A-city search service is The cross-city user The average maximum service quality loss that can be tolerated in the B-city search service is ; Solving an optimized protection model For cross-city users using LBS services Generating a protected current access record So that when cross-city users Use search services, the optimized protection model Can output a fuzzy location So that the fuzzy location Is within a search radius Of the real location Range; The protected current access record and the protected cross-city historical trajectory are combined into a new trajectory, which can resist dynamic adaptive attacks based on cross-city trajectory fusion , and can control the local search service quality loss of A place and the local search service quality loss of B place within the acceptable range of the cross-city user . and .

Citation Information

Patent Citations

  • Generative adversarial network track privacy protection method based on game strategy

    CN117874815A

  • Method, apparatus, and computer program product for anonymizing trajectories

    US20220394425A1