论文标题
分散路由服务的私人位置共享
Private Location Sharing for Decentralized Routing services
论文作者
论文摘要
数据驱动的方法论提供了许多令人兴奋的优势,但它们也引入了新的挑战,尤其是在用户隐私领域。具体而言,收集数据的方式可能会对最终用户构成隐私风险。在许多路由服务中,单个实体(例如,路由服务提供商)收集和管理用户轨迹数据。当涉及用户隐私时,这些系统具有失败点,因为用户必须相信该实体不会出售或使用其数据来推断敏感的私人信息。不幸的是,实际上,许多广告公司为目标广告提供购买此类数据。 以此为动机,我们研究了以隐私保护方式使用位置数据进行路由服务的问题。我们没有让用户将其位置报告给中央运营商,而是提出了一项协议,其中用户参与了分散且保护隐私的计算,以估算网络中道路的旅行时间,以至于任何其他方都不会观察到个人的位置。该协议与安全的多方计算结合使用Laplace机制,以确保其在加密范围内安全,并且其输出是不同的私有。 一个自然的问题是,隐私是否需要在准确性或系统性能方面退化。我们表明,如果一条道路的容量足够高,那么我们的协议估计的旅行时间就可以接近地面真相旅行时间。我们通过数值实验来验证协议,这些实验表明,使用协议作为路由服务提供了隐私保证,而用户旅行时间的开销很小。
Data-driven methodologies offer many exciting upsides, but they also introduce new challenges, particularly in the realm of user privacy. Specifically, the way data is collected can pose privacy risks to end users. In many routing services, a single entity (e.g., the routing service provider) collects and manages user trajectory data. When it comes to user privacy, these systems have a central point of failure since users have to trust that this entity will not sell or use their data to infer sensitive private information. Unfortunately, in practice many advertising companies offer to buy such data for the sake of targeted advertisements. With this as motivation, we study the problem of using location data for routing services in a privacy-preserving way. Rather than having users report their location to a central operator, we present a protocol in which users participate in a decentralized and privacy-preserving computation to estimate travel times for the roads in the network in a way that no individuals' location is ever observed by any other party. The protocol uses the Laplace mechanism in conjunction with secure multi-party computation to ensure that it is cryptogrpahically secure and that its output is differentially private. A natural question is if privacy necessitates degradation in accuracy or system performance. We show that if a road has sufficiently high capacity, then the travel time estimated by our protocol is provably close to the ground truth travel time. We validate the protocol through numerical experiments which show that using the protocol as a routing service provides privacy guarantees with minimal overhead to user travel time.