
Previous work often has used countermeasure techniques such as spatial rounding or noise to preserve location and route privacy. These techniques require a high degree of perturbation to preserve the privacy of sensitive places and routes. This high level of perturbation is problematic for many location-based services, including our PEIR application. As an alternative, we suggest a model-based spatial cloaking approach where portions of a location trace are replaced by “likely” routes.
Our location generation algorithm is based on the following principles:
a) It should protect both sensitive places and routes,
b) The places and routes generated should be based on past history and time parameters for each individual user,
c) The generated location traces must be realistic in terms of the conditions that exist on that day in terms of the physical world (traffic, weather, and speed limits),
d) The mode of transportation should be tailored as well.
e) The generator for routes should use a participant’s real trace in its model to generate these routes.