Publication:
Privacy risks of continuous location sharing under local differential privacy: inference attacks and defenses

dc.contributor.departmentDepartment of Computer Engineering
dc.contributor.departmentGraduate School of Sciences and Engineering
dc.contributor.kuauthorGürsoy, Mehmet Emre
dc.contributor.kuauthorSimitçioğlu, Esad Muhammed
dc.contributor.schoolcollegeinstituteGRADUATE SCHOOL OF SCIENCES AND ENGINEERING
dc.contributor.schoolcollegeinstituteCollege of Engineering
dc.date.accessioned2026-07-22T13:08:49Z
dc.date.issued2026
dc.description.abstractLocal differential privacy (LDP) has recently emerged as a widely adopted standard for privacy-preserving data collection in IoT, including location data and location-based services (LBS). However, in many practical applications, users need to share their location continuously, which creates temporal correlations that can be exploited by adversaries although individual locations are protected by LDP. In this paper, we propose novel inference attacks that exploit these correlations to compromise users’ privacy under continuous location sharing. We develop attacks in two categories: statistical attacks based on Bayesian adversary formulation targeting near-stationary users and Hidden Markov Model (HMM) based attacks targeting mobile users. We further propose two extensions for our HMM-based attacks: informed attacks, which leverage aggregate population statistics, and chain attacks, which apply multiple iterations of HMM construction. We adapt and apply our attacks to four popular LDP protocols (GRR, RAPPOR, OUE, OLH), three datasets, and varying privacy levels. Experiments show that our attacks are effective, highlighting the privacy risks of correlations in continuous location sharing under LDP. Furthermore, we observe that statistical attacks are indeed more effective on stationary users, whereas HMM-based attacks are more effective on mobile users. Finally, we propose three defense strategies to mitigate the risks: Memoization, Replay, and Replication, and experimentally show that the defenses successfully reduce attack effectiveness. We critically analyze the success, efficiency, and utility aspects of the three defenses by considering varying IoT conditions and provide recommendations regarding when to use which defense.
dc.description.harvestedfromManual
dc.description.indexedbyWOS
dc.description.indexedbyScopus
dc.description.publisherscopeInternational
dc.description.readpublishN/A
dc.description.sponsoredbyTubitakEuTÜBİTAK
dc.description.sponsorshipThis work was supported by the Scientific and Technological Research Council of Turkiye (TUBITAK) under grant number 121E303 and the BAGEP Outstanding Young Scientist Award. The authors thank TUBITAK and the Science Academy for their support. We also thank Abdullah Saydemir for his help in obtaining the experiment results.
dc.description.versionPublished Version
dc.identifier.ScopusPercentile84
dc.identifier.ScopusQuartileQ1
dc.identifier.WoSPercentile72.0
dc.identifier.WoSQuartileQ2
dc.identifier.doi10.1016/j.comnet.2026.112333
dc.identifier.eissn1872-7069
dc.identifier.embargoN/A
dc.identifier.grantno1,21E+305
dc.identifier.issn1389-1286
dc.identifier.scopus2-s2.0-105037468770
dc.identifier.urihttp://doi.org/10.1016/j.comnet.2026.112333
dc.identifier.urihttps://hdl.handle.net/20.500.14288/33794
dc.identifier.volume284
dc.identifier.wos001759408800001
dc.keywordsLocal differential privacy
dc.keywordsLocation privacy
dc.keywordsInference attacks
dc.keywordsLocation-based services (LBS)
dc.keywordsHidden markov models
dc.keywordsInternet of things
dc.languageeng
dc.publisherElsevier
dc.relation.affiliationKoç University
dc.relation.collectionKoç University Institutional Repository
dc.relation.ispartofComputer Networks
dc.subjectComputer science
dc.subjectEngineering
dc.subjectTelecommunications
dc.titlePrivacy risks of continuous location sharing under local differential privacy: inference attacks and defenses
dc.typeJournal Article
dspace.entity.typePublication
relation.isOrgUnitOfPublication89352e43-bf09-4ef4-82f6-6f9d0174ebae
relation.isOrgUnitOfPublication3fc31c89-e803-4eb1-af6b-6258bc42c3d8
relation.isOrgUnitOfPublication.latestForDiscovery89352e43-bf09-4ef4-82f6-6f9d0174ebae
relation.isParentOrgUnitOfPublication434c9663-2b11-4e66-9399-c863e2ebae43
relation.isParentOrgUnitOfPublication8e756b23-2d4a-4ce8-b1b3-62c794a8c164
relation.isParentOrgUnitOfPublication.latestForDiscovery434c9663-2b11-4e66-9399-c863e2ebae43

Files