Dual Protection Ring: User Profiling Via Differential Privacy and Service Dissemination Through Private Information Retrieval

📅 2025-06-16
📈 Citations: 0
Influential: 0
📄 PDF

career value

258K/year
🤖 AI Summary
User profiling enables personalized services but introduces severe privacy risks, including behavioral tracking, device fingerprinting, and profile reconstruction attacks. To address these threats, we propose a dual-loop collaborative privacy-preserving framework: (1) On the client side, we employ differential privacy to generate perturbed profiles, integrating dynamic profile entropy control and data evaporation mechanisms to achieve attribute-level controllable privacy decay; (2) On the server side, we adopt a multi-variant private information retrieval (PIR) scheme to enable on-demand service access while preserving end-to-end privacy. To our knowledge, this is the first dual-loop defense framework explicitly designed under formal behavioral attack modeling. Evaluated in an advertising recommendation scenario, our approach achieves latency comparable to baseline methods while reducing sensitive attribute leakage risk by 92.7%, demonstrating significantly enhanced robustness against diverse profiling attacks.

Technology Category

Application Category

📝 Abstract
User profiling is crucial in providing personalised services, as it relies on analysing user behaviour and preferences to deliver targeted services. This approach enhances user experience and promotes heightened engagement. Nevertheless, user profiling also gives rise to noteworthy privacy considerations due to the extensive tracking and monitoring of personal data, potentially leading to surveillance or identity theft. We propose a dual-ring protection mechanism to protect user privacy by examining various threats to user privacy, such as behavioural attacks, profiling fingerprinting and monitoring, profile perturbation, etc., both on the user and service provider sides. We develop user profiles that contain sensitive private attributes and an equivalent profile based on differential privacy for evaluating personalised services. We determine the entropy of the resultant profiles during each update to protect profiling attributes and invoke various processes, such as data evaporation, to artificially increase entropy or destroy private profiling attributes. Furthermore, we use different variants of private information retrieval (PIR) to retrieve personalised services against differentially private profiles. We implement critical components of the proposed model via a proof-of-concept mobile app to demonstrate its applicability over a specific case study of advertising services, which can be generalised to other services. Our experimental results show that the observed processing delays with different PIR schemes are similar to the current advertising systems.
Problem

Research questions and friction points this paper is trying to address.

Protecting user privacy in profiling via differential privacy
Preventing behavioral attacks and profile fingerprinting threats
Enhancing private information retrieval for personalized services
Innovation

Methods, ideas, or system contributions that make the work stand out.

Dual-ring protection via differential privacy
Private information retrieval for service dissemination
Data evaporation to increase profile entropy
🔎 Similar Papers
Imdad Ullah
Imdad Ullah
USYD, UNSW Sydney AU, Data61| CSIRO
PrivacyData analyticsLLMsBlockchainIoT
N
Najm Hassan
Higher Colleges of Technology, United Arab Emirates (UAE)
T
Tariq Ahamed Ahangar
Management Information Systems Department, College of Business Administration, Prince Sattam bin Abdulaziz University, Al-Kharj 16278, Saudi Arabia
Z
Zawar Hussain Shah
Department of Information Technology, Sydney International School of Technology and Commerce, Sydney NSW 2000, Australia
M
Mehregan Mahdavi
Kingsford Institute of Higher Education (KIHE), Sydney NSW 2000, Australia
A
Andrew Levula
School of Business, Excelsia College, Sydney NSW 2113, Australia