• DocumentCode
    2350931
  • Title

    Quantifying Location Privacy

  • Author

    Shokri, Reza ; Theodorakopoulos, George ; Le Boudec, Jean-Yves ; Hubaux, Jean-Pierre

  • Author_Institution
    LCA, EPFL, Lausanne, Switzerland
  • fYear
    2011
  • fDate
    22-25 May 2011
  • Firstpage
    247
  • Lastpage
    262
  • Abstract
    It is a well-known fact that the progress of personal communication devices leads to serious concerns about privacy in general, and location privacy in particular. As a response to these issues, a number of Location-Privacy Protection Mechanisms (LPPMs) have been proposed during the last decade. However, their assessment and comparison remains problematic because of the absence of a systematic method to quantify them. In particular, the assumptions about the attacker´s model tend to be incomplete, with the risk of a possibly wrong estimation of the users´ location privacy. In this paper, we address these issues by providing a formal framework for the analysis of LPPMs, it captures, in particular, the prior information that might be available to the attacker, and various attacks that he can perform. The privacy of users and the success of the adversary in his location-inference attacks are two sides of the same coin. We revise location privacy by giving a simple, yet comprehensive, model to formulate all types of location-information disclosure attacks. Thus, by formalizing the adversary´s performance, we propose and justify the right metric to quantify location privacy. We clarify the difference between three aspects of the adversary´s inference attacks, namely their accuracy, certainty, and correctness. We show that correctness determines the privacy of users. In other words, the expected estimation error of the adversary is the metric of users´ location privacy. We rely on well-established statistical methods to formalize and implement the attacks in a tool: the Location-Privacy Meter that measures the location privacy of mobile users, given various LPPMs. In addition to evaluating some example LPPMs, by using our tool, we assess the appropriateness of some popular metrics for location privacy: entropy and k-anonymity. The results show a lack of satisfactory correlation between these two metrics and the success of the adversary in inferring the users´ actual- - locations.
  • Keywords
    data privacy; mobile computing; statistical analysis; LPPM; attackers model; formal framework; location inference attacks; location privacy protection mechanisms; mobile users; personal communication devices; quantify location privacy; quantifying location privacy; statistical methods; systematic method; users location privacy; wrong estimation; Accuracy; Data privacy; Gold; Measurement; Mobile communication; Privacy; Random variables; Evaluation Framework; Location Privacy; Location Traces; Location-Privacy Meter; Quantifying Metric;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Security and Privacy (SP), 2011 IEEE Symposium on
  • Conference_Location
    Berkeley, CA
  • ISSN
    1081-6011
  • Print_ISBN
    978-1-4577-0147-4
  • Electronic_ISBN
    1081-6011
  • Type

    conf

  • DOI
    10.1109/SP.2011.18
  • Filename
    5958033