Ocean location privacy protection task offloading method based on improved laplace mechanism
By constructing a multi-buoy server threat model and generating pseudo-locations using a pruned Laplace mechanism, combined with the Grey Wolf optimization algorithm and power control, the problem of insufficient defense for location privacy protection in maritime mobile edge computing is solved, and safe and reliable marine mission offloading is achieved.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- NANJING UNIV
- Filing Date
- 2026-02-04
- Publication Date
- 2026-05-08
AI Technical Summary
Existing technologies for location privacy protection in maritime mobile edge computing scenarios have a single defense dimension, failing to consider buoy coverage and transmission power constraints, resulting in unreachable pseudo-locations. Furthermore, the power control model is mismatched with ocean random shadow fading, making it difficult to resist multi-channel attacks.
A system model considering the threat of collusion among multiple buoy servers is constructed. Combining buoy coverage and transmission power constraints, a pruned Laplace mechanism is used to generate geographically indistinguishable pseudo-locations. The offloading decision is optimized through the Grey Wolf optimization algorithm, and power control is performed by combining simulation of received signal strength at sea to ensure that the signal strength is consistent with the pseudo-location.
To effectively avoid false locations falling into communication blind spots or power infeasibility, RSSI simulation and power control are designed in combination with the characteristics of ocean random shadowing fading to resist multi-side channel attacks and achieve safe and reliable ocean mission offloading.
Smart Images

Figure CN121665226B_ABST
Abstract
Description
Technical Field
[0001] This invention belongs to the field of privacy protection technology, and more specifically, relates to a method for offloading ocean location privacy protection tasks based on an improved Laplace mechanism. Background Technology
[0002] With the comprehensive advancement of the smart ocean strategy, tasks such as marine environmental monitoring, maritime emergency rescue, and oceanographic research pose severe challenges to the real-time performance and reliability of data processing. Due to the relative scarcity of maritime communication infrastructure and the excessively long transmission distances of traditional cloud computing centers, it is difficult to meet the demands for immediate processing. Utilizing buoys deployed on the sea surface as edge servers to construct a maritime mobile edge computing (MEC) architecture, providing on-premises computing services to ship users, has become a key solution to these problems.
[0003] However, the openness of the maritime MEC architecture also brings serious location privacy risks. In complex maritime application scenarios, the location of ship users is often highly sensitive. For example, in military patrols and maritime training missions, the exposure of a ship's location can pose a serious security threat; in maritime emergency rescue and law enforcement patrols, the real-time location of rescue or law enforcement forces can be exploited by adversaries; and in the fields of marine resource exploration and commercial shipping, the exposure of key ship trajectories can also lead to damage to commercial interests. Therefore, under the maritime MEC architecture, how to effectively protect the location privacy of ship users during mission unloading has become an urgent problem to be solved. In this architecture, on the one hand, the buoy server is usually operated by a third party. When ship users unload tasks to various buoys, there is a statistical correlation between the amount of unloaded tasks and the physical distance to each buoy. Untrusted buoys can infer the user's location by analyzing the task distribution, forming a mission unloading decision side channel; on the other hand, the Received Signal Strength Indication (RSSI) monotonically decreases with the propagation distance. Multiple untrusted buoys can accurately lock the location of ship users using trilateration based on long-term RSSI observations, forming an RSSI side channel.
[0004] To address the issue of location privacy protection, existing technologies typically employ differential privacy or simple power control methods. For example, the patent document "A Location Privacy Protection Method Based on Differential Privacy" (application date: July 24, 2020, application number: 202010143726.6, publication number: CN111447181 A, the content of which can still be cited) uses differential privacy theory to blur location data by superimposing Laplace noise on the user's location. However, this method mainly targets general location service scenarios and does not consider the energy consumption and latency constraints of task offloading in edge computing, nor does it protect against RSSI side channels. Furthermore, it does not incorporate communication coverage constraints, making it prone to generating unreachable pseudo-locations that fall into communication blind spots, leading to offloading failures. The applicant, Guilin University of Technology, introduced power control to resist RSSI side channels in its patent application document "A Task Offloading and Transmission Power Allocation Optimization Method for Location Privacy Protection" (application date: March 6, 2024, application number: 202410256537.8, application publication number: CN1183383580 A, the content of which can still be cited). However, its design is based on a deterministic path loss model for terrestrial communication and does not consider the random shadowing fading characteristics unique to the marine environment. The generated RSSI signal has significant deviations from the actual sea conditions in terms of statistical characteristics, making it easy for attackers to identify through statistical analysis, thus causing the defense to fail.
[0005] In summary, existing technologies generally suffer from problems such as limited defense dimensions, failure to consider buoy coverage and power constraints leading to unreachability in pseudo-location generation, and easy detection of spoofing due to channel model mismatch when facing highly sensitive location privacy requirements in complex maritime environments. These issues make it difficult to effectively protect the location privacy of ship users in multi-channel attack scenarios and fail to achieve truly safe and reliable marine mission offloading. Summary of the Invention
[0006] Purpose of the Invention: Existing location privacy protection methods in maritime mobile edge computing scenarios suffer from problems such as a single defense dimension, failure to consider buoy coverage and transmission power constraints leading to unreachable pseudo-locations, and mismatch between power control models and ocean random shadowing fading, making it difficult to achieve effective protection against multi-channel attacks. This invention proposes a task offloading method for maritime location privacy protection based on an improved Laplace mechanism to overcome the shortcomings of the above-mentioned technologies.
[0007] To achieve the above-mentioned objectives, the present invention employs the following technical solution:
[0008] A method for offloading ocean location privacy protection tasks based on an improved Laplace mechanism includes the following steps:
[0009] S1: Construct a system model that considers the threat of collusion between multiple buoy servers;
[0010] S2: Combine the buoy coverage area and transmission power constraints to determine the feasible angle range, and use the clipped Laplace mechanism to generate a geographically indistinguishable pseudo-location for the user;
[0011] S3: Under the virtual channel conditions corresponding to the pseudo-location, the weighted sum minimization of offloading energy consumption and time delay is modeled as a discrete optimization problem, and the gray wolf optimization algorithm is used to realize the task offloading decision.
[0012] S4: By using a power control-based method to simulate the received signal strength at sea, the signal strength received by the buoy server is made consistent with the user's pseudo-position.
[0013] Furthermore, step S1 is specifically as follows:
[0014] S1-1: Deployment of ship users and buoy servers:
[0015] Deploy one vessel user and [other vessel] in the target sea area. The buoy server provides the actual location coordinates of the ship user. buoy server The position coordinates are The set of distances between ship users and each buoy server can be represented as: ,in For Euclidean distances, form a set of all distances. The computational tasks for ship users are divided into multiple sub-tasks. Each subtask is independent and executed in parallel; for any subtask Only one processing method is allowed: either execute locally or offload to a single buoy server. :definition For subtasks Uninstalled to ;like For any buoy server If all are true, then it indicates a subtask. Processed locally, denoted as ;
[0016] S1-2: Constructing a multi-buoy server collusion threat model:
[0017] The buoy server infers the true location of the ship user based on the task unloading decision and the side channel of the received signal strength;
[0018] Task offloading decision side channel: 1 The number of offloading tasks carried by each buoy server within one observation window is:
[0019] ,
[0020] gather There is a statistical correlation between the relative distances from ship users to each buoy server, and attackers construct mappings based on empirical models. The location information estimate based on the unloading behavior is obtained:
[0021] ,
[0022] in, The mapping is learned from the empirical model;
[0023] Received signal strength side channel: 1 A buoy server in a time slot The observed received signal strength is denoted as Link gain Represented as:
[0024] ,
[0025] in, For path gain, This is the sea surface path loss index. This indicates the fading of the shadow caused by the obstruction of the waves. This is a small-scale fading; the instantaneous received signal strength observed by the buoy server is:
[0026] ,
[0027] in, For ship users' transmission power, For system bandwidth, For noise power spectral density, the attacker... Time averaging to eliminate small-scale fading At this point, the attacker can deduce the distance based on statistical expectation:
[0028] ,
[0029] ,
[0030] When three or more untrusted buoy servers collude, attackers use trilateration to reverse engineer the location of the ship's user. The task offloading decision-making side channel and the received signal strength side channel are independent of each other, allowing attackers to launch inference attacks separately and obtain position estimates. and .
[0031] Furthermore, step S2 is specifically as follows:
[0032] S2-1: Determine the feasible angle range by combining the buoy coverage area and transmission power constraints:
[0033] Based on the actual location of the ship user Centered on a circle with a disturbance radius of A perturbation region is generated, and the pseudo-positions generated within the perturbation region must simultaneously satisfy the following:
[0034] 1) Unloading feasibility: It must be located within the coverage area of at least one buoy server, i.e., it must meet the buoy coverage constraint;
[0035] 2) Received signal strength mimicry: It needs to be far away from the power range of the buoy server, i.e., it needs to meet the transmit power constraint;
[0036] The angle interval within the disturbance region where the pseudo-position does not meet the unloading feasibility requirement is denoted as... ; Set up a pseudo-position and buoy server The nearest allowed distance is ;by Center and radius Draw a circle, and call this circle the buoy server. The power region; the angle interval between the disturbance region and the power region is denoted as... The pseudo-positions generated within this interval do not satisfy the imitation of the received signal strength;
[0037] For each buoy server A set can be obtained for each. To ensure that both unloading feasibility and the mimicry of received signal strength are satisfied under any circumstances, the unavailable angles are summarized as follows:
[0038] ,
[0039] in, (R), (R) removes unusable angles from the perturbation region to obtain the feasible angle range. ;
[0040] S2-2: Generating geographically indistinguishable pseudo-user locations using a pruned Laplacian mechanism:
[0041] Real location of ship users The pseudo-position generated is the origin of the polar coordinate system. Represented in polar coordinates The range of values is , ,in , For rays and The angle between the horizontal positive axis and the horizontal positive axis, and and If the distribution follows an independent uniform distribution, then the pruning Laplace mechanism generates pseudo-positions. The joint probability density is:
[0042]
[0043] in, This refers to a privacy budget that is geographically indistinguishable. Let be the length of the angle interval, and be the normalization constant. The pseudo-position is generated by first sampling the angle and then sampling the radius. The specific steps are as follows:
[0044] 1) Angle sampling: exist The upper part follows a uniform distribution, and the interval is... An angle is randomly generated inside. ,in Indicates the interval The upper part follows a uniform distribution;
[0045] 2) Radius sampling: For Its marginal probability density is:
[0046] ,
[0047] The cumulative distribution function is:
[0048] ,
[0049] in, Let be the current integration variable; Based on the inversion sampling principle, we obtain for:
[0050] ,
[0051] in This is the -1 branch of the product logarithmic function; the final pseudo-position in Cartesian coordinates is written as:
[0052] .
[0053] Furthermore, step S3 is specifically as follows:
[0054] Given the current pseudo position Connecting ship users with each buoy server The virtual distance is defined as The corresponding channel gain is Then the virtual transmission rate under the pseudo-location is:
[0055] ,
[0056] Calculate the offloading energy consumption at the pseudo-location based on the virtual transmission rate. With delay ,set up To offload the energy consumption and latency balance factor, subtasks In the time slot The task processing cost is Its value is determined by the pseudo-position. Uninstallation decision Decision: Use the Grey Wolf Optimization Algorithm to solve for the pseudo-position. Optimal Unloading Decision The goal is to ensure the unloading decision and the pseudo-position. Minimize task processing cost while maintaining consistency; assign a candidate unloading scheme to each gray wolf, and consider the individual with the lowest fitness value in the population as the candidate unloading scheme. Wolves, the second-best and third-best individuals are respectively wolves and Wolves, the rest are The position of each individual wolf is iteratively updated by simulating the hunting and trapping behavior of gray wolves. After the iteration is complete, the output is... The wolf's corresponding unloading decision is used as a pseudo-position. The optimal uninstallation solution.
[0057] Furthermore, step S4 is specifically as follows:
[0058] S4-1: Statistical matching of received signal strength under maritime channel:
[0059] When ship users are in their actual location Using disguised power The expected signal strength actually received by the buoy server is:
[0060] ,
[0061] Ship users are in false positions Using transmission power The expected signal strength that the buoy server expects to receive is:
[0062] ,
[0063] S4-2: Simulation of Received Signal Strength at Sea Based on Power Control:
[0064] Camouflage power adjusted by ship users It needs to satisfy the condition in the pseudo position The expected received signal strength generated is expected to be similar to that of the buoy server at its actual location. The observed actual received signal strength is expected to be consistent with the expected value, let Thus, the fundamental imitation power is obtained as:
[0065] ,
[0066] in , When the false position is far from the buoy service, The required transmission power is reduced; and when the pseudo-position is close to the buoy server, In this case, a higher transmission power is required for camouflage; it is important to note that the camouflaged signal must still ensure link reachability, meaning the transmission power cannot fall below the minimum power lower bound required to ensure reliable reception by the buoy server. ;
[0067] Introducing sea state-related random disturbance factors The corrected camouflage power was obtained. for:
[0068] ,
[0069] in, This indicates that the mean is 1, and the variance of the disturbance that compensates for the imitation error is... The normal distribution is considered; the maximum transmit power constraint of ship users is taken into account. The final camouflage power used is:
[0070] ,
[0071] And pseudo-position It must be located within a region that meets power constraints, i.e., the pseudo-position and the buoy server. The distance between them must satisfy the following constraints:
[0072] ,
[0073] in, This is the upper limit for the transmission power of ship users.
[0074] The advantages and technical effects of this invention are as follows:
[0075] This invention constructs a feasible pseudo-position region by introducing buoy coverage and transmission power constraints, and uses a pruned Laplace mechanism to generate pseudo-positions, avoiding the problems of pseudo-positions falling into communication blind spots or power infeasibility in existing methods. Simultaneously, it designs a marine RSSI simulation and power control strategy based on the characteristics of ocean random shadowing fading, ensuring statistical matching between buoy server observation signals and pseudo-position information, effectively resisting multi-channel and multi-buoy collusion inference attacks. Furthermore, it jointly optimizes offloading energy consumption and latency, achieving a synergistic improvement in privacy protection and marine mission offloading performance. In summary, this invention effectively reduces the risk of location privacy leakage during mission offloading, achieving safe and reliable marine mission offloading. Attached Figure Description
[0076] Figure 1 This is an overall flowchart of one embodiment of the present invention;
[0077] Figure 2 This is a network architecture diagram of one embodiment of the present invention;
[0078] Figure 3 This is an example diagram illustrating the construction of a feasible angle range by combining the buoy coverage area and the transmission power constraint according to an embodiment of the present invention;
[0079] Figure 4 This is a comparison chart showing the effect of using the method provided by this invention, the standard planar Laplace mechanism, and the power-free ablation scheme in a multi-buoy collusion attack scenario, according to one embodiment of the present invention, on location privacy protection. Detailed Implementation
[0080] To make the objectives, technical solutions, and advantages of this invention clearer, the invention will be further described in detail below with reference to the accompanying drawings and embodiments.
[0081] This embodiment proposes a method for offloading ocean location privacy protection tasks based on an improved Laplace mechanism, the overall flowchart of which is shown below. Figure 1 As shown, it includes the following steps:
[0082] S1: Construct a system model that considers the threat of collusion among multiple buoy servers. The specific steps are as follows:
[0083] S1-1: Deployment of ship users and buoy servers:
[0084] like Figure 2 As shown, one vessel is deployed in the target sea area for users and The buoy server provides the actual location coordinates of the ship user. buoy server The position coordinates are The set of distances between ship users and each buoy server can be represented as ,in For Euclidean distances, form a set of all distances. The computing tasks for ship users are divided into 6 sub-tasks. ,Right now =6; where each subtask is independent and executes in parallel; for any subtask Only one processing method is allowed: either execute locally or uninstall to a single buoy server. :definition For subtasks Uninstalled to ;like For any buoy server If all are true, then it indicates a subtask. Processed locally, denoted as ;
[0085] S1-2: Constructing a multi-buoy server collusion threat model:
[0086] The buoy server infers the true location of the ship user based on the task unloading decision and the side channel of the received signal strength;
[0087] Task offloading decision-making side channel: 1 The number of offloading tasks carried by each buoy server within one observation window is:
[0088] ,
[0089] gather There is a statistical correlation between the relative distances from ship users to each buoy server, and attackers construct mappings based on empirical models. The location information estimate based on the unloading behavior is obtained:
[0090] ,
[0091] in, The mapping is learned from the empirical model;
[0092] Received signal strength side channel: 1 A buoy server in a time slot The observed received signal strength is denoted as Link gain Represented as:
[0093] ,
[0094] in, For path gain, This is the sea surface path loss index. This indicates the fading of the shadow caused by the obstruction of the waves. This is a small-scale fading; the instantaneous received signal strength observed by the buoy server is:
[0095] ,
[0096] in, For ship users' transmission power, For system bandwidth, For noise power spectral density, the attacker... Time averaging to eliminate small-scale fading At this point, the attacker can deduce the distance based on statistical expectation:
[0097] ,
[0098] ,
[0099] When three or more untrusted buoy servers collude, attackers use trilateration to reverse engineer the location of the ship's user. The task offloading decision-making side channel and the received signal strength side channel are independent of each other, allowing attackers to launch inference attacks separately and obtain position estimates. and .
[0100] S2: Combining buoy coverage area and transmission power constraints, determine feasible angle ranges, and use a pruned Laplace mechanism to generate geographically indistinguishable pseudo-locations for users. The specific steps are as follows:
[0101] S2-1: Determine the feasible angle range by combining the buoy coverage area and transmission power constraints:
[0102] Based on the actual location of the ship user Centered on a circle with a disturbance radius of A perturbation region is generated, and the pseudo-positions generated within the perturbation region must simultaneously satisfy the following:
[0103] 1) Unloading feasibility: It must be located within the coverage area of at least one buoy server, i.e., it must meet the buoy coverage constraint;
[0104] 2) Received signal strength mimicry: It must be far from the power range of any buoy server, i.e., it must meet the transmit power constraint;
[0105] Figure 3 The feasible angle region under the aforementioned constraints is shown. Example of construction; such as Figure 3 As shown in (a), there are three buoy servers within the communication range of the ship user, located at... , and The coverage radii of the three buoy servers are respectively denoted as... , and ;Will Figure 3 (a) It is split into three parts, each covered by a separate buoy server, such as Figure 3 (b) As shown in the left section: Ship users are only covered by buoy server 1; although the disturbance radius has been limited to To ensure unloading feasibility, but at certain angles, the pseudo-position still falls outside the coverage area of buoy server 1; these angle intervals in the diagram are denoted as... And marked in blue; in addition, considering the imitation of received signal strength, the pseudo-position cannot be too close to buoy server 1; let the minimum allowable distance between the pseudo-position and buoy server 1 be... ;by Center and radius Draw a circle, called the power region of buoy server 1; in the same example, angles that intersect the power region but are too close to the buoy server are marked in green, forming angle intervals. ; , and , For buoy server 2 and buoy server 3, they play the role of , The same function applies to buoy server 1, so it will not be elaborated here;
[0106] The angle interval within the disturbance region where the pseudo-position does not meet the unloading feasibility requirement is denoted as... The angular interval between the disturbance region and the power region is denoted as... For each buoy server A set can be obtained from each. To ensure that both unloading feasibility and the mimicry of received signal strength are satisfied under any circumstances, the unavailable angles are summarized as follows:
[0107] ,
[0108] in, (R), (R) removes unusable angles from the perturbation region to obtain the feasible angle range. ;
[0109] S2-2: Generating geographically indistinguishable pseudo-user locations using a pruned Laplacian mechanism:
[0110] Real location of ship users The pseudo-position generated is the origin of the polar coordinate system. Represented in polar coordinates The range of values is , ,in , For rays and The angle between the horizontal positive axis and the horizontal positive axis, and and If the distribution follows an independent uniform distribution, then the pruning Laplace mechanism generates pseudo-positions. The joint probability density is:
[0111]
[0112] in, This refers to a privacy budget that is geographically indistinguishable. Let be the length of the angle interval, and be the normalization constant. The pseudo-position is generated by first sampling the angle and then sampling the radius. The specific steps are as follows:
[0113] 1) Angle sampling: exist The upper part follows a uniform distribution, and the interval is... An angle is randomly generated inside. ,in Indicates the interval The upper part follows a uniform distribution;
[0114] 2) Radius sampling: For Its marginal probability density is:
[0115] ,
[0116] The cumulative distribution function is:
[0117] ,
[0118] in, Let be the current integration variable; Based on the inversion sampling principle, we obtain for:
[0119] ,
[0120] in This is the -1 branch of the product logarithmic function; the final pseudo-position in Cartesian coordinates is written as:
[0121] .
[0122] S3: Under the virtual channel conditions corresponding to the pseudo-location, the weighted sum minimization of offloading energy consumption and time delay is modeled as a discrete optimization problem, and the gray wolf optimization algorithm is used to implement the task offloading decision. The specific steps are as follows:
[0123] Given the current pseudo position Connecting ship users with each buoy server The virtual distance is defined as The corresponding channel gain is Then the virtual transmission rate under the pseudo-location is:
[0124] ,
[0125] Calculate the offloading energy consumption at the pseudo-location based on the virtual transmission rate. With delay ,set up To balance energy consumption and latency, this embodiment takes... =0.5; Subtask In the time slot The task processing cost is Its value is determined by the pseudo-position. Uninstallation decision Decision: Use the Grey Wolf Optimization Algorithm to solve for the pseudo-position. Optimal Unloading Decision The goal is to ensure the unloading decision and the pseudo-position. Minimize task processing cost while maintaining consistency; assign a candidate unloading scheme to each gray wolf, and consider the individual with the lowest fitness value in the population as the candidate unloading scheme. Wolves, the second-best and third-best individuals are respectively wolves and Wolves, the rest are The position of each individual wolf is iteratively updated by simulating the hunting and trapping behavior of gray wolves. After the iteration is complete, the output is... The wolf's corresponding unloading decision is used as a pseudo-position. The optimal uninstallation solution.
[0126] S4: By using a power control-based method to simulate the received signal strength at sea, the signal strength received by the buoy server is made consistent with the user's pseudo-position. The specific steps are as follows:
[0127] S4-1: Statistical matching of received signal strength under maritime channel:
[0128] When ship users are in their actual location Using disguised power The expected signal strength actually received by the buoy server is:
[0129] ,
[0130] Ship users are in false positions Using transmission power The expected signal strength that the buoy server expects to receive is:
[0131] ,
[0132] S4-2: Simulation of Received Signal Strength at Sea Based on Power Control:
[0133] Camouflage power adjusted by ship users It needs to satisfy the condition in the pseudo position The expected received signal strength generated is expected to be similar to that of the buoy server at its actual location. The observed actual received signal strength is expected to be consistent with the expected value, let Thus, the fundamental imitation power is obtained as:
[0134] ,
[0135] in , When the false position is far from the buoy service, The required transmission power is reduced; and when the pseudo-position is close to the buoy server, In this case, a higher transmission power is required for camouflage; it is important to note that the camouflaged signal must still ensure link reachability, meaning the transmission power cannot fall below the minimum power lower bound required to ensure reliable reception by the buoy server. ;
[0136] Introducing sea state-related random disturbance factors The corrected camouflage power was obtained. for:
[0137] ,
[0138] in, This indicates that the mean is 1, and the variance of the disturbance that compensates for the imitation error is... The normal distribution is considered; the maximum transmit power constraint of ship users is taken into account. The final camouflage power used is:
[0139] ,
[0140] And pseudo-position It must be located within a region that meets power constraints, i.e., the pseudo-position and the buoy server. The distance between them must satisfy the following constraints:
[0141] ,
[0142] in, This is the upper limit for the transmission power of ship users.
[0143] The results of comparing the position privacy protection effects of the method provided in this invention, the standard planar Laplace mechanism, and the power-free control ablation scheme in a multi-buoy collusion attack scenario are as follows: Figure 4 As shown in the figure. Location privacy protection capability is measured using the Mean Inference Error (MIE) metric. MIE represents the Euclidean distance between the attacker's final inferred location and the user's actual location. The larger the MIE value, the more difficult it is to infer the location, and the better the privacy protection effect. This embodiment was simulated in Matlab R2021a. The experimental platform was an Intel Core i7-12700H 2.70 GHz processor based on the x64 architecture, with 16 GB of memory. All simulations were conducted under the same parameter configuration to ensure the comparability of the results. The main simulation parameters are listed in Table 1.
[0144] Table 1 Simulation Parameters
[0145]
[0146] from Figure 4 It can be seen that the location privacy protection capability of the Standard Planar Laplace mechanism (Standard-PL) decreases most significantly with the increase in the number of colluding buoys. When the number of colluding buoy servers exceeds two, attackers can more easily reverse the user's location through geometric constraints and the elimination of invalid pseudo-locations, resulting in a sharp decrease in MIE. The power-free control ablation scheme (W / O PC) outperforms the Standard Laplace method when there are a few colluding buoys, but because it does not robustly handle the RSSI side channel, its RSSI statistical characteristics show significant differences when the number of colluding buoys increases. Attackers can use trilateration to correct the estimation results, leading to a significant decrease in MIE.
[0147] In contrast, the method of this invention maintains a high average inference error under different numbers of colluding buoys, and even in the extreme scenario of three buoys colluding simultaneously, it can still effectively maintain strong position confusion capability. This is because this invention not only ensures that the pseudo-position is always within the coverage reachable and power feasible region by improving the Laplace mechanism, avoiding rejection by simple geometric screening, but also fundamentally weakens the inference capability of the RSSI side channel by statistically matching the distribution characteristics of the real RSSI and the pseudo-position RSSI through a robust power control mechanism.
[0148] In summary, this invention can effectively reduce the risk of location privacy leakage during the mission unloading process and achieve safe and reliable marine mission unloading.
[0149] The above embodiments are only used to illustrate the technical solutions of the present invention, and are not intended to limit them. Although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art can still modify the technical solutions described in the foregoing embodiments or make equivalent substitutions for some of the technical features. Such modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions claimed by the present invention.
Claims
1. A method for offloading ocean location privacy protection tasks based on an improved Laplace mechanism, characterized in that, Includes the following steps: S1: Construct a system model that considers the threat of collusion between multiple buoy servers; S2: Combining buoy coverage area and transmit power constraints, determine feasible angle ranges, and use a pruned Laplace mechanism to generate geographically indistinguishable pseudo-user locations, as detailed below: S2-1: Determine the feasible angle range by combining the buoy coverage area and transmission power constraints: Based on the actual location of the ship user Centered on a circle with a disturbance radius of A perturbation region is generated, and the pseudo-positions generated within the perturbation region must simultaneously satisfy the following: 1) Unloading feasibility: It must be located within the coverage area of at least one buoy server, i.e., it must meet the buoy coverage constraint; 2) Received signal strength mimicry: It needs to be far away from the power range of the buoy server, i.e., it needs to meet the transmit power constraint; The angle interval within the disturbance region where the pseudo-position does not meet the unloading feasibility requirement is denoted as... ; Set up a pseudo-position and buoy server The nearest allowed distance is ;by Center and radius Draw a circle, and call this circle the buoy server. The power region; the angle interval between the disturbance region and the power region is denoted as... The pseudo-positions generated within this interval do not satisfy the imitation of the received signal strength; For each buoy server A set can be obtained for each. To ensure that both unloading feasibility and the mimicry of received signal strength are satisfied under any circumstances, the unavailable angles are summarized as follows: , in, , By removing unusable angles from the perturbation region, the feasible angle range is obtained. ; S2-2: Generating geographically indistinguishable pseudo-user locations using a pruned Laplacian mechanism: Real location of ship users The pseudo-position generated is the origin of the polar coordinate system. Represented in polar coordinates The range of values is , ,in , For rays and The angle between the horizontal positive axis and the horizontal positive axis, and and If the distribution follows an independent uniform distribution, then the pruning Laplace mechanism generates pseudo-positions. The joint probability density is: in, This refers to a privacy budget that is geographically indistinguishable. Let be the length of the angle interval, and be the normalization constant. The pseudo-position is generated by first sampling the angle and then sampling the radius. The specific steps are as follows: 1) Angle sampling: exist The upper part follows a uniform distribution, and the interval is... An angle is randomly generated inside. ,in Indicates the interval The upper part follows a uniform distribution; 2) Radius sampling: For Its marginal probability density is: , The cumulative distribution function is: , in, Let be the current integration variable; Based on the inversion sampling principle, we obtain for: , in This is the -1 branch of the product logarithmic function; the final pseudo-position in Cartesian coordinates is written as: ; S3: Under the virtual channel conditions corresponding to the pseudo-location, the weighted sum minimization of offloading energy consumption and time delay is modeled as a discrete optimization problem, and the gray wolf optimization algorithm is used to realize the task offloading decision. S4: By using a power control-based method to simulate the received signal strength at sea, the signal strength received by the buoy server is made consistent with the user's pseudo-position.
2. The method for offloading ocean location privacy protection tasks based on the improved Laplace mechanism as described in claim 1, characterized in that, The specific steps of S1 are as follows: S1-1: Deployment of ship users and buoy servers: Deploy one vessel user and [other vessel] in the target sea area. The buoy server provides the actual location coordinates of the ship user. buoy server The position coordinates are The set of distances between ship users and each buoy server can be represented as: ,in For Euclidean distances, form a set of all distances. The computational tasks for ship users are divided into multiple sub-tasks. Each subtask is independent and executed in parallel; for any subtask Only one processing method is allowed: either execute locally or offload to a single buoy server. :definition For subtasks Uninstalled to ;like For any buoy server If all are true, then it indicates a subtask. Processed locally, denoted as ; S1-2: Constructing a multi-buoy server collusion threat model: The buoy server infers the true location of the ship user based on the task unloading decision and the side channel of the received signal strength; Task offloading decision side channel: 1 The number of offloading tasks carried by each buoy server within one observation window is: , gather There is a statistical correlation between the relative distances from ship users to each buoy server, and attackers construct mappings based on empirical models. The location information estimate based on the unloading behavior is obtained: , in, The mapping is learned from the empirical model; Received signal strength side channel: 1 A buoy server in a time slot The observed received signal strength is denoted as Link gain Represented as: , in, For path gain, This is the sea surface path loss index. This indicates the fading of the shadow caused by the obstruction of the waves. This is a small-scale fading; the instantaneous received signal strength observed by the buoy server is: , in, For ship users' transmission power, For system bandwidth, For noise power spectral density, the attacker... Time averaging to eliminate small-scale fading At this point, the attacker can deduce the distance based on statistical expectation: , , When three or more untrusted buoy servers collude, attackers use trilateration to reverse engineer the location of the ship's user. The task offloading decision-making side channel and the received signal strength side channel are independent of each other, allowing attackers to launch inference attacks separately and obtain position estimates. and .
3. The method for offloading ocean location privacy protection tasks based on the improved Laplace mechanism as described in claim 1, characterized in that, Step S3 is as follows: Given the current pseudo position Connecting ship users with each buoy server The virtual distance is defined as The corresponding channel gain is Then the virtual transmission rate under the pseudo-location is: , Calculate the offloading energy consumption at the pseudo-location based on the virtual transmission rate. With delay ,set up To offload the energy consumption and latency balance factor, subtasks In the time slot The task processing cost is Its value is determined by the pseudo-position. Uninstallation decision Decision: Use the Grey Wolf Optimization Algorithm to solve for the pseudo-position. Optimal Unloading Decision The goal is to ensure the unloading decision and the pseudo-position. Minimize task processing cost while maintaining consistency; Each gray wolf is assigned a candidate unloading scheme, and the individual with the lowest fitness value in the population is considered the candidate unloading scheme. Wolves, the second-best and third-best individuals are respectively wolves and Wolves, the rest are The position of each individual wolf is iteratively updated by simulating the hunting and trapping behavior of gray wolves. After the iteration is complete, the output is... The wolf's corresponding unloading decision is used as a pseudo-position. The optimal uninstallation solution.
4. The method for offloading ocean location privacy protection tasks based on the improved Laplace mechanism as described in claim 1, characterized in that, Step S4 is as follows: S4-1: Statistical matching of received signal strength under maritime channel: When ship users are in their actual location Using disguised power The expected signal strength actually received by the buoy server is: , Ship users are in false positions Using transmission power The expected signal strength that the buoy server expects to receive is: , S4-2: Simulation of Received Signal Strength at Sea Based on Power Control: Camouflage power adjusted by ship users It needs to satisfy the condition in the pseudo position The expected received signal strength generated is expected to be similar to that of the buoy server at its actual location. The observed actual received signal strength is expected to be consistent with that, let Thus, the fundamental imitation power is obtained as: , in , When the false position is far from the buoy service, The required transmission power is reduced; and when the pseudo-position is close to the buoy server, In this case, a higher transmission power is required for camouflage; it is important to note that the camouflaged signal must still ensure link reachability, meaning the transmission power cannot fall below the minimum power lower bound required to ensure reliable reception by the buoy server. ; Introducing sea state-related random disturbance factors The corrected camouflage power was obtained. for: , in, This indicates that the mean is 1, and the variance of the disturbance that compensates for the imitation error is... The normal distribution is considered; the maximum transmit power constraint of ship users is taken into account. The final camouflage power used is: , And pseudo-position It must be located within a region that meets power constraints, i.e., the pseudo-position and the buoy server. The distance between them must satisfy the following constraints: , in, This is the upper limit for the transmission power of ship users.
Citation Information
Patent Citations
Position privacy protection method based on differential privacy
CN111447181A
Position privacy protection-oriented task unloading and transmission power allocation optimization method
CN118338358A
Differential privacy-based location privacy protection method for guaranteeing service quality
CN112364379A
Underwater edge privacy protection task unloading method based on differential federated learning
CN120434626A