CiteULike is a free online bibliography manager. Register and you can start organising your references online.

Releasing search queries and clicks privately Export

In WWW '09: Proceedings of the 18th international conference on World wide web (2009), pp. 171-180.

Citation Format

[Posts]

View FullText article


ChaTo's tags for this article

adversarial-ir clicks

X Reviews [Write a review of this article]

X Notes for this article

ChaTo has 0 private notes and 1 public note for this article.

[Talk] Anonymyzing query logs by removing usernames and ips is not enough. Removing numbers/names/dates/locations/etc. Substitution ciphers are easy to break.

Previous/future releases are useful for breaking privacy.

Differential privacy [Dwork et al. 2006] if knowledge about a person is roughly equal if the person uses a search engine wrt if the person does not use the search engine.

Click-graph (1) add random noise to query counts, and if the noisy query count exceeds a certain threshold, include the query. (2) allow each user to add at most d1 queries and at most d2 clicks to the data, ignore the rest. (3) for top 10 URLs for each query, if noisy edge count exceeds a threshold, include the link.

Releasable: 2.5M queries.

Check then if the data is sufficient for certain applications: 1. "Fear of ..." queries. 2. Keyword suggestion for ads, using the degraded click log. Only about 13% of the keyword suggestions are lost.

Future work: release more tail queries, e.g. by grouping queries by similarity.

ChaTo (public note) - 2009-04-23 16:28:26

X Find related articles from these CiteULike users

X Find related articles with these CiteULike tags

X Posting History

X Abstract

The question of how to publish an anonymized search log was brought to the forefront by a well-intentioned, but privacy-unaware AOL search log release. Since then a series of ad-hoc techniques have been proposed in the literature, though none are known to be provably private. In this paper, we take a major step towards a solution: we show how queries, clicks and their associated perturbed counts can be published in a manner that rigorously preserves privacy. Our algorithm is decidedly simple to state, but non-trivial to analyze. On the opposite side of privacy is the question of whether the data we can safely publish is of any use. Our findings offer a glimmer of hope: we demonstrate that a non-negligible fraction of queries and clicks can indeed be safely published via a collection of experiments on a real search log. In addition, we select an application, keyword generation, and show that the keyword suggestions generated from the perturbed data resemble those generated from the original data.


X BibTeX record

X RIS record


Privacy Statement | Terms & Conditions
CiteULike organises scholarly (or academic) papers or literature and provides bibliographic (which means it makes bibliographies) for universities and higher education establishments. It helps undergraduates and postgraduates. People studying for PhDs or in postdoctoral (postdoc) positions. The service is similar in scope to EndNote or RefWorks or any other reference manager like BibTeX, but it is a social bookmarking service for scientists and humanities researchers.