Publication: Privacy risks of continuous location sharing under local differential privacy: inference attacks and defenses
Program
KU Authors
Co-Authors
Editor & Affiliation
Compiler & Affiliation
Translator
Other Contributor
Date
Language
eng
Type
Embargo Status
N/A
Journal Title
Journal ISSN
Volume Title
Alternative Title
Abstract
Local differential privacy (LDP) has recently emerged as a widely adopted standard for privacy-preserving data collection in IoT, including location data and location-based services (LBS). However, in many practical applications, users need to share their location continuously, which creates temporal correlations that can be exploited by adversaries although individual locations are protected by LDP. In this paper, we propose novel inference attacks that exploit these correlations to compromise users’ privacy under continuous location sharing. We develop attacks in two categories: statistical attacks based on Bayesian adversary formulation targeting near-stationary users and Hidden Markov Model (HMM) based attacks targeting mobile users. We further propose two extensions for our HMM-based attacks: informed attacks, which leverage aggregate population statistics, and chain attacks, which apply multiple iterations of HMM construction. We adapt and apply our attacks to four popular LDP protocols (GRR, RAPPOR, OUE, OLH), three datasets, and varying privacy levels. Experiments show that our attacks are effective, highlighting the privacy risks of correlations in continuous location sharing under LDP. Furthermore, we observe that statistical attacks are indeed more effective on stationary users, whereas HMM-based attacks are more effective on mobile users. Finally, we propose three defense strategies to mitigate the risks: Memoization, Replay, and Replication, and experimentally show that the defenses successfully reduce attack effectiveness. We critically analyze the success, efficiency, and utility aspects of the three defenses by considering varying IoT conditions and provide recommendations regarding when to use which defense.
Source
Publisher
Elsevier
Subject
Computer science, Engineering, Telecommunications
Citation
Has Part
Source
Computer Networks
Book Series Title
Edition
DOI
10.1016/j.comnet.2026.112333
