skip to main content

ACM is now Open Access

As part of the Digital Library's transition to Open Access, new features for researchers are available in the Premium Edition. Click here to learn more.

You are currently in the Basic Edition. Features requiring a subscription appear in grey.

10.1145/3637528.3671758acmconferencesArticle/Chapter ViewBasic AbstractPublication PageskddConference Proceedingsconference-collections
Several features on this page require Premium Access.
You are using the Basic Edition. Features requiring a subscription appear in grey.
research-article
Open access

Where Have You Been? A Study of Privacy Risk for Point-of-Interest Recommendation

Published: 24 August 2024 Publication History

Abstract

Abstract

As location-based services (LBS) have grown in popularity, more human mobility data has been collected. The collected data can be used to build machine learning (ML) models for LBS to enhance their performance and improve overall experience for users. However, the convenience comes with the risk of privacy leakage since this type of data might contain sensitive information related to user identities, such as home/work locations. Prior work focuses on protecting mobility data privacy during transmission or prior to release, lacking the privacy risk evaluation of mobility data-based ML models. To better understand and quantify the privacy leakage in mobility data-based ML models, we design a privacy attack suite containing data extraction and membership inference attacks tailored for point-of-interest (POI) recommendation models, one of the most widely used mobility data-based ML models. These attacks in our attack suite assume different adversary knowledge and aim to extract different types of sensitive information from mobility data, providing a holistic privacy risk assessment for POI recommendation models. Our experimental evaluation using two real-world mobility datasets demonstrates that current POI recommendation models are vulnerable to our attacks. We also present unique findings to understand what types of mobility data are more susceptible to privacy attacks. Finally, we evaluate defenses against these attacks and highlight future directions and challenges.

AI Summary

AI-Generated Summary (Experimental)

This summary was generated using automated tools and was not authored or reviewed by the article's author(s). It is provided to support discovery, help readers assess relevance, and assist readers from adjacent research areas in understanding the work. It is intended to complement the author-supplied abstract, which remains the primary summary of the paper. The full article remains the authoritative version of record. Click here to learn more.

Click here to comment on the accuracy, clarity, and usefulness of this summary. Doing so will help inform refinements and future regenerated versions.

To view this AI-generated plain language summary, you must have Premium access.

Formats available

You can view the full content in the following formats:

Supplemental Material

MP4 File - Short Promotion Video "Where Have You Been? A Study of Privacy Risk for Point-of-Interest Recommendation"
The short promotion video introduces our research paper, "Where Have You Been? A Study of Privacy Risk for Point-of-Interest Recommendation" which will appear at KDD '24. As location-based services (LBS) have grown in popularity, more human mobility data has been collected. Considering the importance of privacy for personal mobility data and the often-overlooked privacy leakage through machine learning models trained on this data, we take the first step to evaluate the privacy risks of POI recommendation models, one of the most representative LBS. We provide a novel attack suite from both location and trajectory levels, incorporating unique mobility data characteristics for privacy evaluation. In this video, we will discuss the motivation, attack goals, and some key findings. Please refer to our paper for more detailed information, including our attack design, ablation results, and defense strategies.

References

[1]
Martin Abadi, Andy Chu, Ian Goodfellow, H Brendan McMahan, Ilya Mironov,Kunal Talwar, and Li Zhang. 2016. Deep learning with differential privacy. ACM SIGSAC Conference on Computer and Communications Security.
[2]
Miguel E Andrés, Nicolás E Bordenabe, Konstantinos Chatzikokolakis, and Catus-cia Palamidessi. 2013. Geo-indistinguishability: Differential privacy for location-based systems. ACM SIGSAC Conference on Computer and Communications Security.
[3]
Lei Bai, Lina Yao, Can Li, Xianzhi Wang, and Can Wang. 2020. Adaptive graph convolutional recurrent network for traffic forecasting. International Conference on Neural Information Processing Systems.
[4]
Andrew J Blumberg and Peter Eckersley. 2009. On locational privacy, and how to avoid losing it forever. (2009).
[5]
Nicolás E Bordenabe, Konstantinos Chatzikokolakis, and Catuscia Palamidessi. 2014. Optimal geo-indistinguishable mechanisms for location privacy. ACM SIGSAC Conference on Computer and Communications Security.
[6]
Nicholas Carlini, Steve Chien, Milad Nasr, Shuang Song, Andreas Terzis, and Florian Tramer. 2022. Membership inference attacks from first principles. IEEE Symposium on Security and Privacy.
[7]
Nicolas Carlini, Jamie Hayes, Milad Nasr, Matthew Jagielski, Vikash Sehwag, Florian Tramer, Borja Balle, Daphne Ippolito, and Eric Wallace. 2023. Extracting training data from diffusion models. 32nd USENIX Security Symposium (USENIX Security 23), 5253--5270.
[8]
Nicholas Carlini, Chang Liu, Úlfar Erlingsson, Jernej Kos, and Dawn Song. 2019. The Secret Sharer: Evaluating and testing unintended memorization in neural networks. USENIX Security Symposium.
[9]
Nicholas Carlini, Florian Tramer, Eric Wallace, Matthew Jagielski, Ariel Herbert- Voss, Katherine Lee, Adam Roberts, Tom Brown, Dawn Song, Ulfar Erlingsson, et al 2021. Extracting training data from large language models. 30th USENIX Security Symposium (USENIX Security 21), 2633--2650.
[10]
Meng Chen, Yang Liu, and Xiaohui Yu. 2014. Nlpmm: A next location predictor with markov modeling. Advances in Knowledge Discovery and Data Mining: Pacific-Asia Conference.
[11]
Chen Cheng, Haiqin Yang, Michael R Lyu, and Irwin King. 2013. Where you like to go next: Successive point-of-interest recommendation. International Joint Conference on Artificial Intelligence.
[12]
Eunjoon Cho, Seth A Myers, and Jure Leskovec. 2011. Friendship and mobility: user movement in location-based social networks. ACM SIGKDD International Conference on Knowledge Discovery and Data Mining.
[13]
Jiaxin Ding, Shichuan Xi, Kailong Wu, Pan Liu, Xinbing Wang, and Chenghu Zhou. 2022. Analyzing sensitive information leakage in trajectory embedding models. International Conference on Advances in Geographic Information Systems.
[14]
Cynthia Dwork, Aaron Roth, et al 2014. The algorithmic foundations of differential privacy. (2014).
[15]
EU. 2018. General data protection regulation. https://en.wikipedia.org/wiki/ General_Data_Protection_Regulation.
[16]
Angela Fan, Mike Lewis, and Yann Dauphin. 2018. Hierarchical neural story generation. (2018).
[17]
Natasha Fernandes, Mark Dras, and Annabelle McIver. 2019. Generalised differential privacy for text document processing. Springer International Publishing, Principles of Security and Trust: 8th International Conference, POST 2019, Held as Part of the European Joint Conferences on Theory and Practice of Software, ETAPS 2019, Prague, Czech Republic, April 6--11, 2019, Proceedings 8, 123--148.
[18]
Matt Fredrikson, Somesh Jha, and Thomas Ristenpart. 2015. Model inversion attacks that exploit confidence information and basic countermeasures. ACM SIGSAC Conference on Computer and Communications Security.
[19]
Matt Fredrikson, Somesh Jha, and Thomas Ristenpart. 2015. Model Inversion Attacks That Exploit Confidence Information and Basic Countermeasures. Proceedings of the 22nd ACM SIGSAC Conference on Computer and Communications Security, New York, NY, USA, 1322--1333. https://doi.org/10.1145/2810103.2813677
[20]
Sébastien Gambs, Marc-Olivier Killijian, and Miguel Núñez del Prado Cortez. 2014. De-anonymization attack on geolocated data. (2014).
[21]
Bugra Gedik and Ling Liu. 2005. Location privacy in mobile systems: A personalized anonymization model. IEEE International Conference on Distributed Computing Systems.
[22]
Philippe Golle and Kurt Partridge. 2009. On the anonymity of home/work location pairs. Springer, Pervasive Computing: 7th International Conference, Pervasive 2009, Nara, Japan, May 11--14, 2009. Proceedings 7, 390--397.
[23]
Maziar Gomrokchi, Susan Amin, Hossein Aboutalebi, Alexander Wong, and Doina Precup. 2023. Membership Inference Attacks Against Temporally Corre lated Data in Deep Reinforcement Learning, IEEE Access (2023).
[24]
Wajih Ul Hassan, Saad Hussain, and Adam Bates. 2018. Analysis of privacy protections in fitness tracking social networks-or-you can run, but can you hide? USENIX Security Symposium.
[25]
Jing He, Xin Li, and Lejian Liao. 2017. Category-aware next point-of-interest recommendation via listwise bayesian personalized ranking. International Joint Conference on Artificial Intelligence.
[26]
Benjamin Henne, Christian Szongott, and Matthew Smith. 2013. SnapMe if you can: Privacy threats of other peoples' geo-tagged media and what we can do about it. ACM Conference on Security and Privacy in Wireless and Mobile Networks.
[27]
Md. Ashraful Islam, Mir Mahathir Mohammad, Sarkar Snigdha Sarathi Das, and Mohammed Eunus Ali. 2020. A survey on deep learning based Point-Of-Interest (POI) recommendations. arXiv:cs.IR/2011.10187
[28]
Matthew Jagielski, Jonathan Ullman, and Alina Oprea. 2020. Auditing differentially private machine learning: How private is private SGD? (2020).
[29]
Tao Jiang, Helen J Wang, and Yih-Chun Hu. 2007. Preserving location privacy in wireless LANs. International Conference on Mobile Systems, Applications and Services.
[30]
Yuzhou Jiang, Emre Yilmaz, and Erman Ayday. 2023. Robust Fingerprint of Privacy-Preserving Location Trajectories. Proceedings on Privacy Enhancing Technologies (2023).
[31]
Dejiang Kong and Fei Wu. 2018. HST-LSTM: A hierarchical spatial-temporal long-short term memory network for location prediction. International Joint Conference on Artificial Intelligence.
[32]
John Krumm. 2007. Inference attacks on location tracks. Springer, Pervasive Computing: 5th International Conference, PERVASIVE 2007, Toronto, Canada, May 13--16, 2007. Proceedings 5, 127--143.
[33]
John Krumm. 2007. Inference attacks on location tracks. Springer, Pervasive Computing: 5th International Conference, PERVASIVE 2007, Toronto, Canada, May 13--16, 2007. Proceedings 5, 127--143.
[34]
Shiyong Lan, Yitong Ma, Weikang Huang, Wenwu Wang, Hongyu Yang, and Pyang Li. 2022. Dstagnn: Dynamic spatial-temporal aware graph neural network for traffic flow forecasting. International Conference on Machine Learning.
[35]
Defu Lian, Yongji Wu, Yong Ge, Xing Xie, and Enhong Chen. 2020. Geography-aware sequential location recommendation. ACM SIGKDD International Conference on Knowledge Discovery and Data Mining.
[36]
Defu Lian, Cong Zhao, Xing Xie, Guangzhong Sun, Enhong Chen, and Yong Rui. 2014. GeoMF: Joint geographical modeling and matrix factorization for point-of-interest recommendation. ACM SIGKDD International Conference on Knowledge Discovery and Data Mining.
[37]
Q. Liu, Shu Wu, Liang Wang, and Tieniu Tan. 2016. Predicting the next location: A recurrent model with spatial and temporal contexts. AAAI Conference on Artificial Intelligence.
[38]
Yanchi Liu, Chuanren Liu, Xinjiang Lu, Mingfei Teng, Hengshu Zhu, and Hui Xiong. 2017. Point-of-Interest demand modeling with human mobility patterns. ACM SIGKDD International Conference on Knowledge Discovery and Data Mining.
[39]
Yingtao Luo, Qiang Liu, and Zhaocheng Liu. 2021. Stan: Spatio-temporal attention network for next location recommendation. Web Conference.
[40]
Chuishi Meng, Yu Cui, Qing He, Lu Su, and Jing Gao. 2017. Travel purpose inference with GPS trajectories, POIs, and geo-tagged social media data. IEEE International Conference on Big Data.
[41]
Joseph Meyerowitz and Romit Roy Choudhury. 2009. Hiding stars with fireworks: location privacy through camouflage. Annual International Conference on Mobile Computing and Networking.
[42]
Mike Boland. 2021. Foursquare's power play continues with relaunched places and new API. https://www.localogy.com/2021/03/foursquares-power-play-continues-with-relaunched-places-and-new-api/
[43]
Àlex Miranda-Pascual, Patricia Guerra-Balboa, Javier Parra-Arnau, Jordi Forné, and Thorsten Strufe. 2023. SoK: Differentially private publication of trajectory data. Proceedings on Privacy Enhancing Technologies (2023).
[44]
Jovan Powar and Alastair R Beresford. 2023. SoK: Managing risks of linkage attacks on data privacy. (2023).
[45]
Apostolos Pyrgelis, Carmela Troncoso, and Emiliano De Cristofaro. 2017. Knock knock, who's there? Membership inference on aggregate location data. (2017).
[46]
Apostolos Pyrgelis, Carmela Troncoso, and Emiliano De Cristofaro. 2020. Measuring membership privacy on aggregate location time-series. Proceedings of the ACM on Measurement and Analysis of Computing Systems 4, 2 (2020), 1--28.
[47]
Jinmeng Rao, Song Gao, Yuhao Kang, and Qunying Huang. 2020. LSTM-TrajGAN: A deep learning approach to trajectory privacy protection. arXiv preprint arXiv:2006.10521.
[48]
Lingfei Ren, Ruimin Hu, Dengshi Li, Zheng Wang, Junhang Wu, Xixi Li, and Wenyi Hu. 2023. Who is your friend: inferring cross-regional friendship from mobility profiles. (2023).
[49]
Ahmed Salem, Yang Zhang, Mathias Humbert, Pascal Berrang, Mario Fritz, and Michael Backes. 2018. Ml-leaks: Model and data independent membership inference attacks and defenses on machine learning models. (2018).
[50]
Weiyan Shi, Si Chen, Chiyuan Zhang, Ruoxi Jia, and Zhou Yu. 2022. Just fine-tune twice: Selective differential privacy for large language models. (2022).
[51]
Weiyan Shi, Aiqi Cui, Evan Li, Ruoxi Jia, and Zhou Yu. 2022. Selective Differential Privacy for Language Modeling. Conference of the North American Chapter of the Association for Computational Linguistics: Human Language Technologies.
[52]
Reza Shokri, Marco Stronati, Congzheng Song, and Vitaly Shmatikov. 2017. Membership inference attacks against machine learning models. IEEE Symposium on Security and Privacy.
[53]
R. Shokri, M. Stronati, C. Song, and V. Shmatikov. 2017. Membership inference attacks against machine learning models. IEEE Symposium on Security and Privacy.
[54]
Reza Shokri, George Theodorakopoulos, Panos Papadimitratos, Ehsan Kazemi, and Jean-Pierre Hubaux. 2013. Hiding in the mobile crowd: Location privacy through collaboration. (2013).
[55]
Shubham Sharma. 2022. How Foursquare helps enterprises drive positive results with geospatial technology. https://venturebeat.com/data-infrastructure/how-foursquare-helps-enterprises/
[56]
Mudhakar Srivatsa and Mike Hicks. 2012. Deanonymizing mobility traces: Using social network as a side-channel. ACM Conference on Computer and Communications Security.
[57]
Mudhakar Srivatsa and Mike Hicks. 2012. Deanonymizing mobility traces: Using social network as a side-channel. ACM Conference on Computer and Communications Security.
[58]
Ke Sun, Tieyun Qian, Tong Chen, Yile Liang, Quoc Viet Hung Nguyen, and Hongzhi Yin. 2020. Where to go next: Modeling long-and short-term user preferences for point-of-interest recommendation. AAAI Conference on Artificial Intelligence.
[59]
Florian Tramèr, Reza Shokri, Ayrton San Joaquin, Hoang Le, Matthew Jagielski, Sanghyun Hong, and Nicholas Carlini. 2022. Truth serum: Poisoning machine learning models to reveal their secrets. ACM SIGSAC Conference on Computer and Communications Security.
[60]
Carmen Ruiz Vicente, Dario Freni, Claudio Bettini, and Christian S Jensen. 2011. Location-related privacy in geo-social networks. (2011).
[61]
Nevena Vratonjic, Kévin Huguenin, Vincent Bindschaedler, and Jean-Pierre Hubaux. 2014. A location-privacy threat stemming from the use of shared public IP addresses. (2014).
[62]
Huandong Wang, Changzheng Gao, Yuchen Wu, Depeng Jin, Lina Yao, and Yong Li. 2023. PateGail: a privacy-preserving mobility trajectory generator with imitation learning. In Proceedings of the AAAI Conference on Artificial Intelligence .
[63]
Jingyuan Wang, Jiawei Jiang, Wenjun Jiang, Chao Li, and Wayne Xin Zhao. 2021. LibCity: An open library for traffic prediction. International Conference on Advances in Geographic Information Systems.
[64]
Zehui Wang, Wolfram Höpken, and Dietmar Jannach. 2023. A survey on Point-of-Interest recommendations leveraging heterogeneous data. arXiv:cs.IR/2308.07426
[65]
Zhibo Wang, Wenxin Liu, Xiaoyi Pang, Ju Ren, Zhe Liu, and Yongle Chen. 2020. Towards pattern-aware privacy-preserving real-time data collection. In IEEE INFOCOM 2020-IEEE Conference on Computer Communications . IEEE.
[66]
Haoran Xin, Xinjiang Lu, Tong Xu, Hao Liu, Jingjing Gu, Dejing Dou, and Hui Xiong. 2021. Out-of-town recommendation with travel intention modeling. arXiv:cs.IR/2101.12555
[67]
Dingqi Yang, Benjamin Fankhauser, Paolo Rosso, and Philippe Cudre-Mauroux. 2020. Location prediction over sparse user mobility traces using rnns. International Joint Conference on Artificial Intelligence.
[68]
Dingqi Yang, Daqing Zhang, Vincent W Zheng, and Zhiyong Yu. 2014. Modeling user activity preference by leveraging user spatial temporal characteristics in LBSNs. (2014).
[69]
Song Yang, Jiamou Liu, and Kaiqi Zhao. 2022. GETNext: Trajectory flow map enhanced transformer for next POI recommendation. ACM SIGIR Conference on Research and Development in Information Retrieval.
[70]
Guanglin Zhang, Anqi Zhang, and Ping Zhao. 2020. Locmia: Membership inference attacks against aggregated location data. (2020).
[71]
Jia-Dong Zhang, Chi-Yin Chow, and Yanhua Li. 2014. Lore: Exploiting sequential influence for location recommendations. ACM SIGSPATIAL International Conference on Advances in Geographic Information Systems.
[72]
Shenglin Zhao, Tong Zhao, Haiqin Yang, Michael Lyu, and Irwin King. 2016. STELLAR: Spatial-temporal latent ranking for successive point-of-interest recommendation. AAAI Conference on Artificial Intelligence.

Cited By

View all
  • (2026)Leveraging the Spatial Hierarchy: Coarse-to-fine Trajectory Generation via Cascaded Hybrid DiffusionProceedings of the 32nd ACM SIGKDD Conference on Knowledge Discovery and Data Mining V.110.1145/3770854.3780191(359-370)Online publication date: 9-Aug-2026
  • (2026)SynHAT: A Two-stage Coarse-to-Fine Diffusion Framework for Synthesizing Human Activity TracesProceedings of the ACM on Interactive, Mobile, Wearable and Ubiquitous Technologies10.1145/381021310:2(1-35)Online publication date: 15-Jun-2026
  • (2026)MRP-LLM: Multitask Reflective Large Language Models for Privacy-Preserving Next POI RecommendationProceedings of the 34th ACM Conference on User Modeling, Adaptation and Personalization10.1145/3774935.3806151(166-174)Online publication date: 8-Jun-2026
  • Show More Cited By

Recommendations

Comments

Please enable JavaScript to view thecomments powered by Disqus.

Information & Contributors

Information

Published In

cover image ACM Conferences
KDD '24: Proceedings of the 30th ACM SIGKDD Conference on Knowledge Discovery and Data Mining
August 2024
6901 pages
ISBN:9798400704901
DOI:10.1145/3637528
This work is licensed under a Creative Commons Attribution International 4.0 License.

Sponsors

Publisher

Association for Computing Machinery

New York, NY, United States

Publication History

Published: 24 August 2024

Check for updates

Author Tags

  1. data extraction
  2. membership inference
  3. poi recommendation
  4. privacy-preserving machine learning

Qualifiers

  • Research-article

Funding Sources

Conference

KDD '24
Sponsor:

Acceptance Rates

KDD '24 Paper Acceptance Rate Not Available
Overall Acceptance Rate 2,008 of 13,188 submissions, 15%

Upcoming Conference

KDD '26
The 32nd ACM SIGKDD Conference on Knowledge Discovery and Data Mining
August 9 - 13, 2026
Jeju Island , Republic of Korea

Contributors

Other Metrics

Bibliometrics & Citations

Bibliometrics

Article Metrics

  • Downloads (Last 12 months)...
  • Downloads (Last 6 weeks) ...
Reflects downloads up to 27 Jul 2026

Other Metrics

Citations

Cited By

View all
  • (2026)Leveraging the Spatial Hierarchy: Coarse-to-fine Trajectory Generation via Cascaded Hybrid DiffusionProceedings of the 32nd ACM SIGKDD Conference on Knowledge Discovery and Data Mining V.110.1145/3770854.3780191(359-370)Online publication date: 9-Aug-2026
  • (2026)SynHAT: A Two-stage Coarse-to-Fine Diffusion Framework for Synthesizing Human Activity TracesProceedings of the ACM on Interactive, Mobile, Wearable and Ubiquitous Technologies10.1145/381021310:2(1-35)Online publication date: 15-Jun-2026
  • (2026)MRP-LLM: Multitask Reflective Large Language Models for Privacy-Preserving Next POI RecommendationProceedings of the 34th ACM Conference on User Modeling, Adaptation and Personalization10.1145/3774935.3806151(166-174)Online publication date: 8-Jun-2026
  • (2025)Optimized tourist point-of-interest recommendation through ARIMA and SVD in edge environmentJournal of Cloud Computing: Advances, Systems and Applications10.1186/s13677-025-00793-214:1Online publication date: 12-Nov-2025
  • (2025)FedHGS: A Federated Point-of-Interest Recommendation Method Based on Heterogeneous Graph SemanticsIEEE Transactions on Services Computing10.1109/TSC.2025.360791818:6(3780-3793)Online publication date: Nov-2025
  • (2025)Social Relation-Level Privacy Risks and Preservation in Social Recommender SystemsProceedings of the 48th International ACM SIGIR Conference on Research and Development in Information Retrieval10.1145/3726302.3730086(1728-1737)Online publication date: 13-Jul-2025
  • (2025)A multi-criteria attention-LSTM approach for enhancing privacy and accuracy in recommender systemsSocial Network Analysis and Mining10.1007/s13278-025-01458-315:1Online publication date: 11-Apr-2025
  • (2024)Multi-Device Context-Sensitive Attacks Against PrivacyProceedings of the Fifteenth ACM Conference on Data and Application Security and Privacy10.1145/3714393.3726508(209-220)Online publication date: 19-Jun-2024

Share

Share

Share this Publication link

Share on social media

Morty Proxy This is a proxified and sanitized view of the page, visit original site.