Konum Tabanlı Servislerde Mahremiyet

Yazarlar

Şeyda Danyıldızı
Yavuz Canbay

Özet

Mobil cihazların ve konum tabanlı servislerin yaygınlaşması, büyük miktarda mekân-zamansal yörünge verisinin toplanmasını kolaylaştırmıştır. Bu veriler bireylerin günlük rutinleri, alışkanlıkları ve sağlık bilgileri gibi hassas kişisel detayları barındırdığından, doğrudan paylaşılması ciddi mahremiyet ihlallerine yol açmaktadır. Özel hayatın gizliliği ve KVKK kapsamında, veri sorumlularının bu verileri yayınlamadan önce teknik tedbirler alması ve anonimleştirme yöntemlerini uygulaması yasal bir zorunluluktur. Literatürde yörünge verilerinin korunması amacıyla k-anonimlik, l-çeşitlilik, t-yakınlık ve diferansiyel mahremiyet gibi istatistiksel yöntemler sıklıkla tercih edilmektedir. Geleneksel bir yöntem olan k-anonimlik, yüksek hesaplama maliyeti gerektirmesi, güvenilir üçüncü taraf sunuculara ihtiyaç duyması ve saldırganların arka plan bilgisi karşısında yetersiz kalması gibi dezavantajlara sahiptir. Buna karşılık diferansiyel mahremiyet, sorgu sonuçlarına gürültü ekleyerek çalışan ve saldırganın arka plan bilgisine sahip olduğu durumlarda bile kesin çıkarımlar yapmasını engelleyen matematiksel bir modeldir. Bu çalışma, literatürde yörünge verilerinin anonimleştirilmesi üzerine yapılan güncel akademik araştırmaları, kullanılan veri kümelerini, önerilen metotları ve başarı metriklerini kapsamlı bir şekilde incelemektedir. Sonuç ve değerlendirmeler, diferansiyel mahremiyetin geleneksel modellere kıyasla veri faydası ve mahremiyet dengesini çok daha iyi sağladığını ve konum tabanlı servislerde en güvenilir çözüm olarak öne çıktığını göstermektedir.

The proliferation of mobile devices and location-based services has facilitated the collection of massive amounts of spatio-temporal trajectory data. Since this data contains sensitive personal details such as individuals' daily routines, habits, and health information, its direct disclosure leads to severe privacy violations. Under the scope of the right to privacy and the Personal Data Protection Law (KVKK), data controllers are legally obligated to take technical measures and apply anonymization methods before publishing this data. In the literature, statistical methods such as k-anonymity, l-diversity, t-closeness, and differential privacy are frequently preferred to protect trajectory data. As a traditional method, k-anonymity possesses disadvantages such as requiring high computational costs, relying on trusted third-party servers, and remaining insufficient against attackers with background knowledge. Conversely, differential privacy is a mathematical model that works by adding noise to query results, preventing attackers from making definitive inferences even when they possess background knowledge. This study comprehensively reviews current academic research, utilized datasets, proposed methods, and success metrics regarding the anonymization of trajectory data in the literature. Findings and evaluations demonstrate that differential privacy balances data utility and privacy much better than traditional models, standing out as the most reliable solution for location-based services.

Referanslar

N. Nisha, I. Natgunanathan, S. Gao, and Y. Xiang, "A novel privacy protection scheme for location-based services using collaborative caching," Computer Networks, vol. 213, p. 109107, 2022.

H. Navidan, V. Moghtadaiee, N. Nazaran, and M. Alishahi, "Hide me behind the noise: local differential privacy for indoor location privacy," in 2022 IEEE European Symposium on Security and Privacy Workshops (EuroS&PW), 2022: IEEE, pp. 514-523.

M. Douriez, H. Doraiswamy, J. Freire, and C. T. Silva, "Anonymizing nyc taxi data: Does it matter?," in 2016 IEEE international conference on data science and advanced analytics (DSAA), 2016: IEEE, pp. 140-148.

A. T. Hasan, Q. Jiang, C. Li, and L. Chen, "An effective model for anonymizing personal location trajectory," in Proceedings of the 6th International Conference on Communication and Network Security, 2016, pp. 35-39.

X. Kong et al., "Big trajectory data: A survey of applications and services," IEEE Access vol. 6, pp. 58295-58306, 2018.

R. Talat, M. S. Obaidat, M. Muzammal, A. H. Sodhro, Z. Luo, and S. Pirbhulal, "A decentralised approach to privacy preserving trajectory mining," Future Generation Computer Systems, vol. 102, pp. 382-392, 2020.

P. Canbay and H. Sever, "The Effect of clustering on data privacy," in 2015 IEEE 14th International Conference on Machine Learning and Applications (ICMLA), 2015: IEEE, pp. 277-282.

K. Gu, L. Yang, Y. Liu, and N. Liao, "Trajectory data privacy protection based on differential privacy mechanism," in IOP Conference Series: Materials Science and Engineering, 2018, vol. 351, no. 1: IOP Publishing, p. 012017.

R. Wazirali, "A Review on Privacy Preservation of Location-Based Services in Internet of Things," Intelligent Automation Soft Computing, vol. 31, no. 2, pp. 767-779, 2022.

A. Aloui, O. Kazar, S. Bourekkache, and A. Chikh, "Protecting user privacy in location-based services over road networks," Journal of Location Based Services, pp. 1-42, 2022.

K. V. K. Kurumu, "100 Soruda Kişisel Verilerin Korunması Kanunu," KVKK Yayınları ISBN : 978-975-19-6883-8, p. 86, Nisan 2018, Ankara 2018. [Online]. Available: https://www.kvkk.gov.tr/.

Ş. AKKAYA, "Derin Öğrenme Yöntemi İle Diferansiyel Mahremiyetli Medikal Görüntü Sınıflandırma," Yüksek Lisans Tezi, Gazi Üniversitesi Fen Bilimleri Enstitüsü, p. 77, 2021.

Y. VURAL, "Veri Mahremiyeti: Saldırılar, Korunma Ve Yeni Bir Çözüm Önerisi," Uluslararası Bilgi Güvenliği Mühendisliği Dergisi, vol. 4, no. 2, pp. 21-34, 2018.

C. Mauger, G. Le Mahec, and G. Dequen, "Modeling and evaluation of k-anonymization metrics," in PrivacyPreserving Artificial Intelligence Workshop of AAAI, 2020.

K. Zickuhr, "Location-based services," Pew Research, vol. 679, p. 695, 2013. [Online]. Available: www.pewresearch.org.

X. Yin, Y. Zhu, and J. Hu, "A comprehensive survey of privacy-preserving federated learning: A taxonomy, review, and future directions," ACM Computing Surveys, vol. 54, no. 6, pp. 1-36, 2021.

Z. Xu, J. Zhang, P.-w. Tsai, L. Lin, and C. Zhuo, "Spatiotemporal mobility based trajectory privacy-preserving algorithm in location-based services," Sensors, vol. 21, no. 6, p. 2021, 2021.

X. Zhao, D. Pi, and J. Chen, "Novel trajectory privacy-preserving method based on clustering using differential privacy," Expert Systems with Applications, vol. 149, p. 113241, 2020.

K. V. K. Kurumu, Kişisel Verilerin Silinmesi, Yok Edilmesi Veya Anonim Hale Getirilmesi. https://www.kvkk.gov.tr/: Kişisel Verileri Koruma Kurumu, 2017.

İ. Ali and V. Esra, "Sınıflandırma için diferansiyel mahremiyete dayalı öznitelik seçimi," Gazi Üniversitesi Mühendislik Mimarlık Fakültesi Dergisi, vol. 33, no. 1, 2018.

P. Samarati and L. Sweeney, "Protecting privacy when disclosing information: k-anonymity and its enforcement through generalization and suppression," 1998.

S. Chang, C. Li, H. Zhu, T. Lu, and Q. Li, "Revealing privacy vulnerabilities of anonymous trajectories," IEEE Transactions on Vehicular Technology, vol. 67, no. 12, pp. 12061-12071, 2018.

S. Shaham, M. Ding, B. Liu, Z. Lin, and J. Li, "Machine learning aided anonymization of spatiotemporal trajectory datasets," in IEEE INFOCOM 2019-IEEE Conference on Computer Communications Workshops (INFOCOM WKSHPS), 2019: IEEE, pp. 1-6.

J. Liu and S. Wang, "All-dummy k-anonymous privacy protection algorithm based on location offset," Computing, pp. 1-13, 2022.

T. Peng, Q. Liu, D. Meng, and G. Wang, "Collaborative trajectory privacy preserving scheme in location-based services," Information Sciences, vol. 387, pp. 165-179, 2017.

O. Abul, F. Bonchi, and M. Nanni, "Never walk alone: Uncertainty for anonymity in moving objects databases," in 2008 IEEE 24th international conference on data engineering, 2008: Ieee, pp. 376-385.

N. Rajesh, S. Abraham, S. S. J. I. J. o. C. S. Das, and Engineering, "Trajectory Anonymization Through Generalization of Significant Location Points," vol. 6, 2018.

C. Dwork, "Differential privacy: A survey of results," in International conference on theory and applications of models of computation, 2008: Springer, pp. 1-19.

X. Zhao, Y. Dong, and D. Pi, "Novel trajectory data publishing method under differential privacy," Expert Systems with Applications, vol. 138, p. 112791, 2019.

J. P. Near and C. Abuah, "Programming Differential Privacy," open-source book, p. 108, 2021. [Online]. Available: programming-dp.com.

N. Fernandes, A. McIver, and C. Morgan, "The Laplace Mechanism has optimal utility for differential privacy over continuous queries," in 2021 36th Annual ACM/IEEE Symposium on Logic in Computer Science (LICS), 2021: IEEE, pp. 1-12.

W. Cheng, R. Wen, H. Huang, W. Miao, and C. Wang, "OPTDP: Towards optimal personalized trajectory differential privacy for trajectory data publishing," Neurocomputing, vol. 472, pp. 201-211, 2022.

D. Su, J. Cao, N. Li, E. Bertino, and H. Jin, "Differentially private k-means clustering," in Proceedings of the sixth ACM conference on data and application security and privacy, 2016, pp. 26-37.

Q. Han, Z. Xiong, and K. Zhang, "Research on trajectory data releasing method via differential privacy based on spatial partition," Security Communication Networks vol. 2018, 2018.

R. Chen, B. Fung, and B. C. Desai, "Differentially private trajectory data publication," Cornell University arXiv 2011.

H. Li, Y. Guo, and X. Ren, "An Efficient Location Privacy Protection Method for Location-Based Services based on Differential Privacy," Research Square, p. 26, 2022.

Y. Yan, Z. Sun, A. Mahmood, F. Xu, Z. Dong, and Q. Z. Sheng, "Achieving Differential Privacy Publishing of Location-Based Statistical Data Using Grid Clustering," ISPRS International Journal of Geo-Information, vol. 11, no. 7, p. 404, 2022.

F. Tian, S. Zhang, L. Lu, H. Liu, and X. Gui, "A novel personalized differential privacy mechanism for trajectory data publication," in 2017 International Conference on Networking and Network Applications (NaNA), 2017: IEEE, pp. 61-68.

A. Murat, Y. CANBAY, and Ş. SAĞIROĞLU, "Yörünge Verisi Yayınlamada Mahremiyet Duyarlı Yeni Bir Model Önerisi ve Uygulaması," Politeknik Dergisi, pp. 1-1.

C. Bayrak, "Konum tabanlı uygulamalarda konum ve konum örüntü mahremiyetinin sağlanması," TOBB ETÜ Fen Bilimleri Enstitüsü, 2016.

D. E. Seidl, P. Jankowski, and M.-H. Tsou, "Privacy and spatial pattern preservation in masked GPS trajectory data," International Journal of Geographical Information Science, vol. 30, no. 4, pp. 785-800, 2016.

S. B. Avaghade and S. S. Patil, "Privacy preserving for spatio-temporal data publishing ensuring location diversity using K-anonymity technique," in 2015 International Conference on Computer, Communication and Control (IC4), 2015: IEEE, pp. 1-6.

Z. Tu, K. Zhao, F. Xu, Y. Li, L. Su, and D. Jin, "Protecting Trajectory From Semantic Attack Considering ${k} $-Anonymity, ${l} $-Diversity, and ${t} $-Closeness," IEEE Transactions on Network Service Management vol. 16, no. 1, pp. 264-278, 2018.

L. Yao, Z. Chen, H. Hu, G. Wu, and B. Wu, "Sensitive attribute privacy preservation of trajectory data publishing based on l-diversity," Distributed parallel databases vol. 39, no. 3, pp. 785-811, 2021.

Yayınlanan

5 Aralık 2022

Lisans

Lisans