<?xml version="1.0" encoding="utf-8"?>
<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.1 plus MathML 2.0 plus SVG 1.1//EN" "http://www.w3.org/2002/04/xhtml-math-svg/xhtml-math-svg.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
  <head>
    <meta http-equiv="Content-Type" content="application/xhtml+xml; charset=utf-8"/>
    <title>Project-Team:COMETE</title>
    <link rel="stylesheet" href="../static/css/raweb.css" type="text/css"/>
    <meta name="description" content="New Results - Foundations of information hiding "/>
    <meta name="dc.title" content="New Results - Foundations of information hiding "/>
    <meta name="dc.subject" content=""/>
    <meta name="dc.publisher" content="INRIA"/>
    <meta name="dc.date" content="(SCHEME=ISO8601) 2016-01"/>
    <meta name="dc.type" content="Report"/>
    <meta name="dc.language" content="(SCHEME=ISO639-1) en"/>
    <meta name="projet" content="COMETE"/>
    <script type="text/javascript" src="https://raweb.inria.fr/rapportsactivite/RA2016/static/MathJax/MathJax.js?config=TeX-MML-AM_CHTML">
      <!--MathJax-->
    </script>
  </head>
  <body>
    <div class="tdmdiv">
      <div class="logo">
        <a href="http://www.inria.fr">
          <img style="align:bottom; border:none" src="../static/img/icons/logo_INRIA-coul.jpg" alt="Inria"/>
        </a>
      </div>
      <div class="TdmEntry">
        <div class="tdmentete">
          <a href="uid0.html">Project-Team Comete</a>
        </div>
        <span>
          <a href="uid1.html">Members</a>
        </span>
      </div>
      <div class="TdmEntry">
        <a href="./uid3.html">Overall Objectives</a>
      </div>
      <div class="TdmEntry">Research Program<ul><li><a href="uid5.html&#10;&#9;&#9;  ">Probability and information theory</a></li><li><a href="uid6.html&#10;&#9;&#9;  ">Expressiveness of Concurrent Formalisms</a></li><li><a href="uid7.html&#10;&#9;&#9;  ">Concurrent constraint programming</a></li><li><a href="uid10.html&#10;&#9;&#9;  ">Model checking</a></li></ul></div>
      <div class="TdmEntry">Application Domains<ul><li><a href="uid12.html&#10;&#9;&#9;  ">Security and privacy</a></li></ul></div>
      <div class="TdmEntry">
        <a href="./uid14.html">Highlights of the Year</a>
      </div>
      <div class="TdmEntry">New Software and Platforms<ul><li><a href="uid19.html&#10;&#9;&#9;  ">libqif - A Quantitative Information Flow C++ Toolkit Library</a></li><li><a href="uid35.html&#10;&#9;&#9;  ">D-SPACES - constraint systems with space and extrusion operators</a></li><li><a href="uid36.html&#10;&#9;&#9;  ">Trace Slicer for Timed Concurrent Constraint Programming</a></li></ul></div>
      <div class="TdmEntry">New Results<ul><li class="tdmActPage"><a href="uid38.html&#10;&#9;&#9;  ">Foundations of information hiding </a></li><li><a href="uid47.html&#10;&#9;&#9;  ">Foundations of Concurrency</a></li></ul></div>
      <div class="TdmEntry">Bilateral Contracts and Grants with Industry<ul><li><a href="uid53.html&#10;&#9;&#9;  ">Bilateral Contracts with Industry</a></li></ul></div>
      <div class="TdmEntry">Partnerships and Cooperations<ul><li><a href="uid62.html&#10;&#9;&#9;  ">Regional Initiatives</a></li><li><a href="uid75.html&#10;&#9;&#9;  ">National Initiatives</a></li><li><a href="uid83.html&#10;&#9;&#9;  ">International Initiatives</a></li><li><a href="uid154.html&#10;&#9;&#9;  ">International Research Visitors</a></li></ul></div>
      <div class="TdmEntry">Dissemination<ul><li><a href="uid165.html&#10;&#9;&#9;  ">Promoting Scientific Activities</a></li><li><a href="uid228.html&#10;&#9;&#9;  ">Teaching - Supervision - Juries</a></li></ul></div>
      <div class="TdmEntry">
        <div>Bibliography</div>
      </div>
      <div class="TdmEntry">
        <ul>
          <li>
            <a id="tdmbibentmajor" href="bibliography.html">Major publications</a>
          </li>
          <li>
            <a id="tdmbibentyear" href="bibliography.html#year">Publications of the year</a>
          </li>
          <li>
            <a id="tdmbibentfoot" href="bibliography.html#References">References in notes</a>
          </li>
        </ul>
      </div>
    </div>
    <div id="main">
      <div class="mainentete">
        <div id="head_agauche">
          <small><a href="http://www.inria.fr">
	    
	    Inria
	  </a> | <a href="../index.html">
	    
	    Raweb 
	    2016</a> | <a href="http://www.inria.fr/en/teams/comete">Presentation of the Project-Team COMETE</a> | <a href="http://www.lix.polytechnique.fr/comete/">COMETE Web Site
	  </a></small>
        </div>
        <div id="head_adroite">
          <table class="qrcode">
            <tr>
              <td>
                <a href="comete.xml">
                  <img style="align:bottom; border:none" alt="XML" src="../static/img/icons/xml_motif.png"/>
                </a>
              </td>
              <td>
                <a href="comete.pdf">
                  <img style="align:bottom; border:none" alt="PDF" src="IMG/qrcode-comete-pdf.png"/>
                </a>
              </td>
              <td>
                <a href="../comete/comete.epub">
                  <img style="align:bottom; border:none" alt="e-pub" src="IMG/qrcode-comete-epub.png"/>
                </a>
              </td>
            </tr>
            <tr>
              <td/>
              <td>PDF
</td>
              <td>e-Pub
</td>
            </tr>
          </table>
        </div>
      </div>
      <!--FIN du corps du module-->
      <br/>
      <div class="bottomNavigation">
        <div class="tail_aucentre">
          <a href="./uid36.html" accesskey="P"><img style="align:bottom; border:none" alt="previous" src="../static/img/icons/previous_motif.jpg"/> Previous | </a>
          <a href="./uid0.html" accesskey="U"><img style="align:bottom; border:none" alt="up" src="../static/img/icons/up_motif.jpg"/>  Home</a>
          <a href="./uid47.html" accesskey="N"> | Next <img style="align:bottom; border:none" alt="next" src="../static/img/icons/next_motif.jpg"/></a>
        </div>
        <br/>
      </div>
      <div id="textepage">
        <!--DEBUT2 du corps du module-->
        <h2>Section: 
      New Results</h2>
        <h3 class="titre3">Foundations of information hiding </h3>
        <p>Information hiding refers to the problem of protecting private information
while performing certain tasks or interactions, and trying to avoid that an
adversary can infer such information. This is one of the main areas of
research in Comète; we are exploring several topics, described below.</p>
        <a name="uid39"/>
        <h4 class="titre4">Axioms for Information Leakage</h4>
        <p>Quantitative information flow aims to assess and control the leakage of
sensitive information by computer systems. A key insight in this area is that no
single leakage measure is appropriate in all operational scenarios; as a result,
many leakage measures have been proposed, with many different properties. To
clarify this complex situation, we studied in <a href="./bibliography.html#comete-2016-bid7">[17]</a>
information leakage axiomatically, showing important dependencies among
different axioms. We also established a completeness result about the <span class="math"><math xmlns="http://www.w3.org/1998/Math/MathML"><mi>g</mi></math></span>-leakage
family, showing that any leakage measure satisfying certain
intuitively-reasonable properties can be expressed as a <span class="math"><math xmlns="http://www.w3.org/1998/Math/MathML"><mi>g</mi></math></span>-leakage.</p>
        <a name="uid40"/>
        <h4 class="titre4">Up-To Techniques for Generalized Bisimulation Metrics</h4>
        <p>Bisimulation metrics allow us to compute distances between the behaviors of
probabilistic systems. In <a href="./bibliography.html#comete-2016-bid8">[18]</a> we presented
enhancements of the proof method based on bisimulation metrics, by extending the
theory of up-to techniques to (pre)metrics on discrete probabilistic concurrent
processes.</p>
        <p>Up-to techniques have proved to be a powerful proof method for showing that two
systems are bisimilar, since they make it possible to build (and thereby check)
smaller relations in bisimulation proofs. We defined soundness conditions for
up-to techniques on metrics, and studied compatibility properties that allow us
to safely compose up-to techniques with each other. As an example, we derived
the soundness of the up-to-bisimilarity-metric-and-context technique.</p>
        <p>The study was carried out for a generalized version of the bisimulation metrics,
in which the Kantorovich lifting is parametrized with respect to a distance
function. The standard bisimulation metrics, as well as metrics aimed at
capturing multiplicative properties such as differential privacy, are specific
instances of this general definition.</p>
        <a name="uid41"/>
        <h4 class="titre4">Compositional methods for information-hiding</h4>
        <p>Systems concerned with information hiding often use randomization to obfuscate
the link between the observables and the information to be protected. The degree
of protection provided by a system can be expressed in terms of the probability
of error associated with the inference of the secret information. In
<a href="./bibliography.html#comete-2016-bid9">[12]</a> we considered a probabilistic process
calculus to specify such systems, and we studied how the operators aﬀect the
probability of error. In particular, we characterized constructs that have the
property of not decreasing the degree of protection, and that can therefore be
considered safe in the modular construction of these systems. As a case study,
we applied these techniques to the Dining Cryptographers, and we derive a
generalization of Chaum's strong anonymity result.</p>
        <a name="uid42"/>
        <h4 class="titre4">Differential Privacy Models for Location-Based Services</h4>
        <p>In <a href="./bibliography.html#comete-2016-bid10">[13]</a>, we considered the adaptation of differential
privacy to the context of location-based services (LBSs), which personalize the
information provided to a user based on his current position. Assuming that the
LBS provider is queried with a perturbed version of the position of the user
instead of his exact one, we relied on differential privacy to quantify the
level of indistinguishability (i.e., privacy) provided by this perturbation with
respect to the user's position. In this setting, the adaptation of differential
privacy can lead to various models depending on the precise form of
indistinguishability required. We discussed the set of properties that hold for
these models in terms of privacy, utility and also implementation issues. More
precisely, we first introduced and analyzed one of these models, the
(D,eps)-location privacy, which is directly inspired from the standard
differential privacy model. In this context, we described a general
probabilistic model for obfuscation mechanisms for the locations whose output
domain is the Euclidean space <span class="math"><math xmlns="http://www.w3.org/1998/Math/MathML"><msup><mi>E</mi><mn>2</mn></msup></math></span>. In this model, we characterized the
satisfiability conditions of (D,eps)-location privacy for a particular mechanism
and also measured its utility with respect to an arbitrary loss function.
Afterwards, we presented and analyzed symmetric mechanisms in which all
locations are perturbed in a unified manner through a noise function, focusing
in particular on circular noise functions. We proved that, under certain
assumptions, the circular functions are rich enough to provide the same privacy
and utility levels as other more complex (i.e., non-circular) noise functions,
while being easier to implement. Finally, we extended our results to a
generalized notion for location privacy, called `l-privacy' capturing both
(D,eps)-location privacy and also the notion of geo-indistinguishability
recently introduced by Andrès, Bordenabe, Chatzikokolakis and Palamidessi.</p>
        <a name="uid43"/>
        <h4 class="titre4">Practical Mechanisms for Location Privacy</h4>
        <p>The continuously increasing use of location-based services poses an important
threat to the privacy of users. A natural defense is to employ an obfuscation
mechanism, such as those providing geo-indistinguishability, a framework for
obtaining formal privacy guarantees that has become popular in recent years.</p>
        <p>Ideally, one would like to employ an optimal obfuscation mechanism, providing
the best utility among those satisfying the required privacy level. In theory
optimal mechanisms can be constructed via linear programming. In practice,
however, this is only feasible for a radically small number of locations. As a
consequence, all known applications of geo-indistinguishability simply use noise
drawn from a planar Laplace distribution.</p>
        <p>In <a href="./bibliography.html#comete-2016-bid11">[23]</a> we studied methods for substantially
improving the utility of location obfuscation, while having practical
applicability as a central constraint. We provided such solutions for both
infinite (continuous or discrete) as well as large but finite domains of
locations, using a Bayesian remapping procedure as a key ingredient. We
evaluated
our techniques in two real world complete datasets, without any restriction on
the evaluation area, and showed important utility improvements wrt the standard
planar Laplace approach.</p>
        <a name="uid44"/>
        <h4 class="titre4">Preserving differential privacy under finite-precision semantics</h4>
        <p>The approximation introduced by finite-precision representation of continuous
data can induce arbitrarily large information leaks even when the computation
using exact semantics is secure. Such leakage can thus undermine design efforts
aimed at protecting sensitive information. In <a href="./bibliography.html#comete-2016-bid12">[14]</a> we
focussed on differential privacy, an approach to privacy that emerged from the
area of statistical databases and is now widely applied also in other domains.
In this approach, privacy is protected by adding noise to the values correlated
to the private data. The typical mechanisms used to achieve differential privacy
have been proved correct in the ideal case in which computations are made using
infinite-precision semantics. We analyzed the situation at the implementation
level, where the semantics is necessarily limited by finite precision, i.e., the
representation of real numbers and the operations on them are rounded according
to some level of precision. We showed that in general there are violations of
the differential privacy property, and we studied the conditions under which we
can still guarantee a limited (but, arguably, acceptable) variant of the
property, under only a minor degradation of the privacy level. Finally, we
illustrated our results on two examples: the standard Laplacian mechanism
commonly used in differential privacy, and a bivariate version of it recently
introduced in the setting of privacy-aware geolocation.</p>
        <a name="uid45"/>
        <h4 class="titre4">Quantifying Leakage in the Presence of Unreliable Sources of Information</h4>
        <p>Belief and min-entropy leakage are two well-known approaches to quantify
information flow in security systems. Both concepts stand as alternatives to the
traditional approaches founded on Shannon entropy and mutual information , which
were shown to provide inadequate security guarantees. In
<a href="./bibliography.html#comete-2016-bid13">[16]</a> we unified the two concepts in one model so as to
cope with the frequent (potentially inaccurate, misleading or outdated)
attackers' side information about individuals on social networks, online forums,
blogs and other forms of online communication and information sharing. To this
end we proposed a new metric based on min-entropy that takes into account the
adversary's beliefs.</p>
        <a name="uid46"/>
        <h4 class="titre4">On the Compositionality of Quantitative Information Flow</h4>
        <p>In the min-entropy approach to quantitative information flow, the leakage is
defined in terms of a minimization problem, which, in the case of large systems,
can be computationally rather heavy. The same happens for the recently proposed
generalization called <span class="math"><math xmlns="http://www.w3.org/1998/Math/MathML"><mi>g</mi></math></span>-vulnerability. In <a href="./bibliography.html#comete-2016-bid14">[25]</a> we
studied the case in which the channel associated to the system can be decomposed
into simpler channels, which typically happens when the observables consist of
several components. Our main contribution is the derivation of bounds on the
<span class="math"><math xmlns="http://www.w3.org/1998/Math/MathML"><mi>g</mi></math></span>-leakage of the whole system in terms of the <span class="math"><math xmlns="http://www.w3.org/1998/Math/MathML"><mi>g</mi></math></span>-leakages of its components.
We also considered the particular cases of min-entropy leakage and of parallel
channels, generalizing and systematizing results from the literature. We
demonstrated the effectiveness of our method and evaluate the precision of our
bounds using examples.</p>
      </div>
      <!--FIN du corps du module-->
      <br/>
      <div class="bottomNavigation">
        <div class="tail_aucentre">
          <a href="./uid36.html" accesskey="P"><img style="align:bottom; border:none" alt="previous" src="../static/img/icons/previous_motif.jpg"/> Previous | </a>
          <a href="./uid0.html" accesskey="U"><img style="align:bottom; border:none" alt="up" src="../static/img/icons/up_motif.jpg"/>  Home</a>
          <a href="./uid47.html" accesskey="N"> | Next <img style="align:bottom; border:none" alt="next" src="../static/img/icons/next_motif.jpg"/></a>
        </div>
        <br/>
      </div>
    </div>
  </body>
</html>
