TY - GEN
T1 - Optimal Obfuscation Mechanisms via Machine Learning
AU - Romanelli, Marco
AU - Chatzikokolakis, Kostantinos
AU - Palamidessi, Catuscia
N1 - Publisher Copyright:
© 2020 IEEE.
PY - 2020/6/1
Y1 - 2020/6/1
N2 - We consider the problem of obfuscating sensitive information while preserving utility, and we propose a machine-learning approach inspired by the generative adversarial networks paradigm. The idea is to set up two nets: the generator, that tries to produce an optimal obfuscation mechanism to protect the data, and the classifier, that tries to de-obfuscate the data. By letting the two nets compete against each other, the mechanism improves its degree of protection, until an equilibrium is reached. We apply our method to the case of location privacy, and we perform experiments on synthetic data and on real data from the Gowalla dataset. We evaluate the privacy of the mechanism not only by its capacity to defeat the classifier, but also in terms of the Bayes error, which represents the strongest possible adversary. We compare the privacy-utility tradeoff of our method with that of the planar Laplace mechanism used in geo-indistinguishability, showing favorable results. Like the Laplace mechanism, our system can be deployed at the user end for protecting his location.
AB - We consider the problem of obfuscating sensitive information while preserving utility, and we propose a machine-learning approach inspired by the generative adversarial networks paradigm. The idea is to set up two nets: the generator, that tries to produce an optimal obfuscation mechanism to protect the data, and the classifier, that tries to de-obfuscate the data. By letting the two nets compete against each other, the mechanism improves its degree of protection, until an equilibrium is reached. We apply our method to the case of location privacy, and we perform experiments on synthetic data and on real data from the Gowalla dataset. We evaluate the privacy of the mechanism not only by its capacity to defeat the classifier, but also in terms of the Bayes error, which represents the strongest possible adversary. We compare the privacy-utility tradeoff of our method with that of the planar Laplace mechanism used in geo-indistinguishability, showing favorable results. Like the Laplace mechanism, our system can be deployed at the user end for protecting his location.
U2 - 10.1109/CSF49147.2020.00019
DO - 10.1109/CSF49147.2020.00019
M3 - Conference contribution
AN - SCOPUS:85090451274
T3 - Proceedings - IEEE Computer Security Foundations Symposium
SP - 153
EP - 168
BT - Proceedings - 2020 IEEE 33rd Computer Security Foundations Symposium, CSF 2020
PB - IEEE Computer Society
T2 - 33rd IEEE Computer Security Foundations Symposium, CSF 2020
Y2 - 22 June 2020 through 25 June 2020
ER -