This paper investigates whether state-of-the-art deep learning trajectory generators can be adapted to satisfy differential privacy (DP) while retaining usable utility, and introduces RouteMIA, the first closed-box membership inference attack tailored to synthetic trajectories.
Abstract
Synthetic trajectories have become a crucial tool for enabling data sharing in domains such as telecommunications and urban planning, yet most generators provide neither formal privacy guarantees nor empirical validation of the protection they claim. This paper investigates whether state-of-the-art deep learning trajectory generators can be adapted to satisfy differential privacy (DP) while retaining usable utility, and makes three contributions. First, we analyze 16 state-of-the-art generators and determine which can be trained with Differentially Private Stochastic Gradient Descent (DP-SGD), showing that common architectural choices — such as index-based coordinate look-ups at inference — silently void the guarantee. Second, we present Sec-LSTM-TrajGAN, a DP adaptation of LSTM-TrajGAN, a well-known trajectory generator chosen after the analysis of the existing models. Third, we introduce RouteMIA, to our knowledge the first closed-box membership inference attack tailored to synthetic trajectories, which adapts the distance-to-closest-record attack to sequential spatio-temporal data and requires access only to the released dataset. Evaluating on GeoLife (<inline-formula> <tex-math notation="LaTeX">$17,000$ </tex-math></inline-formula> trajectories) and Porto (<inline-formula> <tex-math notation="LaTeX">$100,000$ </tex-math></inline-formula> trajectories) datasets for several scenarios of increasing privacy. RouteMIA attains an AUC of 0.59 and 0.55 against the non-private models, which drops to <inline-formula> <tex-math notation="LaTeX">$\approx 0.50$ </tex-math></inline-formula> — chance level — for every private configuration. Notably, gradient clipping alone, with no noise added, already accounts for this entire empirical gain, at a utility cost of a distance JSD rising from 0.12 to 0.20 on Porto and essentially none on GeoLife, whereas strict budgets (<inline-formula> <tex-math notation="LaTeX">$\varepsilon \leq 3$ </tex-math></inline-formula>) degrade GeoLife markedly (distance JSD up to 0.35). Per-example clipping, not the noise, therefore delivers the measurable protection against this attack — a cheap empirical complement to, but not a replacement for, formal guarantees.
Generative Flow Networks (GFlowNets) have emerged as a flexible framework for amortised inference over discrete and mixed discrete-continuous objects, requiring only an unnormalised target density specified through a reward. In this work, we formulate forward-policy training in GFlowNets through the information geometr...
Differentially private stochastic gradient descent (DP-SGD) protects training data by adding calibrated Gaussian noise to clipped gradient updates; however, the resulting perturbations inevitably interfere with optimization and reduce classification accuracy. To address this limitation, this paper proposes chaotic po...
Zi-Han Zhao, Zhi-Fang Wang· Engineering Research Express· 0 citations
This work introduces Adversarial Importance Sampling (Advis), a method that uses importance sampling over trajectories from standard training to estimate and optimize verifiable worst-case returns and introduces advrl, a modular PyTorch library that provides clean, single-file implementations of existing robustness met...
Amine Andam, Jamal Bentahar, M. Hedabou· 0 citations
FISGuard reduces the ProjRes attack AUC to near the random-guessing level of 0.5 in most settings, while maintaining downstream task performance close to that of the undefended model and introducing only limited computational overhead, thereby achieving a favorable privacy--utility trade-off.
Cloud-based Large Language Model (LLM) inference services typically require users to submit plain-text inputs, thereby posing severe privacy risks. Existing privacy-preserving paradigms are mostly task-specific and often necessitate pervasive modifications to the entire server-side model. This reliance introduces subst...
Wentao Zhong, Yu-Ting Li, Di-Cong Yu et al.· IEEE Transactions on Informa...· 0 citations
Data reconstruction attacks have empirically been successful in recovering training samples from learned models, raising privacy concerns and motivating defenses with guarantees that remain valid against future threats. While differential privacy (DP) provides formal protection, choosing the privacy budget remains a ch...
Max Cairney-Leeming, Simone Bombari, Marco Mondelli· 0 citations
We use cookies to run the site and, with your consent, for analytics and to show ads.
See our Cookie Policy.