A cross-city user trajectory privacy protection method for dynamic adaptive attacks
The cross-city user trajectory privacy protection model built through adversarial learning mechanism solves the problems of service quality and trajectory preference changes in cross-city user trajectory privacy protection, and achieves effective protection under dynamic adaptive attacks.
Patent Information
- Application Number
- CN202511416140.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-09-30
- Publication Date
- 2026-01-27
- Estimated Expiration
- 2045-09-30
AI Technical Summary
Existing technologies struggle to balance the location service quality requirements and changes in user trajectory preferences across cities in protecting user trajectory privacy, and lack effective dynamic adaptive attack defense mechanisms.
A cross-city user trajectory privacy protection model is built using an adversarial learning mechanism, including an encoder-decoder network, a protection module, and an attack module. Through a gating weighted fusion mechanism and adversarial learning optimization, a balance between trajectory privacy and service quality is achieved.
It achieves effective protection of cross-city user trajectories under dynamic adaptive attacks, taking into account the service quality needs and user trajectory preferences of different cities, and provides comprehensive privacy protection.
Smart Images

Figure CN120915598B_ABST
Abstract
Description
Technical Field
[0001] This invention belongs to the field of privacy protection technology, specifically relating to a method for protecting the privacy of cross-city user trajectories in response to dynamic adaptive attacks. Background Technology
[0002] With the rapid development of mobile internet and location technology, users generate a large amount of fine-grained aggregated data during cross-city travel. Once this data is leaked, it can easily expose personal travel patterns and privacy. Cross-city trajectories often cover a user's residence, workplace, and travel destination, making them far more sensitive than single-city check-in data, thus requiring more urgent practical protection. However, in cross-city scenarios, there is currently no research on trajectory privacy protection against dynamic adaptive attacks under user preference migration patterns, which could lead to the misuse of trajectory data.
[0003] Current research on cross-city user behavior primarily focuses on location recommendation tasks. These tasks aim to migrate user access preferences from an information-rich source city to a target city, thereby alleviating the cold start problem. The core of these methods lies in connecting users' local access preferences with their preferences in different cities. To achieve preference migration, many existing methods assume a correlation between user access preferences in the source and target cities, and that this correlation is shared by all users.
[0004] Overall, cross-city user trajectory privacy protection faces two major challenges. First, users may require different quality of location services in different cities. While they may need slightly lower quality services in their familiar local cities, they often require higher quality services in unfamiliar cities. How to reconcile the different location service quality assurance needs of various cities in cross-city trajectory privacy protection mechanisms is a crucial issue that needs to be addressed. Second, users' trajectory preferences in different cities may change due to various privacy influences such as local customs and travel purposes. How to balance and integrate users' trajectory preferences in different cities to better design protection schemes is also a key issue that needs to be resolved. Summary of the Invention
[0005] The purpose of this invention is to propose a cross-city user trajectory privacy protection method for dynamic adaptive attacks. This method simulates an attack-defense game through an adversarial learning mechanism to achieve alternating optimization of the attack strategy of the attack module and the protection strategy of the protection module, thereby obtaining a cross-city user trajectory privacy protection model for dynamic adaptive attacks that effectively balances user trajectory privacy and service quality in multiple cities.
[0006] To achieve the above objectives, the present invention adopts the following technical solution:
[0007] A method for protecting the privacy of cross-city user trajectories in response to dynamic adaptive attacks includes the following steps:
[0008] Step 1. Construct a cross-city user trajectory privacy protection model for dynamic adaptive attacks, which includes the following structure:
[0009] A codec network is used to learn the trajectory feature representations of users in different cities;
[0010] The protection module includes a front-end regional trajectory feature fusion layer and an access record protection layer;
[0011] The input to the pre-protection regional trajectory feature fusion layer is the current access record and the protected cross-city historical trajectory. The pre-protection trajectory feature representation is extracted by the encoder-decoder network, and then the pre-protection regional trajectory fusion feature is obtained based on the gated weighted fusion mechanism.
[0012] The input to the access record protection layer is the regional trajectory fusion feature before protection, which is mapped based on the protection strategy to obtain the current access record after protection;
[0013] The attack module includes a post-regional trajectory feature fusion layer and a trajectory prediction layer;
[0014] The input to the post-regional trajectory feature fusion layer is the protected current access record and the protected cross-city historical trajectory. The protected trajectory feature representation is extracted by the encoder-decoder network, and then the protected regional trajectory fusion feature is obtained based on the gated weighted fusion mechanism.
[0015] The input to the trajectory prediction layer is the protected regional trajectory fusion feature, which is mapped based on the attack strategy to obtain the guessed trajectory.
[0016] Step 2. Introduce an adversarial learning mechanism between the protection module and the attack module, and construct an optimization objective function for trajectory privacy protection under cross-regional search services with limited service quality by combining trajectory privacy loss and service quality loss, and train a cross-city user trajectory privacy protection model for dynamic adaptive attacks.
[0017] Step 3. Use the trained cross-city user trajectory privacy protection model for dynamic adaptive attacks to protect the privacy of cross-city user trajectories.
[0018] The present invention has the following advantages:
[0019] As described above, this invention discloses a method for protecting cross-city user trajectory privacy against dynamic adaptive attacks. The method constructs a cross-city user trajectory privacy protection model for dynamic adaptive attacks, the core of which includes a dynamic adaptive attack structure (attack module) and a protection module that balances trajectory privacy and service quality. The attack effect of the attack module is used to quantify the protection effect of the protection module on cross-city trajectory privacy, thus solving the quantification problem of cross-city user trajectory privacy. Simultaneously, this invention employs a learnable weighted gating weighted fusion mechanism to achieve trajectory privacy feature fusion, supporting the construction of the attack and protection modules and meeting the need for full mining of user privacy features in cross-city scenarios. Furthermore, this invention proposes different penalty functions to control the service quality of different cities separately, ultimately achieving an effective balance modeling between user trajectory privacy and service quality in cross-city scenarios. This invention can take into account users' access preferences in both local and remote cities, obtaining a vector representation of user access preferences in the latent semantic space through weighted fusion of local and remote trajectory privacy features. Based on the trajectory privacy features of cross-city migration fusion, this invention can provide more comprehensive trajectory privacy protection for users traveling across cities, while ensuring the quality of search services and resisting cross-city trajectory inference. Attached Figure Description
[0020] Figure 1 This is a flowchart of a cross-city user trajectory privacy protection method for dynamic adaptive attacks in an embodiment of the present invention.
[0021] Figure 2 This is a model architecture diagram of a cross-city user trajectory privacy protection model for dynamic adaptive attacks in an embodiment of the present invention.
[0022] Figure 3 for Figure 2 A magnified view of a portion of region II in the middle.
[0023] Figure 4 for Figure 2 A magnified view of a portion of region I.
[0024] Figure 5 This is a schematic diagram of the codec network structure in an embodiment of the present invention. Detailed Implementation
[0025] The present invention will be further described in detail below with reference to the accompanying drawings and specific embodiments:
[0026] Example 1
[0027] Existing solutions face two main challenges in protecting user trajectory privacy across cities. First, users may require different quality of location services in different cities, necessitating compatibility with the location service quality assurance needs of different cities. Second, users' trajectory preferences in different cities may change due to various privacy factors such as local customs and travel purposes, and there is a lack of suitable solutions on how to take into account and integrate users' trajectory preferences in different cities to better design protection schemes.
[0028] To address the aforementioned issues, this invention presents a method for protecting the privacy of cross-city user trajectories against dynamic adaptive attacks, designed for location-based social network users traveling across cities, in order to achieve cross-city trajectory privacy embedding and cross-city trajectory privacy feature fusion.
[0029] This invention designs a unified cross-city protection mechanism based on the adversarial concept to achieve a balance between trajectory privacy and service quality in different cities. It proposes a cross-city user trajectory privacy protection model oriented towards dynamic adaptive attacks, comprising two components: a protection module and an attack module. First, the protection module extracts user trajectory features from different cities and designs a pre-protection regional trajectory feature fusion layer based on gated weighted fusion to obtain pre-protection regional trajectory fusion features to support privacy protection for current access records. Second, the protected current access record and the protected cross-city historical trajectory are concatenated to obtain the protected user cross-city trajectory, which is then analyzed using the attack module. The attack module uses a post-protection regional trajectory feature fusion layer to obtain the user's post-protection regional trajectory fusion features in different cities, and then reconstructs and restores the cross-city trajectory through a trajectory prediction layer, outputting the guessed access record and the guessed trajectory. Finally, an adversarial learning mechanism is introduced between the protection module and the attack module to simulate the attack and defense game. Through alternating optimization of parameters, the attack strategy and protection strategy are alternately optimized, thus obtaining a cross-city user trajectory privacy protection model that effectively balances user trajectory privacy and service quality in multiple cities and is oriented towards dynamic adaptive attacks.
[0030] The following section will first introduce dynamic adaptive inference attacks based on cross-city trajectory fusion.
[0031] This invention targets attackers who can obtain cross-city trajectories generated by the same user using location services in different cities. Furthermore, attackers can leverage publicly available protected applications to train a dynamic adaptive attack model, i.e., a cross-city attack model.
[0032] Specifically, for protection applications Attackers input real user trajectories (real cross-city trajectories) and can obtain corresponding protected cross-city trajectories. These protected cross-city trajectory-real cross-city trajectory pairs are then used to train a dynamic adaptive attack model. For protected user cross-city trajectories, attackers know access record information including fuzzy latitude and longitude coordinates.
[0033] During training, for cross-city attack models Preset users After protection application The protected cross-city trajectory segments are Cross-city attack model The goal is to protect applications through learning. The mechanism and structure are used to improve guessing ability, and the specific process is defined as follows:
[0034] ).
[0035] in, For cross-city attack model The output is the guessed trajectory. and All contain One access record. For cross-city attack model The parameter set, i.e., the cross-city attack model The attack strategy. The process of generating a hypothetical trajectory for a cross-city attack model.
[0036] Then, the cross-city trajectory privacy protection framework based on adversarial learning of this invention will be introduced.
[0037] To defend against dynamic adaptive attacks targeting cross-city search trajectory privacy, this invention proposes a user trajectory privacy protection framework based on an adversarial approach, establishing a cross-city user trajectory privacy protection model resistant to dynamic adaptive attacks. This protection framework consists of a cross-city trajectory privacy protection module, referred to as the protection module. The cross-city trajectory inference attack module is referred to as the attack module. The system is structured to simulate both protective applications and potential attacks during the attack and defense process, using protection and attack modules respectively. A dynamically adaptive attack module is introduced. Dynamic adversarial training yields the optimal protection module, enabling users to minimize trajectory privacy loss when facing maximum attacks, and within the protection module... In order to ensure the controllability of the loss of utility, i.e. the loss of service quality, caused by location ambiguity.
[0038] This invention will protect the module Defined as a real access record and protected access logs The random mapping between them, this specific process is expressed as:
[0039] .
[0040] in, Indicates cross-city users Protected historical sites refer to protected historical sites spanning multiple cities. contain One access record. express The actual access information at the current moment is the current access record. This refers to the protected current access record. This refers to the parameter settings of the protection module, i.e., the protection strategy.
[0041] Protection module It will output a blurry position. , Indicates protection module The process of generating a fuzzy position.
[0042] At the same time, the attack module Defined as a by and Fuzzy trajectory pieced together and guessed trajectory A random mapping between them, and it is represented as:
[0043] .
[0044] in, Indicates attack module The parameter settings constitute the attack strategy. Guessing the trajectory. contain One access record. Indicates attack module The process of generating a guessed trajectory.
[0045] The following section provides a detailed description of the cross-city user trajectory privacy protection method for dynamic adaptive attacks.
[0046] like Figure 1 As shown, the method for protecting the privacy of cross-city user trajectories against dynamic adaptive attacks includes the following steps:
[0047] Step 1. Build a cross-city user trajectory privacy protection model for dynamic adaptive attacks, which includes a codec network, a protection module, and an attack module.
[0048] The encoder-decoder network is used to learn the trajectory feature representations of users in different cities.
[0049] Codec network details are as follows Figure 5 As shown, the encoder-decoder network includes a region discriminator, a trajectory feature encoder for region A, a trajectory feature decoder for region A, a trajectory feature encoder for region B, a trajectory feature decoder for region B, and a true / false trajectory discriminator.
[0050] The region discriminator is used to determine the city to which the trajectory belongs, which includes city A and city B.
[0051] The A-location trajectory feature encoder is used to extract the trajectory feature representation of cross-city users in location A based on their check-in records in location A.
[0052] The A-location trajectory feature decoder is used to decode the trajectory feature representation of cross-city users in location A, and obtain the restored trajectory of cross-city users in location A, i.e., the restored check-in record in location A.
[0053] The B-location trajectory feature encoder is used to extract the trajectory feature representation of cross-city users in location B based on their check-in records in location B.
[0054] The B-location trajectory feature decoder is used to decode the trajectory feature representation of cross-city users in location B, and obtain the restored trajectory of cross-city users in location B, i.e., the restored check-in record in location B.
[0055] The true / false trajectory discriminator is used to determine whether a trajectory is being recovered.
[0056] The signal processing flow in the codec network is as follows:
[0057] The input to the codec network is access records. This includes check-in records for user A and check-in records for user B.
[0058] Access records in the input codec network Based on the geographic identifier of each location in the trajectory, the trajectory matrix of location A is extracted. and trajectory matrix of location B and will and Missing positions are filled with 0s, where , , Indicates the length of the trajectory. Indicates access records The encoding length.
[0059] The trajectory matrix of location A Input A trajectory feature encoder This yields the vector representation of user trajectory privacy features in a high-dimensional space. That is, the trajectory characteristics of cross-city users in location A:
[0060] .
[0061] Using the trajectory feature decoder at location A Decode the data to obtain the recovery trajectory of the cross-city user in location A.
[0062] The trajectory matrix at location B Input B location trajectory feature encoder This yields the vector representation of user trajectory privacy features in a high-dimensional space. That is, the trajectory characteristics of cross-city users in location B:
[0063] .
[0064] Using the trajectory feature decoder at location B Decode the data to obtain the recovery trajectory of the cross-city user in location B.
[0065] The codec network is used to support cross-city trajectory privacy representation learning for protection and attack modules.
[0066] When the decoder network is used to support the learning of cross-city trajectory privacy representations for the protection module, the access records input to the codec network include the current access records and the protected cross-city historical trajectories. These are processed by the codec network for feature extraction, and its output is the pre-protection trajectory feature representation. Conversely, when the decoder network is used to support the learning of cross-city trajectory privacy representations for the attack module, the access records input to the codec network include the protected current access records and the protected cross-city historical trajectories. These are processed by the codec network for feature extraction, and its output is the post-protection trajectory feature representation.
[0067] Taking the protection module as an example, the method of this invention will record each access record. The data is vectorized based on inherent attributes such as latitude and longitude. On this basis, the actual access record, i.e., the current access record, is then... The encoding and the user's previous A protected historical trajectory is a cross-city historical trajectory that has been protected. Forming the input matrix Furthermore, based on the geographical identifier of each location in the trajectory, the trajectory matrices for locations A and B are extracted respectively. The trajectory matrix for location A in the protection module is denoted as... The trajectory matrix of location B in the protection module is denoted as ,in , Missing bits are padded with 0s. After input embedding, the method of this invention employs two independent, pre-trained encoder networks. and This is used to extract trajectory features, thereby obtaining the trajectory feature representation before protection.
[0068] When the decoder network supports the cross-city trajectory privacy representation learning of the attack module, the access records to the input codec network include protected current access records and protected cross-city historical trajectories. Similarly, it is necessary to extract the trajectory matrices for location A and location B. The trajectory matrix for location A in the attack module is denoted as... The trajectory matrix of location B in the attack module is denoted as ,in , Missing bits are padded with 0s, and then passed through the encoder network. and To extract trajectory features, and then obtain the protected trajectory feature representation.
[0069] Encoder Network and This invention is a neural network trained together with a protection module and an attack module. It utilizes an automatic encoder-decoder to learn the trajectory feature representations of users in different cities, and employs a regional discriminator. And true / false trajectory discriminator For encoder networks and The encoding quality is monitored. Among these, the regional discriminator... Used to determine the city to which a trajectory belongs, taking the extraction of user trajectory features in two cities, A and B, as an example, the regional discriminator... It will determine whether the trajectory belongs to city A or city B. The true / false trajectory discriminator... This is used to distinguish between the actual trajectory and the recovered trajectory.
[0070] Specifically, the trajectory feature representations of cross-city users in location A (output from the trajectory feature encoder in location A) and the trajectory feature representations of cross-city users in location B (output from the trajectory feature encoder in location B) are input into the geographic discriminator. By the region discriminator The output determines the city to which the trajectory belongs. In this embodiment, the region discriminator... A two-layer multilayer perceptron (MLP) is preferred for distinguishing the city to which a trajectory belongs, and its output is the predicted city probability. .
[0071] Access records in the input codec network Extracted trajectory matrix of location A and trajectory matrix of location B The recovered trajectories of cross-city users in city A (output from the trajectory feature decoder at city A) and the recovered trajectories of cross-city users in city B (output from the trajectory feature decoder at city B) are respectively input into the true / false trajectory discriminator. The true / false trajectory discriminator The output determines whether the trajectory is recovered. In this embodiment, the true / false trajectory discriminator... A two-layer multilayer perceptron (MLP) is preferred for distinguishing between real and false trajectories, and its output is the probability of predicting whether a trajectory is real or false. .
[0072] The protection module includes a front-end regional trajectory feature fusion layer and an access record protection layer.
[0073] like Figure 4 As shown, the inputs to the protection module are the protected historical check-in records and actual access records. The actual access records are the current access records. Protected historical check-in routes are protected cross-city historical routes. This includes protected local check-in records and protected remote check-in records. The output of the protection module is the protected access record, which is the protected current access record. .
[0074] The input to the pre-protection regional trajectory feature fusion layer is the current access record and the protected cross-city historical trajectory. The pre-protection trajectory feature representation is extracted by the encoder-decoder network, and then the pre-protection regional trajectory fusion feature is obtained based on the gating weighted fusion mechanism.
[0075] This embodiment achieves cross-city trajectory privacy feature fusion based on a learnable weighted gating fusion mechanism. The gating weighted fusion mechanism is described in detail below:
[0076] Will Record the privacy features of cross-city users' travel routes in location A ,Will Record the privacy features of cross-city users' travel routes in location B The trajectory characteristics of cross-city users in locations A and B are then represented as follows: ,in .
[0077] Track privacy features and A weighted fusion method with variable weights is used to obtain the fused cross-city trajectory privacy features, i.e., the regional trajectory fusion features. Specifically, feature fusion is performed in the pre-protection regional trajectory feature fusion layer of the protection module to obtain the pre-protection regional trajectory fusion features, and feature fusion is performed in the post-protection regional trajectory feature fusion layer of the attack module to obtain the post-protection regional trajectory fusion features.
[0078] Variable weights By analyzing the input trajectory matrix The matrix transformation is performed, and then the normalized weight probability distribution is obtained through the softmax layer. The specific process is as follows:
[0079] .
[0080] in, Used to indicate the city where the record currently to be protected is located. , Indicates a softmax layer. Trajectory matrix Column vectors. This represents a learnable parameter vector with length . .
[0081] For each city, there are local and out-of-town trajectories. Therefore, the trajectory matrix for local and out-of-town locations... Each privacy feature represents Each corresponds to a learnable weight. This is used for weighted fusion, and the specific process of weighted fusion with variable weights is expressed as follows:
[0082] .
[0083] in, This represents the regional trajectory fusion characteristics. The above process ultimately yields regional trajectory fusion characteristics, which can be used to further support the protection module in carrying out protection work.
[0084] The input to the access record protection layer is the regional trajectory fusion feature before protection, which is mapped based on the protection strategy to obtain the current access record after protection.
[0085] Signal in protection module The processing flow in the access record protection layer is represented as follows:
[0086] .
[0087] in, This indicates the current access record that has been protected. This refers to the access record protection layer network, whose core architecture is a general time series decoding network, including but not limited to RNN, LSTM, GRU, and Transformer encoders.
[0088] To protect the pre-regional trajectory fusion features, it uses the current access record and protected trans-city historical sites Input codec network extracts pre-protection trajectory feature representation And based on variable weights The gating weighted fusion mechanism was obtained.
[0089] in, Represents the trajectory matrix of the input access record protection layer, with variable weights. By analyzing the trajectory matrix The matrix is transformed, and then the normalized weight probability distribution is obtained by passing it through a softmax layer.
[0090] The attack module includes a post-regional trajectory feature fusion layer and a trajectory prediction layer.
[0091] like Figure 3 As shown, the input to the attack module is a protected trajectory, which includes a protected current access log. and protected trans-city historical sites The protected cross-city historical trajectory also includes protected local check-in records and protected remote check-in records. The attack module's output is a guessed trajectory, which includes... A guessed access record.
[0092] The input to the post-regional trajectory feature fusion layer is the protected current access record and the protected cross-city historical trajectory. The protected trajectory feature representation is extracted by the encoder-decoder network, and then the protected regional trajectory fusion feature is obtained based on the gated weighted fusion mechanism.
[0093] The input to the trajectory prediction layer is the protected regional trajectory fusion feature, which is mapped based on the attack strategy to obtain the guessed trajectory.
[0094] After being protected and utilizing the regional trajectory fusion features, the attack module infers the original trajectory information through a trajectory prediction layer network. The signal then passes through the attack module. The processing flow in the trajectory prediction layer is represented as follows:
[0095] .
[0096] in, This indicates a guess about the trajectory. This refers to the trajectory prediction layer network, whose core architecture is a general time series decoding network, including but not limited to RNN, LSTM, GRU, and Transformer encoders.
[0097] To protect post-regional trajectory fusion features, it uses protected current access records. and protected trans-city historical sites Input codec network extracts protected trajectory feature representation And based on variable weights The gating weighted fusion mechanism was obtained.
[0098] in, Represents the trajectory matrix of the input trajectory prediction layer, with variable weights. By analyzing the trajectory matrix The matrix is transformed, and then the normalized weight probability distribution is obtained by passing it through a softmax layer.
[0099] Step 2. Introduce an adversarial learning mechanism between the protection module and the attack module, and construct an optimization objective function for trajectory privacy protection under cross-regional search services with limited service quality by combining trajectory privacy loss and service quality loss, and train a cross-city user trajectory privacy protection model for dynamic adaptive attacks.
[0100] The method of this invention designs trajectory privacy loss and service quality loss to quantify cross-city trajectory privacy and cross-city service quality. Specifically, the trajectory privacy loss and service quality loss are as follows:
[0101] In the cross-city trajectory privacy protection framework, the protection module and attack modules Organized together in a mutually antagonistic relationship, forming a framework for cross-city users. Non-cooperative game theory for trajectory privacy, protection module and attack modules The total benefit of protecting user location privacy across cities is zero, i.e., the protection module... The information being protected is also an attack module. Information that could not be guessed.
[0102] Therefore, this invention employs an attack module. Expected loss To measure cross-city users After protection module Loss of privacy due to protected trajectory ,Right now To define the attack module Expected loss This invention, from the attacker's perspective, naturally proposes an ideal guessing trajectory. It should be as close as possible to the user's actual trajectory in geographic space. Therefore, attack module Expected loss The calculation formula is:
[0103] .
[0104] in, Indicates the expected value. For cross-city users The true trajectory and All contain One access record. Represents the true trajectory and guessing the trajectory The physical distance between them. This invention introduces mean square error to measure the true trajectory. and guessing the trajectory The physical distance between modules is used to achieve rapid convergence of module parameters during training.
[0105] To balance trajectory privacy and quality loss between search services in different cities, this invention addresses the quality loss of local search services in location A. Loss of local search service quality in location B Quantified, expressed as:
[0106] .
[0107] .
[0108] in, , Indicates cross-city users The true location Indicates protection module The output fuzzy position, Indicates the actual location and fuzzy position The physical distance between them.
[0109] Indicates the first A service identifier for a protected access record. When When =0, Access records for the search service in location A, when When =1, Access records for the search service in location B.
[0110] In this embodiment, a balancing mechanism between cross-city trajectory privacy and multi-city service quality is also designed. The process of constructing the trajectory privacy protection optimization objective function under cross-regional search services with limited service quality is as follows:
[0111] The method of this invention simultaneously learns the optimal cross-city trajectory privacy protection strategy. Cross-city trajectory inference attack strategy And use loss functions to respectively and The effectiveness of the strategy is controlled.
[0112] Using attack modules Expected loss To measure the attack module In attack strategy The attack effect.
[0113] Adopt cross-city users After protection module Loss of privacy due to protected trajectory Loss of local search service quality in location A Loss of local search service quality in location B For protection module In protection strategy The effectiveness of protection under these conditions is measured.
[0114] The objective function for optimizing trajectory privacy protection in cross-regional search services with limited service quality is:
[0115] .
[0116] .
[0117] .
[0118] in, Indicates fixed attack module Network parameters, i.e., attack strategies Training protection module Loss of trajectory privacy minimize. Indicates fixed protection module Network parameters, i.e., protection policies Training attack module Loss of trajectory privacy maximize. This represents the average maximum quality of service loss that a user can tolerate in the search service for city A. This represents the average maximum service quality loss that users can tolerate in the search service in city B.
[0119] Simultaneously dependent on the attack process and protection process Threshold and With user trajectory length Multiplication is used to limit the deviation of the protection result.
[0120] Step 2 of this embodiment also includes a region discriminator. And true / false trajectory discriminator The training conducted.
[0121] Regional discriminator Using a binary cross-entropy loss function The expression for training is:
[0122] .
[0123] in, Indicates the actual city label and predicting city probability The differences between them.
[0124] True / False Trajectory Discriminator The binary cross-entropy loss function is used for training, and its expression is:
[0125] .
[0126] in, Indicates whether the actual trajectory is real or fake. And the probability of true or false prediction of trajectory The differences between them.
[0127] In this embodiment, the process of training the cross-city user trajectory privacy protection model for dynamic adaptive attacks is as follows:
[0128] Through punishment and For the portion exceeding the limit, the loss in local search service quality for users in different cities is controlled. The constrained optimization objective, i.e., the trajectory privacy protection optimization objective function under cross-regional search service with limited service quality, is transformed into an unconstrained optimization objective function, the expression of which is:
[0129] .
[0130] in, and For penalty weights.
[0131] For unconstrained optimization objective functions, an adversarial learning mechanism is introduced, first fixing the protection module. Network parameters and attack modules Network parameters Update by minimizing the attack module. Expected loss This leads to a loss of trajectory privacy. Maximize, and thus obtain the current Optimized attack module under protection Network parameters.
[0132] Then fix the attack module The network parameters, and the protection module The network parameters are updated to allow cross-city users to access the network. After protection module Loss of privacy due to protected trajectory Minimize. Alternately protect modules based on an adversarial approach. and attack modules Optimizing and updating network parameters ensures model convergence.
[0133] Then, the region discriminator is used. And true / false trajectory discriminator Trajectory feature encoder at location A respectively and the trajectory feature encoder at location B Optimization was performed. The final trained encoder for location A was obtained. The encoder for city B is used to encode the user trajectory matrix of city A. This is used to encode the user trajectory matrix in city B, resulting in a vector representation of the user's access preferences in different regions.
[0134] This invention employs adaptive moment estimation based on gradient descent to update and optimize network parameters, particularly for the protection module. and attack modules The network parameters are updated using an adaptive moment estimation method based on gradient descent.
[0135] When the quality of local search services is lost and Each remains within the constraint range and Within this range, while simultaneously achieving privacy protection of the trajectory. When minimizing, it is considered that and The value of tends to be optimal.
[0136] The optimal attack model is finally obtained. and the optimal protection model The cross-city user trajectory privacy protection model proposed in this invention, which is designed to withstand dynamic adaptive attacks, can provide trajectory privacy protection for users traveling between cities A and B.
[0137] Step 3. Use the trained cross-city user trajectory privacy protection model for dynamic adaptive attacks to protect the privacy of cross-city user trajectories.
[0138] In this embodiment, step 3 specifically involves:
[0139] For cross-city users who use local search services simultaneously in both location A and location B Pre-set potential dynamic adaptive attack model Cross-city users Protected trans-city historical trails Cross-city users At any moment The actual access record is the current access record. Users across cities Maximum acceptable search radius As The fuzzy radius is preset for cross-city users. The maximum tolerable average quality of service loss in the search service of city A is: Preset cross-city users The maximum tolerable average quality of service loss in the search service of City B is .
[0140] Solve for an optimal protection model. For cross-city users using LBS services, i.e., location-based services Generate an optimal access record, i.e., a protected current access record. This makes it possible for users in different cities to... When using search services, the optimal protection model It can output an optimal fuzzy position. This makes the position ambiguous. In real location search radius Within the range.
[0141] A new trajectory is created by combining protected current access records and protected cross-city historical trajectories. This new trajectory can resist dynamic adaptive attacks based on cross-city trajectory fusion. It can also control the quality loss of local search services in location A and location B for cross-city users. acceptable range and Inside.
[0142] The cross-city dynamic adaptive trajectory inference attack targeted by this invention can obtain the location service trajectory of cross-city users, and then input the real user trajectory, i.e. the real cross-city trajectory, into a publicly available protection framework, i.e., a protection application, to obtain the protected cross-city user trajectory, i.e. the protected cross-city trajectory. This protected cross-city trajectory-real cross-city trajectory pair is used to train the dynamic adaptive cross-city trajectory inference attack model, i.e., the dynamic adaptive attack model.
[0143] To defend against dynamic adaptive attacks, the method of this invention must ensure effective cross-city trajectory privacy protection even when the input-output pair (i.e., the real cross-city trajectory - the protected cross-city trajectory pair) is accessible to potential attackers. Based on an adversarial approach, this invention alternately optimizes the attack module and the protection module to obtain the optimal attack strategy based on cross-city trajectory fusion and the optimal protection strategy that effectively resists such attacks. This dynamic adversarial learning process enables the final protection module to minimize user trajectory privacy loss even when facing attacks that maximize multi-source trajectory fusion, while ensuring that the quality loss of different services caused by protection remains within an acceptable range for the user.
[0144] The model of the cross-city user trajectory privacy protection model for dynamic adaptive attacks in this embodiment is shown in Figure 2. The core of the model includes two parts: one is the dynamic adaptive attack structure part, i.e., the attack module, and the other is the protection part that balances trajectory privacy and service quality, i.e., the protection module.
[0145] The attack effect of the attack module will be used to quantify the cross-city trajectory privacy protection effect of the protection module, thereby solving the problem of quantifying user trajectory privacy across cities. Simultaneously, this invention employs a weighted, learnable trajectory privacy feature fusion method to support the construction of both the attack and protection modules, meeting the need for full mining of user privacy features in cross-city scenarios. Furthermore, this invention proposes different penalty functions for the service quality of different cities for separate control, ultimately achieving an effective balance modeling between user trajectory privacy and service quality in cross-city scenarios.
[0146] This invention's method can balance the authenticity of trajectory data before and after protection, achieving a fusion representation of user access preferences in both local and out-of-city locations. By considering user access preferences in both local and out-of-city locations, a weighted fusion of local and out-of-city trajectory privacy features yields a vector representation of user access preferences in the latent semantic space. Furthermore, this invention uses generative adversarial network modeling to simulate the attack and defense process between cross-city trajectory inference and trajectory privacy protection. It fully utilizes user access records in different cities to protect global trajectory privacy, and based on trajectory privacy features fused from cross-city migration, it provides more comprehensive trajectory privacy protection for users traveling across cities, ensuring search service quality while resisting cross-city trajectory inference.
[0147] Of course, the above description is only a preferred embodiment of the present invention. The present invention is not limited to the above-described embodiments. It should be noted that any equivalent substitutions or obvious modifications made by those skilled in the art under the guidance of this specification fall within the scope of this specification and should be protected by the present invention.
Claims
1. A method for protecting cross-city user trajectory privacy against dynamic adaptive attacks, characterized in that, Includes the following steps: Step 1. Construct a cross-city user trajectory privacy protection model for dynamic adaptive attacks, which includes the following structure: A codec network is used to learn the trajectory feature representations of users in different cities; The encoder-decoder network includes a region discriminator and a trajectory feature encoder for location A. A location trajectory feature decoder, B location trajectory feature encoder B-location trajectory feature decoder and true / false trajectory discriminator; The region discriminator is used to determine the city to which the trajectory belongs, including cities A and B. A-location trajectory feature encoder and the trajectory feature encoder at location B. Independent, pre-trained encoder networks are used respectively. and To extract trajectory features; The trajectory feature representations of cross-city users in location A (output from the trajectory feature encoder in location A) and the trajectory feature representations of cross-city users in location B (output from the trajectory feature encoder in location B) are input into the region discriminator. By the region discriminator Output the result indicating the city to which the trajectory belongs; Access records in the input codec network The recovered trajectories of cross-city users in city A (output from the trajectory feature decoder at city A) and the recovered trajectories of cross-city users in city B (output from the trajectory feature decoder at city B) are respectively input into the true / false trajectory discriminator. The true / false trajectory discriminator Output the result of whether the trajectory is recovered; The true / false trajectory discriminator is used to determine whether a trajectory is being recovered. The protection module includes a front-end regional trajectory feature fusion layer and an access record protection layer; The input to the pre-protection regional trajectory feature fusion layer is the current access record and the protected cross-city historical trajectory. The pre-protection trajectory feature representation is extracted by the encoder-decoder network, and then the pre-protection regional trajectory fusion feature is obtained based on the gated weighted fusion mechanism. The input to the access record protection layer is the regional trajectory fusion feature before protection, which is mapped based on the protection strategy to obtain the current access record after protection; The attack module includes a post-regional trajectory feature fusion layer and a trajectory prediction layer; The input to the post-regional trajectory feature fusion layer is the protected current access record and the protected cross-city historical trajectory. The protected trajectory feature representation is extracted by the encoder-decoder network, and then the protected regional trajectory fusion feature is obtained based on the gated weighted fusion mechanism. The input to the trajectory prediction layer is the protected regional trajectory fusion feature, which is mapped based on the attack strategy to obtain the guessed trajectory. Step 2. Introduce an adversarial learning mechanism between the protection module and the attack module, and construct an optimization objective function for trajectory privacy protection under cross-regional search services with limited service quality by combining trajectory privacy loss and service quality loss, and train a cross-city user trajectory privacy protection model for dynamic adaptive attacks. Step 3. Use the trained cross-city user trajectory privacy protection model for dynamic adaptive attacks to protect the privacy of cross-city user trajectories; The specific gating weighted fusion mechanism is as follows: Will Record the privacy features of cross-city users' travel routes in location A ,Will Record the privacy features of cross-city users' travel routes in location B ,in Represents the trajectory matrix of location A. Let B be the trajectory matrix; then the trajectory characteristics of cross-city users in locations A and B are represented as follows: ,in ; Track privacy features and The cross-city trajectory privacy features, i.e., the regional trajectory fusion features, are obtained by using a weighted fusion method with variable weights.
2. The method for protecting cross-city user trajectory privacy against dynamic adaptive attacks according to claim 1, characterized in that, In step 1, the trajectory feature encoder at location A is used to extract the trajectory feature representation of cross-city users in location A; The A-location trajectory feature decoder is used to decode the trajectory feature representation of cross-city users in location A, and obtain the recovered trajectory of cross-city users in location A; The B-location trajectory feature encoder is used to extract the trajectory feature representation of cross-city users in location B; The B-location trajectory feature decoder is used to decode the trajectory feature representation of cross-city users in location B, and obtain the recovered trajectory of cross-city users in location B.
3. The method for protecting cross-city user trajectory privacy against dynamic adaptive attacks according to claim 2, characterized in that, In step 1, the signal processing flow in the codec network is as follows: The input to the codec network is access records. This includes check-in records for user A and check-in records for user B; Access records in the input codec network Based on the geographic identifier of each location in the trajectory, the trajectory matrix of location A is extracted. and trajectory matrix of location B and will and Missing positions are filled with 0s, where , , Indicates the length of the trajectory. Indicates access records The encoding length; The trajectory matrix of location A Input A trajectory feature encoder This yields the vector representation of user trajectory privacy features in a high-dimensional space. That is, the trajectory characteristics of cross-city users in location A: ; Using the trajectory feature decoder at location A Decode the data to obtain the recovery trajectory of the cross-city user in location A; The trajectory matrix at location B Input B location trajectory feature encoder This yields the vector representation of user trajectory privacy features in a high-dimensional space. That is, the trajectory characteristics of cross-city users in location B: ; Using the trajectory feature decoder at location B Decode the data to obtain the recovery trajectory of the cross-city user in location B.
4. The method for protecting cross-city user trajectory privacy against dynamic adaptive attacks according to claim 3, characterized in that, In step 1, the gated weighted fusion mechanism specifically refers to: Variable weights By analyzing the input trajectory matrix The matrix transformation is performed, and then the normalized weight probability distribution is obtained through the softmax layer. The specific process is as follows: ; in, , Indicates a softmax layer. Trajectory matrix Column vectors; This represents a learnable parameter vector with length . ; The specific process of weighted fusion with variable weights is represented as follows: ; in, This indicates the regional trajectory fusion characteristics.
5. The method for protecting cross-city user trajectory privacy against dynamic adaptive attacks according to claim 4, characterized in that, In step 1, the signal is in the protection module. The processing flow in the access record protection layer is represented as follows: ; in, This indicates a protected current access record. Indicates the access record protection layer network; To protect the pre-regional trajectory fusion features, it uses the current access record and protected trans-city historical sites Input codec network extracts pre-protection trajectory feature representation And based on variable weights The gated weighted fusion mechanism is obtained; in, Represents the trajectory matrix of the input access record protection layer, with variable weights. By analyzing the trajectory matrix The matrix transformation is performed, and then the normalized weight probability distribution is obtained by passing it through a softmax layer. Signal in attack module The processing flow in the trajectory prediction layer is represented as follows: ; in, Indicates guessing the trajectory. This represents the trajectory prediction layer network; To protect post-regional trajectory fusion features, it uses protected current access records. and protected trans-city historical sites Input codec network extracts protected trajectory feature representation And based on variable weights The gated weighted fusion mechanism is obtained; in, Represents the trajectory matrix of the input trajectory prediction layer, with variable weights. By analyzing the trajectory matrix The matrix is transformed, and then the normalized weight probability distribution is obtained by passing it through a softmax layer.
6. The method for protecting cross-city user trajectory privacy against dynamic adaptive attacks according to claim 5, characterized in that, In step 2, the loss of trajectory privacy and the loss of service quality specifically refer to: Protection module and attack modules Organized together in a mutually antagonistic relationship, forming a framework for cross-city users. Non-cooperative game theory for trajectory privacy, protection module and attack modules The total benefit of information regarding cross-city user trajectory privacy is zero. Using attack modules Expected loss To measure cross-city users After protection module Loss of privacy due to protected trajectory ,Right now ; Attack Module Expected loss The calculation formula is: ; in, Indicates the expected value. For cross-city users The true trajectory and All contain Access records; Represents the true trajectory and guessing the trajectory The physical distance between them is measured by mean square error; The loss of local search service quality in location A Loss of local search service quality in location B Quantified, expressed as: ; ; in, , Indicates cross-city users The true location Indicates protection module The output fuzzy position, Indicates the actual location and fuzzy position The physical distance between them; Indicates the first A protected access record service identifier; when When =0, Access records for the search service in location A, when When =1, Access records for the search service in location B.
7. The method for protecting cross-city user trajectory privacy against dynamic adaptive attacks according to claim 6, characterized in that, In step 2, the process of constructing the trajectory privacy protection optimization objective function for cross-regional search services with limited service quality is as follows: Using attack modules Expected loss To measure the attack module In attack strategy The attack effect below; Adopt cross-city users After protection module Loss of privacy after protection of trajectory Loss of local search service quality in location A Loss of local search service quality in location B For protection modules In protection strategy The effectiveness of protection under these conditions is measured; The objective function for optimizing trajectory privacy protection in cross-regional search services with limited service quality is: ; ; ; in, Indicates fixed attack module Network parameters, i.e., attack strategies Training protection module Loss of trajectory privacy minimize; Indicates fixed protection module Network parameters, i.e., protection policies Training attack module Loss of trajectory privacy maximize; This represents the average maximum quality of service loss that a user can tolerate in the search service for city A. This represents the average maximum service quality loss that users can tolerate in the search service in city B.
8. The method for protecting cross-city user trajectory privacy against dynamic adaptive attacks according to claim 7, characterized in that, Step 2 also includes a region discriminator. And true / false trajectory discriminator The training conducted; Regional discriminator Using a binary cross-entropy loss function The expression for training is: ; in, Indicates the actual city label and predicting city probability The differences between them; True / False Trajectory Discriminator The binary cross-entropy loss function is used for training, and its expression is: ; in, Indicates whether the actual trajectory is real or fake. And the probability of true or false prediction of trajectory The differences between them.
9. The method for protecting cross-city user trajectory privacy against dynamic adaptive attacks according to claim 8, characterized in that, In step 2, the process of training the cross-city user trajectory privacy protection model for dynamic adaptive attacks is as follows: Through punishment and For the portion exceeding the limit, the loss in local search service quality for users in different cities is controlled. The constrained optimization objective, i.e., the trajectory privacy protection optimization objective function under cross-regional search service with limited service quality, is transformed into an unconstrained optimization objective function, the expression of which is: ; in, and For penalty weighting; For unconstrained optimization objective functions, an adversarial learning mechanism is introduced, first fixing the protection module. Network parameters and attack modules Network parameters Update by minimizing the attack module. Expected loss This leads to a loss of trajectory privacy. Maximize, and thus obtain the current Optimized attack module under protection Network parameters; Then fix the attack module The network parameters, and the protection module The network parameters are updated to allow cross-city users to access the network. After protection module Loss of privacy due to protected trajectory minimize; Then, the region discriminator is used. And true / false trajectory discriminator Trajectory feature encoder at location A respectively and B location trajectory feature encoder Optimize; For protection modules and attack modules The network parameters are updated using an adaptive moment estimation method based on gradient descent; When the quality of local search services is lost and Each remains within the constraint range and Within this range, while simultaneously achieving privacy protection of the trajectory. When minimizing, it is considered that and The value of tends to be optimal; The optimal attack model is finally obtained. and the optimal protection model .
10. The method for protecting cross-city user trajectory privacy against dynamic adaptive attacks according to claim 9, characterized in that, Step 3 specifically involves: For cross-city users who use local search services simultaneously in both location A and location B Pre-set potential dynamic adaptive attack model Cross-city users Protected trans-city historical trails Cross-city users At any moment The actual access record is the current access record. Users across cities Maximum acceptable search radius As The fuzzy radius is preset for cross-city users. The maximum tolerable average quality of service loss in the search service of city A is: Preset cross-city users The maximum tolerable average quality of service loss in the search service of City B is ; Solve for an optimal protection model. For cross-city users using LBS services Generate a protected current access record. This makes it possible for users in different cities to... Optimal protection model when using search services Able to output a fuzzy position This makes the position ambiguous. In real location search radius Within the range; A new trajectory is created by combining protected current access records and protected cross-city historical trajectories. This new trajectory can resist dynamic adaptive attacks based on cross-city trajectory fusion. It can also control the quality loss of local search services in location A and location B for cross-city users. acceptable range and Inside.