arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

无处不在的秘密:移动性预测模型中的记忆审计

Secrets Everywhere: Auditing Memorization in Mobility Prediction Models

Anne Josiane Kouam, Hristo Boyadzhiev, Konrad Rieck

arXiv 2608.02052首次发表:更新:

发表机构

Inria; TU Berlin; BIFOLD(法国国家信息与自动化研究所; 柏林工业大学; 数据科学与人工智能柏林研究所)

机构由 AI 辅助整理,请以论文原文为准。

AI 中文总结

本文首次系统审计移动性预测模型的记忆风险,提出框架量化不同粒度的移动性记忆,发现普遍记忆模式关联用户规律性并提升数据提取风险,呼吁开展强制性隐私审计。

AI 中文摘要

人类移动性预测模型用于预测用户轨迹中的下一个位置,正越来越多地应用于城市分析、导航和个性化服务中。然而,人们对其从训练数据中记忆和暴露敏感用户轨迹的潜在能力知之甚少。尽管记忆在语言模型中已被广泛研究,但移动性预测带来了独特挑战:训练序列编码了不同时空尺度下的人类行为,在不同粒度上产生隐私风险。本文中,我们首次对移动性预测模型中的记忆进行系统审计。尽管已有研究表明此类模型可能出现隐私泄露,我们仍对其记忆风险进行了大规模系统评估与量化。我们识别出关键挑战,包括缺乏随机性空间、轨迹的多尺度结构以及用户特定的行为多样性。为解决这些挑战,我们引入一个框架,用于在不同粒度级别(单个位置、锚点对和子轨迹段)量化移动性记忆。我们还开发了基于用户的参考集,以评估模型偏好训练数据而非现实替代方案的可能性。我们在多个模型和数据集上的评估显示,存在与用户规律性相关的普遍记忆模式,增加了推理时的数据提取风险。我们的发现呼吁对移动性预测模型进行强制性隐私审计。

英文摘要

Human mobility prediction models, which forecast the next location in a user's trajectory, are increasingly deployed in urban analytics, navigation, and personalized services. Yet, little is known about their potential to memorize and expose sensitive user trajectories from training data. While memorization has been extensively studied in language models, mobility prediction poses unique challenges: training sequences encode human behavior at various spatial and temporal scales, creating privacy risks at different granularities. In this paper, we conduct the first systematic audit of memorization in mobility prediction models. While prior work has shown that privacy leaks can arise from such models, we systematically assess and quantify memorization risks at scale. We identify key challenges, including the lack of a randomness space, the multi-scale structure of trajectories, and user-specific behavioral diversity. To address these challenges, we introduce a framework to quantify mobility memorization at different levels of granularity: individual locations, anchor pairs, and subtrajectory segments. We also develop user-grounded reference sets to assess how likely a model is to prefer training data over realistic alternatives. Our evaluation across multiple models and datasets reveals pervasive memorization patterns that correlate with user regularity and increase the risk of data extraction at inference time. Our findings call for mandatory privacy auditing in mobility prediction models.

CommentsFull version of the paper accepted for publication at the ACM SIGSAC Conference on Computer and Communications Security (CCS 2026). Includes supplementary appendices omitted from the proceedings version

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑