{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,27]],"date-time":"2026-06-27T12:46:33Z","timestamp":1782564393272,"version":"3.54.5"},"reference-count":64,"publisher":"MDPI AG","issue":"3","license":[{"start":{"date-parts":[[2014,3,21]],"date-time":"2014-03-21T00:00:00Z","timestamp":1395360000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/3.0\/"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Entropy"],"abstract":"<jats:p>Recommendation systems are information-filtering systems that tailor information to users on the basis of knowledge about their preferences. The ability of these systems to profile users is what enables such intelligent functionality, but at the same time, it is the source of serious privacy concerns. In this paper we investigate a privacy-enhancing technology that aims at hindering an attacker in its efforts to accurately profile users based on the items they rate. Our approach capitalizes on the combination of two perturbative mechanisms\u2014the forgery and the suppression of ratings. While this technique enhances user privacy to a certain extent, it inevitably comes at the cost of a loss in data utility, namely a degradation of the recommendation\u2019s accuracy. In short, it poses a trade-off between privacy and utility. The theoretical analysis of such trade-off is the object of this work. We measure privacy as the Kullback-Leibler divergence between the user\u2019s and the population\u2019s item distributions, and quantify utility as the proportion of ratings users consent to forge and eliminate. Equipped with these quantitative measures, we find a closed-form solution to the problem of optimal forgery and suppression of ratings, an optimization problem that includes, as a particular case, the maximization of the entropy of the perturbed profile. We characterize the optimal trade-off surface among privacy, forgery rate and suppression rate,and experimentally evaluate how our approach could contribute to privacy protection in a real-world recommendation system.<\/jats:p>","DOI":"10.3390\/e16031586","type":"journal-article","created":{"date-parts":[[2014,3,21]],"date-time":"2014-03-21T12:06:20Z","timestamp":1395403580000},"page":"1586-1631","update-policy":"https:\/\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":20,"title":["Optimal Forgery and Suppression of Ratings for Privacy Enhancement in Recommendation Systems"],"prefix":"10.3390","volume":"16","author":[{"given":"Javier","family":"Parra-Arnau","sequence":"first","affiliation":[{"name":"Department of Telematics Engineering, Universitat Polit\u00e8cnica de Catalunya (UPC), C. Jordi Girona 1-3, Barcelona 08034, Spain"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"David","family":"Rebollo-Monedero","sequence":"additional","affiliation":[{"name":"Department of Telematics Engineering, Universitat Polit\u00e8cnica de Catalunya (UPC), C. Jordi Girona 1-3, Barcelona 08034, Spain"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-8401-3292","authenticated-orcid":false,"given":"Jordi","family":"Forn\u00e9","sequence":"additional","affiliation":[{"name":"Department of Telematics Engineering, Universitat Polit\u00e8cnica de Catalunya (UPC), C. Jordi Girona 1-3, Barcelona 08034, Spain"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"1968","published-online":{"date-parts":[[2014,3,21]]},"reference":[{"key":"ref_1","doi-asserted-by":"crossref","unstructured":"Parra-Arnau, J., Rebollo-Monedero, D., and Forn\u00e9, J. (2011, January 15\u201316). A privacy-protecting architecture for collaborative filtering via forgery and suppression of ratings. Leuven, Belgium.","DOI":"10.1007\/978-3-642-28879-1_4"},{"key":"ref_2","doi-asserted-by":"crossref","first-page":"203","DOI":"10.1023\/A:1011196000674","article-title":"Information filtering: Overview of issues, research and systems","volume":"11","author":"Hanani","year":"2001","journal-title":"User Model. User-Adap. Interact"},{"key":"ref_3","unstructured":"Oard, D., and Kim, J. (1998, January 27). Implicit Feedback for Recommender Systems. Madison, WI, USA."},{"key":"ref_4","doi-asserted-by":"crossref","first-page":"734","DOI":"10.1109\/TKDE.2005.99","article-title":"Toward the next generation of recommender systems: A survey of the state-of-the-art and possible extensions","volume":"17","author":"Adomavicius","year":"2005","journal-title":"IEEE Trans. Knowl. Data Eng"},{"key":"ref_5","doi-asserted-by":"crossref","unstructured":"Su, X., and Khoshgoftaar, T.M. (2009). A survey of collaborative filtering techniques. Adv. Artif. Intell, 2009, Article No. 4.","DOI":"10.1155\/2009\/421425"},{"key":"ref_6","doi-asserted-by":"crossref","unstructured":"Cranor, L.F. (2003, January 30). \u2018I Didn\u2019t Buy it for Myself\u2019: Privacy and Ecommerce Personalization. Washington, DC, USA.","DOI":"10.1145\/1005140.1005158"},{"key":"ref_7","doi-asserted-by":"crossref","unstructured":"Narayanan, A., and Shmatikov, V. (2008, January 16). Robust De-anonymization of Large Sparse Datasets. Washington, DC, USA.","DOI":"10.1109\/SP.2008.33"},{"key":"ref_8","unstructured":"Available online: http:\/\/en.wikipedia.org\/wiki\/NetflixPrize."},{"key":"ref_9","unstructured":"Zaslow, J. If TiVo thinks you are gay, here\u2019s how to set it straight. Available online: http:\/\/online.wsj.com\/news\/articles\/SB1038261936872356908."},{"key":"ref_10","unstructured":"Bilton, N., and Stelter, B. Sony says Playstation hacker got personal data. Available online: http:\/\/www.nytimes.com\/2011\/04\/27\/technology\/27playstation.html."},{"key":"ref_11","unstructured":"Ovide, S. Evernote discloses security breach. Available online: http:\/\/online.wsj.com\/article\/SB10001424127887323478304578336373531236296.html."},{"key":"ref_12","unstructured":"Available online: http:\/\/en.wikipedia.org\/wiki\/AOLsearchdatascandal."},{"key":"ref_13","unstructured":"Available online: http:\/\/www.lastfm.es\/legal\/privacy."},{"key":"ref_14","unstructured":"Helft, M. U.S. judge orders youtube to hand over video logs. Available online: http:\/\/www.nytimes.com\/2008\/07\/03\/technology\/03iht-04youtube.14219540.html?r=0."},{"key":"ref_15","unstructured":"Fox, S. (2000). Trust and Privacy Online: Why Americans Want to Rewrite the Rules, Pew Charitable Trusts."},{"key":"ref_16","doi-asserted-by":"crossref","first-page":"80","DOI":"10.1145\/299157.299175","article-title":"Building consumer trust online","volume":"42","author":"Hoffman","year":"1999","journal-title":"Commun. ACM"},{"key":"ref_17","doi-asserted-by":"crossref","first-page":"53","DOI":"10.1016\/j.future.2013.01.001","article-title":"Measuring the privacy of user profiles in personalized information systems","volume":"33","year":"2014","journal-title":"Future Gen. Comput. Syst"},{"key":"ref_18","doi-asserted-by":"crossref","unstructured":"Rebollo-Monedero, D., Parra-Arnau, J., and Forn\u00e9, J. (2011, January 8\u201310). An information-theoretic privacy criterion for query forgery in information retrieval. Jeju Island, Korea.","DOI":"10.1007\/978-3-642-27189-2_16"},{"key":"ref_19","unstructured":"Polat, H., and Du, W. (2003, January 1\u20133). Privacy-preserving collaborative filtering using randomized perturbation techniques. San Francisco, CA, USA."},{"key":"ref_20","unstructured":"Kargupta, H., Datta, S., Wang, Q., and Sivakumar, K. (2003, January 19\u201322). On the privacy preserving properties of random data perturbation techniques. Washington, DC, USA."},{"key":"ref_21","doi-asserted-by":"crossref","unstructured":"Huang, Z., Du, W., and Chen, B. (2005, January 14\u201316). Deriving private information from randomized data. Baltimore, MD, USA.","DOI":"10.1145\/1066157.1066163"},{"key":"ref_22","doi-asserted-by":"crossref","unstructured":"Polat, H., and Du, W. (2005, January 13\u201317). SVD-based collaborative filtering with privacy. Santa Fe, NM, USA.","DOI":"10.1145\/1066677.1066860"},{"key":"ref_23","doi-asserted-by":"crossref","unstructured":"Agrawal, D., and Aggarwal, C.C. (2001, January 21\u201324). On the design and quantification of privacy preserving data mining algorithms. Santa Barbara, CA, USA.","DOI":"10.1145\/375551.375602"},{"key":"ref_24","doi-asserted-by":"crossref","first-page":"66","DOI":"10.1145\/290163.290168","article-title":"Crowds: Anonymity for Web transactions","volume":"1","author":"Reiter","year":"1998","journal-title":"ACM Trans. Inf. Syst. Secur"},{"key":"ref_25","doi-asserted-by":"crossref","unstructured":"Chow, C., Mokbel, M.F., and Liu, X. (2006, January 10\u201311). A peer-to-peer spatial cloaking algorithm for anonymous location-based services. Arlington, VA, USA.","DOI":"10.1145\/1183471.1183500"},{"key":"ref_26","unstructured":"Rebollo-Monedero, D., Forn\u00e9, J., Subirats, L., Solanas, A., and Mart\u00ednez-Ballest\u00e9, A. (2009, January 25\u201328). A collaborative protocol for private retrieval of location-based information. Barcelona, Spain."},{"key":"ref_27","doi-asserted-by":"crossref","first-page":"4631","DOI":"10.1109\/TIT.2010.2054471","article-title":"Optimal query forgery for private information retrieval","volume":"56","year":"2010","journal-title":"IEEE Trans. Inf. Theory"},{"key":"ref_28","unstructured":"Parra-Arnau, J., Rebollo-Monedero, D., and Forn\u00e9, J. (September, January 30). A privacy-preserving architecture for the semantic Web based on tag suppression. Bilbao, Spain."},{"key":"ref_29","first-page":"46","article-title":"Optimal tag suppression for privacy protection in the semantic Web","volume":"81\u201382","author":"Esparza","year":"2012","journal-title":"Data Knowl. Eng"},{"key":"ref_30","doi-asserted-by":"crossref","first-page":"180","DOI":"10.1109\/TKDE.2012.248","article-title":"Privacy-preserving enhanced collaborative tagging","volume":"26","author":"Perego","year":"2014","journal-title":"IEEE Trans. Knowl. Data Eng"},{"key":"ref_31","doi-asserted-by":"crossref","unstructured":"Canny, J. (2002, January 11\u201315). Collaborative filtering with privacy via factor analysis. Tampere, Finland.","DOI":"10.1145\/564376.564419"},{"key":"ref_32","doi-asserted-by":"crossref","unstructured":"Canny, J.F. (2002, January 12\u201315). Collaborative filtering with privacy. Oakland, CA, USA.","DOI":"10.1145\/564376.564419"},{"key":"ref_33","doi-asserted-by":"crossref","unstructured":"Ahmad, W., and Khokhar, A. (2007, January 29\u201331). An architecture for privacy preserving collaborative filtering on Web portals. Washington, DC, USA.","DOI":"10.1109\/ISIAS.2007.4299786"},{"key":"ref_34","doi-asserted-by":"crossref","first-page":"472","DOI":"10.1109\/TSMCC.2010.2040275","article-title":"Privacy-preserving collaborative recommender systems","volume":"40","author":"Zhan","year":"2010","journal-title":"IEEE Trans. Syst. Man Cybern"},{"key":"ref_35","unstructured":"Deng, M. (2010). Privacy preserving content protection. [Ph.D. Dissertation, Katholieke University]."},{"key":"ref_36","unstructured":"Cottrell, L. Mixmaster and remailer attacks, 1994. Available online: http:\/\/obscura.com\/~loki\/remailer\/remailer-essay.html."},{"key":"ref_37","doi-asserted-by":"crossref","unstructured":"Serjantov, A., and Newman, R.E. (2003, January 26\u201328). On the anonymity of timed pool mixes. Security and Privacy in the Age of Uncertainty, Proceedings of the Workshop Private, Anonymous Issues Network, Distribution System.","DOI":"10.1007\/978-0-387-35691-4_41"},{"key":"ref_38","unstructured":"M\u00f6ller, U., Cottrell, L., Palfrader, P., and Sassaman, L. Mixmaster protocol\u2014Version 2. Available online: http:\/\/www.freehaven.net\/anonbib\/cache\/mixmaster-spec.txt."},{"key":"ref_39","doi-asserted-by":"crossref","unstructured":"Kesdogan, D., Egner, J., and B\u00fcschkes, R. (1998, January 14\u201317). Stop-and-go mixes: Providing probabilistic anonymity in an open system. Portland, OR, USA.","DOI":"10.1007\/3-540-49380-8_7"},{"key":"ref_40","doi-asserted-by":"crossref","first-page":"84","DOI":"10.1145\/358549.358563","article-title":"Untraceable electronic mail, return addresses, and digital pseudonyms","volume":"24","author":"Chaum","year":"1981","journal-title":"Commun. ACM"},{"key":"ref_41","unstructured":"Rennhard, M., and Plattner, B. (2003, January 9\u201311). Practical anonymity for the masses with mix-networks. Linz, Austria."},{"key":"ref_42","doi-asserted-by":"crossref","unstructured":"Danezis, G. (2003, January 26\u201328). Mix-networks with restricted routes. Dresden, Germany.","DOI":"10.1007\/978-3-540-40956-4_1"},{"key":"ref_43","unstructured":"Goldschlag, D., Reed, M., and Syverson, P. (June, January 30). Hiding routing information. Cambridge, UK."},{"key":"ref_44","unstructured":"Reed, M.G., Syverson, P.F., and Goldschlag, D.M. (1996, January 9\u201313). Proxies for anonymous routing. San Diego, CA, USA."},{"key":"ref_45","doi-asserted-by":"crossref","unstructured":"Dingledine, R., Mathewson, N., and Syverson, P. (2004, January 9\u201313). Tor: The second-generation onion router. Berkeley, CA, USA.","DOI":"10.21236\/ADA465464"},{"key":"ref_46","doi-asserted-by":"crossref","unstructured":"Levine, B.N., Reiter, M.K., Wang, C., and Wright, M. (2004, January 9\u201313). Timing attacks in low-latency mix systems. San Diego, CA, USA.","DOI":"10.1007\/978-3-540-27809-2_25"},{"key":"ref_47","doi-asserted-by":"crossref","unstructured":"Bauer, K., McCoy, D., Grunwald, D., Kohno, T., and Sicker, D. (2007). Low-resource routing attacks against anonymous systems, University of Colorado. Technical Report.","DOI":"10.1145\/1314333.1314336"},{"key":"ref_48","unstructured":"Murdoch, S.J., and Danezis, G. (2005, January 8\u201311). Low-cost traffic analysis of tor. Washington, DC, USA."},{"key":"ref_49","unstructured":"Pfitzmann, B., and Pfitzmann, A. (1990, January 21\u201324). How to break the direct RSA implementation of mixes. Aarhus, Denmark."},{"key":"ref_50","unstructured":"U.S. online and mobile privacy perceptions report. Available online: http:\/\/www.truste.com\/about-TRUSTe\/press-room\/newstrustereleasesuscustomerfindingsreport."},{"key":"ref_51","unstructured":"Toubiana, V., Narayanan, A., Boneh, D., Nissenbaum, H., and Barocas, S. (March, January 28). Adnostic: Privacy preserving targeted advertising. San Diego, CA, USA."},{"key":"ref_52","unstructured":"Fredrikson, M., and Livshits, B. (2011, January 22\u201325). RePriv: Re-envisioning in-browser privacy. Berkeley, CA, USA."},{"key":"ref_53","first-page":"641","article-title":"Query profile obfuscation by means of optimal query exchange between users","volume":"9","year":"2012","journal-title":"IEEE Trans. Depend. Secure Comput"},{"key":"ref_54","first-page":"61","article-title":"A privacy-protecting architecture for recommendation systems via the suppression of ratings","volume":"6","year":"2012","journal-title":"Int. J. Security, Appl"},{"key":"ref_55","doi-asserted-by":"crossref","unstructured":"Li, N., Li, T., and Venkatasubramanian, S. (2007, January 15\u201320). t-Closeness: Privacy beyond k-anonymity and l-diversity. Istanbul, Turkey.","DOI":"10.1109\/ICDE.2007.367856"},{"key":"ref_56","doi-asserted-by":"crossref","unstructured":"Cover, T.M., and Thomas, J.A. (2006). Elements of Information Theory, Wiley. [2nd ed].","DOI":"10.1002\/047174882X"},{"key":"ref_57","unstructured":"Available online: https:\/\/support.google.com\/adwords\/answer\/3056153."},{"key":"ref_58","unstructured":"Available online: http:\/\/www.google.es\/ads\/displaynetwork."},{"key":"ref_59","unstructured":"Estra da Jim\u00e9nez, J.A. Implementation of a firefox extension that measures user privacy risk in web search. Available online: http:\/\/hdl.handle.net\/2099.1\/19549."},{"key":"ref_60","unstructured":"Hoyos, A.F.R. Evaluation of the privacy risk for online search and social tagging systems. Available online: http:\/\/hdl.handle.net\/2099.1\/19550."},{"key":"ref_61","unstructured":"Ibaraki, T., and Katoh, N. (1988). Resource Allocation Problems: Algorithmic Approaches, MIT Press."},{"key":"ref_62","doi-asserted-by":"crossref","unstructured":"Boyd, S., and Vandenberghe, L. (2004). Convex Optimization, Cambridge University Press.","DOI":"10.1017\/CBO9780511804441"},{"key":"ref_63","unstructured":"Available online: http:\/\/www.grouplens.org."},{"key":"ref_64","unstructured":"Available online: http:\/\/www.grouplens.org\/system\/files\/ml-10m-README.html."}],"container-title":["Entropy"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.mdpi.com\/1099-4300\/16\/3\/1586\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,10,11]],"date-time":"2025-10-11T21:09:28Z","timestamp":1760216968000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.mdpi.com\/1099-4300\/16\/3\/1586"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2014,3,21]]},"references-count":64,"journal-issue":{"issue":"3","published-online":{"date-parts":[[2014,3]]}},"alternative-id":["e16031586"],"URL":"https:\/\/doi.org\/10.3390\/e16031586","relation":{},"ISSN":["1099-4300"],"issn-type":[{"value":"1099-4300","type":"electronic"}],"subject":[],"published":{"date-parts":[[2014,3,21]]}}}