Designing a Location Trace Anonymization Contest

For a better understanding of anonymization methods for location traces, we have designed and held a location trace anonymization contest that deals with a long trace (400 events per user) and fine-grained locations (1024 regions). In our contest, each team anonymizes her original traces, and then t...

Ausführliche Beschreibung

Gespeichert in:
Bibliographische Detailangaben
Veröffentlicht in:Proceedings on Privacy Enhancing Technologies 2023-01, Vol.2023 (1), p.225-243
Hauptverfasser: Murakami, Takao, Arai, Hiromi, Hamada, Koki, Hatano, Takuma, Iguchi, Makoto, Kikuchi, Hiroaki, Kuromasa, Atsushi, Nakagawa, Hiroshi, Nakamura, Yuichi, Nishiyama, Kenshiro, Nojima, Ryo, Oguri, Hidenobu, Watanabe, Chiemi, Yamada, Akira, Yamaguchi, Takayasu, Yamaoka, Yuji
Format: Artikel
Sprache:eng
Online-Zugang:Volltext
Tags: Tag hinzufügen
Keine Tags, Fügen Sie den ersten Tag hinzu!
Beschreibung
Zusammenfassung:For a better understanding of anonymization methods for location traces, we have designed and held a location trace anonymization contest that deals with a long trace (400 events per user) and fine-grained locations (1024 regions). In our contest, each team anonymizes her original traces, and then the other teams perform privacy attacks against the anonymized traces. In other words, both defense and attack compete together, which is close to what happens in real life. Prior to our contest, we show that re-identification alone is insufficient as a privacy risk and that trace inference should be added as an additional risk. Specifically, we show an example of anonymization that is perfectly secure against re-identification and is not secure against trace inference. Based on this, our contest evaluates both the re-identification risk and trace inference risk and analyzes their relationship. Through our contest, we show several findings in a situation where both defense and attack compete together. In particular, we show that an anonymization method secure against trace inference is also secure against re-identification under the presence of appropriate pseudonymization. We also report defense and attack algorithms that won first place, and analyze the utility of anonymized traces submitted by teams in various applications such as POI recommendation and geo-data analysis.
ISSN:2299-0984
2299-0984
DOI:10.56553/popets-2023-0014