Skip to content
Open access

On the Adaptation of Trajectory Generative Models to Enforce Differential Privacy Through Gradient Perturbation

2026 · IEEE Access · Vol 14, pp. 134654-134668 · 0 citations · 57 references

TL;DR

This paper investigates whether state-of-the-art deep learning trajectory generators can be adapted to satisfy differential privacy (DP) while retaining usable utility, and introduces RouteMIA, the first closed-box membership inference attack tailored to synthetic trajectories.

Abstract

Synthetic trajectories have become a crucial tool for enabling data sharing in domains such as telecommunications and urban planning, yet most generators provide neither formal privacy guarantees nor empirical validation of the protection they claim. This paper investigates whether state-of-the-art deep learning trajectory generators can be adapted to satisfy differential privacy (DP) while retaining usable utility, and makes three contributions. First, we analyze 16 state-of-the-art generators and determine which can be trained with Differentially Private Stochastic Gradient Descent (DP-SGD), showing that common architectural choices — such as index-based coordinate look-ups at inference — silently void the guarantee. Second, we present Sec-LSTM-TrajGAN, a DP adaptation of LSTM-TrajGAN, a well-known trajectory generator chosen after the analysis of the existing models. Third, we introduce RouteMIA, to our knowledge the first closed-box membership inference attack tailored to synthetic trajectories, which adapts the distance-to-closest-record attack to sequential spatio-temporal data and requires access only to the released dataset. Evaluating on GeoLife (<inline-formula> <tex-math notation="LaTeX">$17,000$ </tex-math></inline-formula> trajectories) and Porto (<inline-formula> <tex-math notation="LaTeX">$100,000$ </tex-math></inline-formula> trajectories) datasets for several scenarios of increasing privacy. RouteMIA attains an AUC of 0.59 and 0.55 against the non-private models, which drops to <inline-formula> <tex-math notation="LaTeX">$\approx 0.50$ </tex-math></inline-formula> — chance level — for every private configuration. Notably, gradient clipping alone, with no noise added, already accounts for this entire empirical gain, at a utility cost of a distance JSD rising from 0.12 to 0.20 on Porto and essentially none on GeoLife, whereas strict budgets (<inline-formula> <tex-math notation="LaTeX">$\varepsilon \leq 3$ </tex-math></inline-formula>) degrade GeoLife markedly (distance JSD up to 0.35). Per-example clipping, not the noise, therefore delivers the measurable protection against this attack — a cheap empirical complement to, but not a replacement for, formal guarantees.

Read PDF

Similar papers

Preprint Aug 2026

Information-Geometric Forward Policy Training in GFlowNets

Generative Flow Networks (GFlowNets) have emerged as a flexible framework for amortised inference over discrete and mixed discrete-continuous objects, requiring only an unnormalised target density specified through a reward. In this work, we formulate forward-policy training in GFlowNets through the information geometr...

Y. Raykov, Rodrigo Veiga · 1 citation
Open access Sep 2026

CPSGD: Differentially Private Stochastic Gradient Descent with Chaotic Post-Processing and Momentum Optimization

Differentially private stochastic gradient descent (DP-SGD) protects training data by adding calibrated Gaussian noise to clipped gradient updates; however, the resulting perturbations inevitably interfere with optimization and reduce classification accuracy. To address this limitation, this paper proposes chaotic po...

Zi-Han Zhao, Zhi-Fang Wang · 0 citations
#machine learning Preprint Sep 2026

Robust Policy Optimization via Adversarial Importance Sampling

This work introduces Adversarial Importance Sampling (Advis), a method that uses importance sampling over trajectories from standard training to estimate and optimize verifiable worst-case returns and introduces advrl, a modular PyTorch library that provides clean, single-file implementations of existing robustness met...

Amine Andam, Jamal Bentahar, M. Hedabou · 0 citations
#artificial intelligence Preprint Aug 2026

FISGuard: Defending Against Membership Inference via Fixed Input Subspaces

FISGuard reduces the ProjRes attack AUC to near the random-guessing level of 0.5 in most settings, while maintaining downstream task performance close to that of the undefended model and introducing only limited computational overhead, thereby achieving a favorable privacy--utility trade-off.

Hao-Cheng Jiang, Hua Shen · 0 citations
2026

PI-SAFE: Practical Privacy-Preserving LLM Inference With Adversarial Fine-Tuning for Optimized Utility

Cloud-based Large Language Model (LLM) inference services typically require users to submit plain-text inputs, thereby posing severe privacy risks. Existing privacy-preserving paradigms are mostly task-specific and often necessitate pervasive modifications to the entire server-side model. This reliance introduces subst...

Wentao Zhong, Yu-Ting Li, Di-Cong Yu et al. · 0 citations
#artificial intelligence Preprint Sep 2026

A Sharp Transition in Data Reconstruction under Differential Privacy

Data reconstruction attacks have empirically been successful in recovering training samples from learned models, raising privacy concerns and motivating defenses with guarantees that remain valid against future threats. While differential privacy (DP) provides formal protection, choosing the privacy budget remains a ch...

Max Cairney-Leeming, Simone Bombari, Marco Mondelli · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.