<?xml version="1.0" encoding="utf-8"?>
<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.1 plus MathML 2.0 plus SVG 1.1//EN" "http://www.w3.org/2002/04/xhtml-math-svg/xhtml-math-svg.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
  <head>
    <meta http-equiv="Content-Type" content="application/xhtml+xml; charset=utf-8"/>
    <title>Project-Team:COMETE</title>
    <link rel="stylesheet" href="../static/css/raweb.css" type="text/css"/>
    <meta name="description" content="New Results - Foundations of information hiding "/>
    <meta name="dc.title" content="New Results - Foundations of information hiding "/>
    <meta name="dc.subject" content=""/>
    <meta name="dc.publisher" content="INRIA"/>
    <meta name="dc.date" content="(SCHEME=ISO8601) 2015-01"/>
    <meta name="dc.type" content="Report"/>
    <meta name="dc.language" content="(SCHEME=ISO639-1) en"/>
    <meta name="projet" content="COMETE"/>
    <!-- Piwik -->
    <script type="text/javascript" src="/rapportsactivite/piwik.js"></script>
    <noscript><p><img src="//piwik.inria.fr/piwik.php?idsite=49" style="border:0;" alt="" /></p></noscript>
    <!-- End Piwik Code -->
  </head>
  <body>
    <div class="tdmdiv">
      <div class="logo">
        <a href="http://www.inria.fr">
          <img style="align:bottom; border:none" src="../static/img/icons/logo_INRIA-coul.jpg" alt="Inria"/>
        </a>
      </div>
      <div class="TdmEntry">
        <div class="tdmentete">
          <a href="uid0.html">Project-Team Comete</a>
        </div>
        <span>
          <a href="uid1.html">Members</a>
        </span>
      </div>
      <div class="TdmEntry">
        <a href="./uid3.html">Overall Objectives</a>
      </div>
      <div class="TdmEntry">Research Program<ul><li><a href="uid5.html&#10;&#9;&#9;  ">Probability and information theory</a></li><li><a href="uid6.html&#10;&#9;&#9;  ">Expressiveness of Concurrent Formalisms</a></li><li><a href="uid7.html&#10;&#9;&#9;  ">Concurrent constraint programming</a></li><li><a href="uid10.html&#10;&#9;&#9;  ">Model checking</a></li></ul></div>
      <div class="TdmEntry">Application Domains<ul><li><a href="uid12.html&#10;&#9;&#9;  ">Security and privacy</a></li></ul></div>
      <div class="TdmEntry">
        <a href="./uid14.html">Highlights of the Year</a>
      </div>
      <div class="TdmEntry">New Software and Platforms<ul><li><a href="uid19.html&#10;&#9;&#9;  ">Location Guard</a></li></ul></div>
      <div class="TdmEntry">New Results<ul><li class="tdmActPage"><a href="uid21.html&#10;&#9;&#9;  ">Foundations of information hiding </a></li><li><a href="uid26.html&#10;&#9;&#9;  ">Foundations of Concurrency</a></li></ul></div>
      <div class="TdmEntry">Partnerships and Cooperations<ul><li><a href="uid31.html&#10;&#9;&#9;  ">National Initiatives</a></li><li><a href="uid39.html&#10;&#9;&#9;  ">European Initiatives</a></li><li><a href="uid51.html&#10;&#9;&#9;  ">International Initiatives</a></li><li><a href="uid105.html&#10;&#9;&#9;  ">International Research Visitors</a></li></ul></div>
      <div class="TdmEntry">Dissemination<ul><li><a href="uid117.html&#10;&#9;&#9;  ">Promoting Scientific Activities</a></li><li><a href="uid190.html&#10;&#9;&#9;  ">Teaching - Supervision - Juries</a></li></ul></div>
      <div class="TdmEntry">
        <div>Bibliography</div>
      </div>
      <div class="TdmEntry">
        <ul>
          <li>
            <a id="tdmbibentmajor" href="bibliography.html">Major publications</a>
          </li>
          <li>
            <a id="tdmbibentyear" href="bibliography.html#year">Publications of the year</a>
          </li>
          <li>
            <a id="tdmbibentfoot" href="bibliography.html#References">References in notes</a>
          </li>
        </ul>
      </div>
    </div>
    <div id="main">
      <div class="mainentete">
        <div id="head_agauche">
          <small><a href="http://www.inria.fr">
	    
	    Inria
	  </a> | <a href="../index.html">
	    
	    Raweb 
	    2015</a> | <a href="http://www.inria.fr/en/teams/comete">Presentation of the Project-Team COMETE</a> | <a href="http://www.lix.polytechnique.fr/comete/">COMETE Web Site
	  </a></small>
        </div>
        <div id="head_adroite">
          <table class="qrcode">
            <tr>
              <td>
                <a href="comete.xml">
                  <img style="align:bottom; border:none" alt="XML" src="../static/img/icons/xml_motif.png"/>
                </a>
              </td>
              <td>
                <a href="comete.pdf">
                  <img style="align:bottom; border:none" alt="PDF" src="IMG/qrcode-comete-pdf.png"/>
                </a>
              </td>
              <td>
                <a href="../comete/comete.epub">
                  <img style="align:bottom; border:none" alt="e-pub" src="IMG/qrcode-comete-epub.png"/>
                </a>
              </td>
            </tr>
            <tr>
              <td/>
              <td>PDF
</td>
              <td>e-Pub
</td>
            </tr>
          </table>
        </div>
      </div>
      <!--FIN du corps du module-->
      <br/>
      <div class="bottomNavigation">
        <div class="tail_aucentre">
          <a href="./uid19.html" accesskey="P"><img style="align:bottom; border:none" alt="previous" src="../static/img/icons/previous_motif.jpg"/> Previous | </a>
          <a href="./uid0.html" accesskey="U"><img style="align:bottom; border:none" alt="up" src="../static/img/icons/up_motif.jpg"/>  Home</a>
          <a href="./uid26.html" accesskey="N"> | Next <img style="align:bottom; border:none" alt="next" src="../static/img/icons/next_motif.jpg"/></a>
        </div>
        <br/>
      </div>
      <div id="textepage">
        <!--DEBUT2 du corps du module-->
        <h2>Section: 
      New Results</h2>
        <h3 class="titre3">Foundations of information hiding </h3>
        <p>Information hiding refers to the problem of protecting private information
while performing certain tasks or interactions, and trying to avoid that an
adversary can infer such information. This is one of the main areas of
research in Comète; we are exploring several topics, described below.</p>
        <a name="uid22"/>
        <h4 class="titre4">On the information leakage of differentially-private mechanisms</h4>
        <p>Differential privacy aims at protecting the privacy of participants in
statistical databases. Roughly, a mechanism satisfies differential privacy if
the presence or value of a single individual in the database does not
significantly change the likelihood of obtaining a certain answer to any
statistical query posed by a data analyst. Differentially-private mechanisms are
often oblivious: first the query is processed on the database to produce a true
answer, and then this answer is adequately randomized before being reported to
the data analyst. Ideally, a mechanism should minimize leakage, i.e., obfuscate
as much as possible the link between reported answers and individuals' data,
while maximizing utility, i.e., report answers as similar as possible to the
true ones. These two goals, however, are in conflict with each other, thus
imposing a trade-off between privacy and utility.</p>
        <p>In <a href="./bibliography.html#comete-2015-bid1">[12]</a>  we used quantitative information flow principles to
analyze leakage and utility in oblivious differentially-private mechanisms. We
introduced a technique that exploits graph symmetries of the adjacency relation
on databases to derive bounds on the min-entropy leakage of the mechanism. We
considered a notion of utility based on identity gain functions, which is
closely related to min-entropy leakage, and we derived bounds for it. Finally,
given some graph symmetries, we provided a mechanism that maximizes utility
while preserving the required level of differential privacy.</p>
        <a name="uid23"/>
        <h4 class="titre4">Geo-indistinguishability: A Principled Approach to Location Privacy</h4>
        <p>With the increasing popularity of handheld devices, location-based applications
and services have access to accurate and real-time location information, raising
serious privacy concerns for their users. In <a href="./bibliography.html#comete-2015-bid2">[17]</a> 
we reported on our ongoing project aimed at protecting the privacy of the user
when dealing with location-based services. The starting point of our approach is
the principle of geo-indistinguishability, a formal notion of privacy that
protects the user’s exact location, while allowing approximate information –
typically needed to obtain a certain desired service – to be released. We then
presented two mechanisms for achieving geo-indistinguishability, one generic to
sanitize locations in any setting with reasonable utility, the other
custom-built for a limited set of locations but providing optimal utility.
Finally we extended our mechanisms to the case of location traces, where the
user releases his location repeatedly along the day and we provide a method to
limit the degradation of the privacy guarantees due to the correlation between
the points. All the mechanisms were tested on real datasets and compared both
among themselves and with respect to the state of the art in the field.</p>
        <a name="uid24"/>
        <h4 class="titre4">Constructing elastic distinguishability metrics for location
privacy</h4>
        <p>The recently introduced notion of geo-indistinguishability tries to address the
problem of accessing location-aware services in a privacy-friendly way by
adapting the well-known concept of differential privacy to the area of
location-based systems. Although geo-indistinguishability presents various
appealing aspects, it has the problem of treating space in a uniform way,
imposing the addition of the same amount of noise everywhere on the map.</p>
        <p>In <a href="./bibliography.html#comete-2015-bid3">[13]</a>  we proposed a novel elastic
distinguishability metric that warps the geometrical distance, capturing the
different degrees of density of each area. As a consequence, the obtained
mechanism adapts the level of noise while achieving the same degree of privacy
everywhere. We also showed how such an elastic metric can easily incorporate the
concept of a "geographic fence" that is commonly employed to protect the highly
recurrent locations of a user, such as his home or work. We performed an
extensive evaluation of our technique by building an elastic metric for Paris'
wide metropolitan area, using semantic information from the OpenStreetMap
database. We compared the resulting mechanism against the Planar Laplace
mechanism satisfying standard geo-indistinguishability, using two real-world
datasets from the Gowalla and Brightkite location-based social networks. The
results showed that the elastic mechanism adapts well to the semantics of each
area, adjusting the noise as we move outside the city center, hence offering
better overall privacy.</p>
        <a name="uid25"/>
        <h4 class="titre4">Quantitative Information Flow for Scheduler-Dependent Systems</h4>
        <p>Quantitative information flow analyses measure how much information on secrets
is leaked by publicly observable outputs. One area of interest is to quantify
and estimate the information leakage of composed systems. Prior work has focused
on running disjoint component systems in parallel and reasoning about the
leakage compositionally, but has not explored how the component systems are run
in parallel or how the leakage of composed systems can be minimised.</p>
        <p>In <a href="./bibliography.html#comete-2015-bid4">[23]</a>  we considered the manner in which parallel
systems can be combined or scheduled. This considers the effects of scheduling
channels where resources may be shared, or whether the outputs may be
incrementally observed. We also generalised the attacker’s capability, of
observing outputs of the system, to consider attackers who may be imperfect in
their observations, e.g. when outputs may be confused with one another, or when
assessing the time taken for an output to appear. Our main contribution was to
present how scheduling and observation affect information leakage properties. In
particular, that scheduling can hide some leaked information from perfect
observers, while some scheduling may reveal secret information that is hidden to
imperfect observers. In addition we presented an algorithm to construct a
scheduler that minimises the min-entropy leakage and min-capacity in the
presence of any observer.</p>
      </div>
      <!--FIN du corps du module-->
      <br/>
      <div class="bottomNavigation">
        <div class="tail_aucentre">
          <a href="./uid19.html" accesskey="P"><img style="align:bottom; border:none" alt="previous" src="../static/img/icons/previous_motif.jpg"/> Previous | </a>
          <a href="./uid0.html" accesskey="U"><img style="align:bottom; border:none" alt="up" src="../static/img/icons/up_motif.jpg"/>  Home</a>
          <a href="./uid26.html" accesskey="N"> | Next <img style="align:bottom; border:none" alt="next" src="../static/img/icons/next_motif.jpg"/></a>
        </div>
        <br/>
      </div>
    </div>
  </body>
</html>
