Trajectory Obfuscation via Generative State-Space Models

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for obfuscating user location trajectories fail to generate plausible trajectories that preserve privacy while maintaining utility for location-based applications, often revealing obfuscation due to lack of spatiotemporal correlation and consistency with valid routes and user behavior.

Innovation Solution

A generative state-space model is trained using user location data to create a plausible obfuscated trajectory that respects spatiotemporal correlations, conforms to valid street routes, and preserves user behavior patterns, using a path generator to merge actual and fake locations with minimal distortion, ensuring privacy and utility.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If existing obfuscation methods are used to hide sensitive locations, then privacy is protected, but the trajectory becomes implausible and loses utility for location-based applications

Engineering Contradiction:
Improveprivacy protectionVSAvoidtrajectory utility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent introduces a generative model as an intermediary that transforms actual trajectories into obfuscated trajectories. This mediator learns the underlying patterns of user behavior and generates synthetic trajectories that preserve these patterns while removing sensitive information, thus maintaining both privacy and utility simultaneously

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent changes the parameter representation of trajectories by learning a latent space representation through neural networks. By transforming trajectories into this learned parameter space and then reconstructing them, the system can control the degree of obfuscation while preserving essential characteristics needed for application utility

Inventive Principle:
Principle #35Parameter changes

2Object-affected harmful factors

If simple location obfuscation is applied, then sensitive places are hidden, but spatiotemporal correlation and consistency with valid routes are lost

Engineering Contradiction:
Improvesensitive information exposureVSAvoidtrajectory consistency
Core Design Contradiction:
Object-affected harmful factorsVSManufacturing precision

Solution Approach 1:

The patent employs feedback mechanisms where the generative model is trained on actual trajectories and continuously refines its output to match ground truth patterns. The loss function provides feedback on how well the obfuscated trajectories preserve spatiotemporal correlations and route validity, guiding the model to maintain precision while obfuscating sensitive information

Inventive Principle:
Principle #23Feedback

3Productivity

If detailed user location data is preserved for application functionality, then trajectory utility is maintained, but privacy of sensitive places is compromised

Engineering Contradiction:
Improveapplication functionalityVSAvoidprivacy information
Core Design Contradiction:
ProductivityVSLoss of information

Solution Approach 1:

The patent segments the trajectory data into sensitive and non-sensitive components by learning from training data which locations are sensitive. The generative model then selectively obfuscates only the sensitive segments while preserving non-sensitive portions, maintaining application functionality where possible while protecting privacy where needed

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS10531287B2Plausible obfuscation of user location trajectories
Publication Date: 2020.01.07 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US10531287B2 patent drawing
  • US10531287B2 patent drawing
  • US10531287B2 patent drawing

AI summary

Aspects of the invention include receiving, using a processing system, an actual user location trajectory that includes a plurality of geographic locations of places visited by a user. It is determined that at least one of the plurality of places visited by the user has been identified as a sensitive place. An obfuscated user location trajectory is created that preserves the privacy of the sensitive places that is consistent with the actual user location trajectory that conforms to a valid street route on a map, preserves spatiotemporal correlation between geographic locations, and is consistent with geographic locations visited by the user in the past. Contents of the obfuscated user location trajectory are output to an application in place of contents of the actual user location trajectory.