Paper 2014/502

What's the Gist? Privacy-Preserving Aggregation of User Profiles

Igor Bilogrevic, Julien Freudiger, Emiliano De Cristofaro, and Ersin Uzun

Abstract

Over the past few years, online service providers have started gathering increasing amounts of personal information to build user profiles and monetize them with advertisers and data brokers. Users have little control of what information is processed and are often left with an all-or-nothing decision between receiving free services or refusing to be profiled. This paper explores an alternative approach where users only disclose an aggregate model -- the ``gist'' -- of their data. We aim to preserve data utility and simultaneously provide user privacy. We show that this approach can be efficiently supported by letting users contribute encrypted and differentially-private data to an aggregator. The aggregator combines encrypted contributions and can only extract an aggregate model of the underlying data. We evaluate our framework on a dataset of 100,000 U.S. users obtained from the U.S. Census Bureau and show that (i) it provides accurate aggregates with as little as 100 users, (ii) it generates revenue for both users and data brokers, and (iii) its overhead is appreciably low.

Metadata
Available format(s)
PDF
Category
Applications
Publication info
Published elsewhere. ESORICS 2014
Keywords
privacy
Contact author(s)
me @ emilianodc com
History
2014-06-27: last of 2 revisions
2014-06-26: received
See all versions
Short URL
https://ia.cr/2014/502
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2014/502,
      author = {Igor Bilogrevic and Julien Freudiger and Emiliano De Cristofaro and Ersin Uzun},
      title = {What's the Gist? Privacy-Preserving Aggregation of User Profiles},
      howpublished = {Cryptology {ePrint} Archive, Paper 2014/502},
      year = {2014},
      url = {https://eprint.iacr.org/2014/502}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.