Preserving privacy in participatory sensing systems

被引:72
作者
Huang, Kuan Lun [1 ]
Kanhere, Salil S. [1 ]
Hu, Wen [2 ]
机构
[1] Univ New S Wales, Sch Comp Sci & Engn, Sydney, NSW, Australia
[2] CSIRO ICT Ctr, Autonomous Syst Lab, Sydney, NSW, Australia
关键词
k-Anonymity; l-Diversity; Anonymity; Privacy; Participatory sensing; MICROAGGREGATION;
D O I
10.1016/j.comcom.2009.08.012
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
The ubiquity of mobile devices has brought forth the concept of participatory sensing, whereby ordinary citizens can now contribute and share information from the urban environment. However, such applications introduce a key research challenge: preserving the privacy of the individuals contributing data. In this paper, we study two different privacy concepts, k-anonymity and I-diversity, and demonstrate how their privacy models can be applied to protect users' spatial and temporal privacy in the context of participatory sensing. The first part of the paper focuses on schemes implementing k-anonymity. We propose the use of microaggregation. a technique used for facilitating disclosure control in databases, as an alternate to tessellation, which is the current state-of-the-art for location privacy in participatory sensing applications. We conduct a comparative study of the two techniques and demonstrate that each has its advantage in certain mutually exclusive situations. We then propose the Hybrid Variable size Maximum Distance to Average Vector (Hybrid-VMDAV) algorithm, which combines the positive aspects of microaggregation and tessellation. The second part of the paper addresses the limitations of the k-anonymity privacy model. We employ the principle of I-diversity and propose an I-diverse version of VMDAV (LD-VMDAV) as an improvement. In particular, LD-VMDAV is robust in situations where an adversary may have gained partial knowledge about certain attributes of the victim. We evaluate the performances of our proposed techniques using real-world traces. Our results show that Hybrid-VMDAV improves the percentage of positive identifications made by an application server by up to 100% and decreases the amount of information loss by about 40%. We empirically show that LD-VMDAV always outperforms its k-anonymity counterpart. In particular, it improves the ability of the applications to accurately interpret the anonymized location and time included in user reports. Our studies also confirm that perturbing the true locations of the users with random Gaussian noise can provide an extra layer of protection, while causing little impact on the application performance. (C) 2009 Elsevier B.V. All rights reserved.
引用
收藏
页码:1266 / 1280
页数:15
相关论文
共 31 条
[1]  
[Anonymous], 2006, 22 INT C DAT ENG WOR, DOI DOI 10.1109/ICDEW.2006.116
[2]  
[Anonymous], 2002, K ANONYMITY
[3]  
[Anonymous], 2006, P 2 ANN INT WIR INT
[4]  
Burke J., 2006, P WORLD SENS WEB WOR
[5]  
Calandriello G., 2007, VANET 07, P1928, DOI DOI 10.1145/1287748.1287752
[6]  
Cornelius C., 2008, P 6 INT C MOB SYST A
[7]   Ordinal, continuous and heterogeneous k-anonymity through microaggregation [J].
Domingo-Ferrer, J ;
Torra, V .
DATA MINING AND KNOWLEDGE DISCOVERY, 2005, 11 (02) :195-212
[8]   Practical data-oriented microaggregation for statistical disclosure control [J].
Domingo-Ferrer, J ;
Mateo-Sanz, JM .
IEEE TRANSACTIONS ON KNOWLEDGE AND DATA ENGINEERING, 2002, 14 (01) :189-201
[9]  
Domingo-Ferrer J, 2006, LECT NOTES COMPUT SC, V4032, P106
[10]  
DONG Y, 2008, P IEEE DCOSS 2008 JU