Publication:
Privacy risks of continuous location sharing under local differential privacy: inference attacks and defenses

Placeholder

School / College / Institute

Organizational Unit

Program

KU Authors

Co-Authors

Editor & Affiliation

Compiler & Affiliation

Translator

Other Contributor

Date

Language

eng

Embargo Status

N/A

Journal Title

Journal ISSN

Volume Title

Alternative Title

Abstract

Local differential privacy (LDP) has recently emerged as a widely adopted standard for privacy-preserving data collection in IoT, including location data and location-based services (LBS). However, in many practical applications, users need to share their location continuously, which creates temporal correlations that can be exploited by adversaries although individual locations are protected by LDP. In this paper, we propose novel inference attacks that exploit these correlations to compromise users’ privacy under continuous location sharing. We develop attacks in two categories: statistical attacks based on Bayesian adversary formulation targeting near-stationary users and Hidden Markov Model (HMM) based attacks targeting mobile users. We further propose two extensions for our HMM-based attacks: informed attacks, which leverage aggregate population statistics, and chain attacks, which apply multiple iterations of HMM construction. We adapt and apply our attacks to four popular LDP protocols (GRR, RAPPOR, OUE, OLH), three datasets, and varying privacy levels. Experiments show that our attacks are effective, highlighting the privacy risks of correlations in continuous location sharing under LDP. Furthermore, we observe that statistical attacks are indeed more effective on stationary users, whereas HMM-based attacks are more effective on mobile users. Finally, we propose three defense strategies to mitigate the risks: Memoization, Replay, and Replication, and experimentally show that the defenses successfully reduce attack effectiveness. We critically analyze the success, efficiency, and utility aspects of the three defenses by considering varying IoT conditions and provide recommendations regarding when to use which defense.

Source

Publisher

Elsevier

Subject

Computer science, Engineering, Telecommunications

Citation

Has Part

Source

Computer Networks

Book Series Title

Edition

DOI

10.1016/j.comnet.2026.112333

item.page.datauri

Link

Rights

Copyrights Note

Endorsement

Review

Supplemented By

Referenced By

Related Goal

0

Views

0

Downloads

View PlumX Details