<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Publishing DTD v1.1 20151215//EN" "http://jats.nlm.nih.gov/publishing/1.1/JATS-journalpublishing1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink" xmlns:mml="http://www.w3.org/1998/Math/MathML" xml:lang="en" article-type="research-article" dtd-version="1.1">
<front>
<journal-meta>
<journal-id journal-id-type="pmc">CMC</journal-id>
<journal-id journal-id-type="nlm-ta">CMC</journal-id>
<journal-id journal-id-type="publisher-id">CMC</journal-id>
<journal-title-group>
<journal-title>Computers, Materials &#x0026; Continua</journal-title>
</journal-title-group>
<issn pub-type="epub">1546-2226</issn>
<issn pub-type="ppub">1546-2218</issn>
<publisher>
<publisher-name>Tech Science Press</publisher-name>
<publisher-loc>USA</publisher-loc>
</publisher>
</journal-meta>
<article-meta>
<article-id pub-id-type="publisher-id">66270</article-id>
<article-id pub-id-type="doi">10.32604/cmc.2025.066270</article-id>
<article-categories>
<subj-group subj-group-type="heading">
<subject>Article</subject>
</subj-group>
</article-categories>
<title-group>
<article-title>Adversarial Perturbation for Sensor Data Anonymization: Balancing Privacy and Utility</article-title>
<alt-title alt-title-type="left-running-head">Adversarial Perturbation for Sensor Data Anonymization: Balancing Privacy and Utility</alt-title>
<alt-title alt-title-type="right-running-head">Adversarial Perturbation for Sensor Data Anonymization: Balancing Privacy and Utility</alt-title>
</title-group>
<contrib-group>
<contrib id="author-1" contrib-type="author" corresp="yes">
<name name-style="western"><surname>Hasegawa</surname><given-names>Tatsuhito</given-names></name><xref ref-type="author-notes" rid="afn1">#</xref><email>t-hase@u-fukui.ac.jp</email></contrib>
<contrib id="author-2" contrib-type="author">
<name name-style="western"><surname>Fujino</surname><given-names>Kyosuke</given-names></name><xref ref-type="author-notes" rid="afn1">#</xref></contrib>
<aff id="aff-1"><institution>Graduate School of Engineering, University of Fukui, Fukui, 910-8507</institution>, <country>Japan</country></aff>
</contrib-group>
<author-notes>
<corresp id="cor1"><label>&#x002A;</label>Corresponding Author: Tatsuhito Hasegawa. Email: <email>t-hase@u-fukui.ac.jp</email></corresp>
<fn id="afn1">
<p><sup>#</sup>These authors contributed equally to this work</p>
</fn>
</author-notes>
<pub-date date-type="collection" publication-format="electronic">
<year>2025</year>
</pub-date>
<pub-date date-type="pub" publication-format="electronic">
<day>03</day><month>07</month><year>2025</year>
</pub-date>
<volume>84</volume>
<issue>2</issue>
<fpage>2429</fpage>
<lpage>2454</lpage>
<history>
<date date-type="received">
<day>03</day>
<month>4</month>
<year>2025</year>
</date>
<date date-type="accepted">
<day>29</day>
<month>5</month>
<year>2025</year>
</date>
</history>
<permissions>
<copyright-statement>&#x00A9; 2025 The Authors.</copyright-statement>
<copyright-year>2025</copyright-year>
<copyright-holder>Published by Tech Science Press.</copyright-holder>
<license xlink:href="https://creativecommons.org/licenses/by/4.0/">
<license-p>This work is licensed under a <ext-link ext-link-type="uri" xlink:type="simple" xlink:href="https://creativecommons.org/licenses/by/4.0/">Creative Commons Attribution 4.0 International License</ext-link>, which permits unrestricted use, distribution, and reproduction in any medium, provided the original work is properly cited.</license-p>
</license>
</permissions>
<self-uri content-type="pdf" xlink:href="TSP_CMC_66270.pdf"></self-uri>
<abstract>
<p>Recent advances in wearable devices have enabled large-scale collection of sensor data across healthcare, sports, and other domains but this has also raised critical privacy concerns, especially under tightening regulations such as the General Data Protection Regulation (GDPR), which explicitly restrict the processing of data that can re-identify individuals. Although existing anonymization approaches such as the Anonymizing AutoEncoder (AAE) can reduce the risk of re-identification, they often introduce substantial waveform distortions and fail to preserve information beyond a single classification task (e.g., human activity recognition). This study proposes a novel sensor data anonymization method based on Adversarial Perturbations (AP) to address these limitations. By generating minimal yet targeted noise, the proposed method significantly degrades the accuracy of identity classification while retaining essential features for multiple tasks such as activity, gender, or device-position recognition. Moreover, to enhance robustness against frequency-domain analysis, additional models trained on transformed (e.g., short-time Fourier transform (STFT)) representations are incorporated into the perturbation process. A multi-task formulation is introduced that selectively suppresses person-identifying features while reinforcing those relevant to other desired tasks without retraining large autoencoder-based architectures. The proposed framework is, to our knowledge, the first AP-based anonymization technique that (i) defends simultaneously against time- and frequency-domain attacks and (ii) allows per-task trade-off control on a single forward-back-propagation run, enabling real-time, on-device deployment on commodity hardware. On three public datasets, the proposed method reduces person-identification accuracy from 60&#x2013;90% to near-chance levels (<inline-formula id="ieqn-1"><mml:math id="mml-ieqn-1"><mml:mo>&#x2264;</mml:mo><mml:mspace width="negativethinmathspace" /><mml:mn>5</mml:mn></mml:math></inline-formula>%) while preserving the original activity-recognition F1 both in the time and frequency domains. Compared with the baseline AAE, the proposed method improves downstream task F1 and lowers waveform mean squared error, demonstrating a better privacy-utility trade-off without additional model retraining. These findings underscore the effectiveness and flexibility of AP in privacy-preserving sensor-data processing, offering a practical solution that safeguards user identity while retaining rich, application-critical information.</p>
</abstract>
<kwd-group kwd-group-type="author">
<kwd>Human activity recognition</kwd>
<kwd>privacy-aware IoT</kwd>
<kwd>adversarial perturbation</kwd>
</kwd-group>
<funding-group>
<award-group id="awg1">
<funding-source>Japan Society for the Promotion of Science</funding-source>
<award-id>23K11164</award-id>
</award-group>
</funding-group>
</article-meta>
</front>
<body>
<sec id="s1">
<label>1</label>
<title>Introduction</title>
<p>Wearable devices have rapidly evolved in recent years, enabling continuous and large-scale collection of sensor data related to human activity, physiology, and environment. These sensors, embedded in smartwatches, smartphones, or fitness bands, capture diverse signals such as acceleration, heart rate, and gyroscopic measurements. Such capabilities have facilitated breakthroughs in healthcare applications [<xref ref-type="bibr" rid="ref-1">1</xref>&#x2013;<xref ref-type="bibr" rid="ref-3">3</xref>], sports science [<xref ref-type="bibr" rid="ref-4">4</xref>], and human-computer interaction [<xref ref-type="bibr" rid="ref-5">5</xref>]. However, the increased availability and granularity of sensor data have also raised critical privacy concerns [<xref ref-type="bibr" rid="ref-6">6</xref>,<xref ref-type="bibr" rid="ref-7">7</xref>]. Sensitive attributes, ranging from demographic information to health indicators, can be inferred from seemingly harmless motion signals when advanced machine learning techniques are applied [<xref ref-type="bibr" rid="ref-8">8</xref>,<xref ref-type="bibr" rid="ref-9">9</xref>].</p>
<p>To mitigate the risk of re-identification and protect sensitive personal attributes, various anonymization frameworks have been proposed [<xref ref-type="bibr" rid="ref-10">10</xref>,<xref ref-type="bibr" rid="ref-11">11</xref>]. One well-studied approach is the Anonymizing AutoEncoder (AAE) [<xref ref-type="bibr" rid="ref-12">12</xref>,<xref ref-type="bibr" rid="ref-13">13</xref>], which integrates autoencoder-based transformations with a supervised loss term to degrade identity-related features while preserving a target classification task (e.g., Human Activity Recognition; HAR). While AAE can effectively lower identification accuracy, it often introduces substantial distortions in the waveform, reducing the data&#x2019;s utility for tasks beyond the one explicitly used in training the autoencoder. Moreover, it assumes that new analysis models will be trained on the anonymized data itself, making it difficult to reuse established models trained on non-anonymized (raw) signals.</p>
<p>This study proposes a new sensor data anonymization framework Anonymizing Adversarial Perturbation (AAP), which applies subtle perturbations to inputs, leveraging adversarial perturbations (AP) [<xref ref-type="bibr" rid="ref-14">14</xref>], to balance privacy and multi-task utility. The proposed method uses identity classification models to generate targeted, minimal distortions that degrade re-identification accuracy, while concurrently reinforcing or preserving important features for other tasks such as gender or detailed HAR. This extended scheme is referred to as Frequency-informed AAP (F-AAP) and Multi-task Frequency-informed AAP (MF-AAP). Through extensive experiments on publicly available sensor datasets (Motion Sense [<xref ref-type="bibr" rid="ref-15">15</xref>], MHEALTH [<xref ref-type="bibr" rid="ref-16">16</xref>], and UniMiB SHAR [<xref ref-type="bibr" rid="ref-17">17</xref>]), this study demonstrates that:
<list list-type="simple">
<list-item><label>1.</label><p>The proposed adversarial-perturbation approach preserves richer waveform characteristics than autoencoder-based anonymization, enabling higher accuracy on tasks not explicitly considered during anonymization.</p></list-item>
<list-item><label>2.</label><p>Incorporating multiple models trained in time and frequency domains leads to greater resilience against re-identification, even if adversaries transform the signals using short-time Fourier Transform (STFT) methods.</p></list-item>
<list-item><label>3.</label><p>A multi-task formulation allows users to selectively strengthen or weaken different task-related features with no need to retrain large generative networks, greatly improving flexibility in real-world deployments.</p></list-item>
</list></p>
<p>Although anonymization methods based on autoencoders [<xref ref-type="bibr" rid="ref-12">12</xref>] and Generative Adversarial Networks (GANs) [<xref ref-type="bibr" rid="ref-11">11</xref>] can obscure user identity, they require large models and retraining and often degrade downstream&#x2013;task accuracy. Moreover, prior work implicitly assumes that an attacker operates in the time domain, overlooking the fact that simple spectral transforms can re-expose user-specific cues. To date, no study has applied adversarial perturbations to sensor signals while simultaneously preserving the utility of multiple downstream tasks. This gap motivates the present work, which introduces AAP, F-AAP, and MF-AAP to (i) anonymize wearable-sensor data with minimal waveform distortion, (ii) remain robust in both time and frequency domains, and (iii) retain high accuracy for activity, position, and gender recognition. Overall, the adversarial-perturbation methodology offers a lightweight yet powerful alternative to AAE-based sensor data anonymization. By focusing on minimal and targeted modifications, it achieves strong privacy guarantees while maintaining high utility across diverse tasks, which is essential for the next generation of wearable sensing systems.</p>
<p>The objectives of this study are as follows:
<list list-type="simple">
<list-item><label>O1</label><p> Reduce person-identification accuracy to chance level while introducing minimal waveform distortion.</p></list-item>
<list-item><label>O2</label><p> Achieve robustness against spectral attacks by leveraging both time- and frequency-domain models.</p></list-item>
<list-item><label>O3</label><p> Enable selective utility preservation for multiple downstream tasks without retraining large networks.</p></list-item>
</list></p>
<p>The remainder of this paper is organized as follows: <xref ref-type="sec" rid="s2">Section 2</xref> reviews related work; <xref ref-type="sec" rid="s3">Section 3</xref> defines the privacy-preserving scenario of this study; <xref ref-type="sec" rid="s4">Section 4</xref> details the proposed AAP, F-AAP, and MF-AAP; <xref ref-type="sec" rid="s5">Section 5</xref> presents experimental setup and results; <xref ref-type="sec" rid="s6">Section 6</xref> discusses limitations and future work; finally, <xref ref-type="sec" rid="s7">Section 7</xref> concludes the paper.</p>
</sec>
<sec id="s2">
<label>2</label>
<title>Related Work</title>
<p>Sensor data have been extensively leveraged in diverse domains, ranging from industrial settings and urban infrastructures to healthcare and daily life. Nevertheless, such broad applicability has also prompted critical discussions on privacy and security. This section first introduces representative use cases of sensor data, followed by an overview of HAR methodologies. Existing anonymization techniques, including conventional statistical methods, GAN-based approaches, and autoencoder-based methods, are surveyed, after which recent advances in adversarial perturbation for privacy are discussed. The present study is then positioned in relation to these prior works.</p>
<sec id="s2_1">
<label>2.1</label>
<title>Applications of Sensor Data</title>
<p>Sensor deployments in industrial IoT environments have enabled real-time monitoring and optimization of manufacturing processes. Xu et al. [<xref ref-type="bibr" rid="ref-18">18</xref>] proposed a hierarchical resource allocation algorithm that takes into account safety, privacy, and reliability constraints, thereby enhancing efficiency across industrial operations. In the context of smart cities, Talebkhah et al. [<xref ref-type="bibr" rid="ref-19">19</xref>] reported ongoing projects that utilize sensor networks for traffic control, environmental surveillance, and disaster management. These initiatives highlight the transformative potential of large-scale sensor deployments in urban planning and sustainability.</p>
<p>Wearable technologies are also finding widespread adoption in sports science and consumer fitness. Lam Po Tang [<xref ref-type="bibr" rid="ref-4">4</xref>] demonstrated how wearable sensors collecting heart rate and posture data can be harnessed to refine training regimens and speed recovery. Meanwhile, newly developed smart garments and textiles are emerging to measure physiological signals in everyday settings. In healthcare, sensor-based HAR has proven beneficial for patient care and clinical efficiency. Lee et al. [<xref ref-type="bibr" rid="ref-20">20</xref>] introduced a lifelogging system employing three-axis accelerometers and combined statistical and spectral features to achieve high-accuracy HAR for daily-life analysis. Similarly, Xu et al. [<xref ref-type="bibr" rid="ref-21">21</xref>] exploited random forest classifiers augmented with contextual information to recognize activities among seniors. Inoue et al. [<xref ref-type="bibr" rid="ref-22">22</xref>] developed a system for analyzing nursing workflows, aiming to improve operational efficiencies in clinical environments. Sensor technologies have likewise progressed across a broad spectrum, encompassing systems for pain monitoring and mitigation [<xref ref-type="bibr" rid="ref-3">3</xref>] as well as implantable <italic>in-vivo</italic> sensors [<xref ref-type="bibr" rid="ref-2">2</xref>]. While these studies underscore the utility of sensor data, they also underline the growing importance of privacy protection to secure personal information against misuse.</p>
</sec>
<sec id="s2_2">
<label>2.2</label>
<title>HAR</title>
<p>HAR encompasses a range of techniques aimed at classifying sensor signals into specific behavioral categories. Traditional HAR approaches predominantly employed handcrafted statistical or spectral features, which were then input into machine learning algorithms. Kwapisz et al. [<xref ref-type="bibr" rid="ref-23">23</xref>] used smartphone accelerometers to identify walking and stair-climbing behaviors, demonstrating how fundamental statistical features can boost model accuracy. By contrast, Shoaib et al. [<xref ref-type="bibr" rid="ref-24">24</xref>] combined data from smartphones and wristbands to handle more complex activities and highlighted the value of sensor diversity. Voicu et al. [<xref ref-type="bibr" rid="ref-25">25</xref>] integrated readings from accelerometers, gyroscopes, and gravity sensors, showcasing the feasibility of accurate activity classification solely using commercial smartphones. There are also cases where accelerometers have been applied to enhance the security of voice authentication [<xref ref-type="bibr" rid="ref-26">26</xref>].</p>
<p>In more recent developments, deep learning models, particularly convolutional neural networks and recurrent neural networks, have been adopted in an end-to-end manner. Li et al. [<xref ref-type="bibr" rid="ref-27">27</xref>] found that deep neural networks outperform methods reliant on hand-crafted features when analyzing wearable sensor data. DenseNet-inspired architectures have also been proposed to capture spatiotemporal dependencies effectively, as exemplified by Ronald et al. [<xref ref-type="bibr" rid="ref-28">28</xref>] in their HARDenseNet. Ronald et al. [<xref ref-type="bibr" rid="ref-29">29</xref>] integrated ResNet and Inception modules to develop iSPLInception, achieving high accuracy in HAR tasks. In recent years, efforts to leverage Transformer architectures for human activity recognition have also become widespread [<xref ref-type="bibr" rid="ref-30">30</xref>&#x2013;<xref ref-type="bibr" rid="ref-32">32</xref>]. While deep learning has propelled the performance of HAR systems, it has also amplified privacy concerns, because large-scale sensor data collection can reveal sensitive personal details.</p>
</sec>
<sec id="s2_3">
<label>2.3</label>
<title>Sensor Data Anonymization</title>
<p>In the field of sensor data anonymization for HAR, several comprehensive surveys have been conducted [<xref ref-type="bibr" rid="ref-33">33</xref>,<xref ref-type="bibr" rid="ref-34">34</xref>]. Based on these surveys, existing algorithm-based anonymization methods can be broadly classified into three categories: (a) Statistical Anonymization, (b) Generation-based Anonymization, and (c) Reconstruction-based Anonymization.</p>
<sec id="s2_3_1">
<label>2.3.1</label>
<title>(a) Statistical Anonymization Techniques</title>
<p>Several statistical approaches exist for sensor data anonymization, each attempting to mask identity-revealing details while preserving data utility. Filtering eliminates identifiable patterns in sensor signals through time- or frequency-domain transformations [<xref ref-type="bibr" rid="ref-35">35</xref>]. For instance, removing certain frequency bands may obscure users&#x2019; unique motion signatures. However, this strategy risks losing salient information necessary for downstream tasks. Data perturbation injects random noise to conceal personal features without fully distorting the dataset&#x2019;s broader statistical properties. Gaussian noise addition [<xref ref-type="bibr" rid="ref-36">36</xref>] is a commonly cited example. Striking a balance is vital: excessive noise diminishes data utility, while insufficient noise leaves identifying cues intact.</p>
<p>Data generalization replaces precise readings with coarser-grained versions. For example, converting timestamps to approximate time bins or rounding sensor measurements to broader intervals can mitigate re-identification risks [<xref ref-type="bibr" rid="ref-37">37</xref>]. By introducing <inline-formula id="ieqn-2"><mml:math id="mml-ieqn-2"><mml:mi>k</mml:mi></mml:math></inline-formula>-anonymity [<xref ref-type="bibr" rid="ref-38">38</xref>], each data record becomes indistinguishable from at least <inline-formula id="ieqn-3"><mml:math id="mml-ieqn-3"><mml:mo stretchy="false">(</mml:mo><mml:mi>k</mml:mi><mml:mo>&#x2212;</mml:mo><mml:mn>1</mml:mn><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula> others, but at the cost of reduced specificity for analytics [<xref ref-type="bibr" rid="ref-39">39</xref>]. Differential privacy provides a formal mechanism to limit the impact of any single record on aggregate statistics. However, implementing it in sensor-based HAR remains nontrivial, since ensuring robust privacy often requires a high level of noise, thereby degrading recognition accuracy [<xref ref-type="bibr" rid="ref-10">10</xref>]. Random Projection (RP) [<xref ref-type="bibr" rid="ref-40">40</xref>] is a technique that projects high-dimensional data into a randomly chosen lower-dimensional subspace, leveraging the Johnson-Lindenstrauss lemma to approximately preserve pairwise distances. This property hampers direct reidentification attempts because reconstructing the original sensor signals becomes more difficult. However, when the projection dimension is chosen with care, the sensor data can still retain sufficient utility for subsequent recognition tasks such as classification or clustering. A trade-off nevertheless remains: an overly aggressive reduction in dimensionality may obscure features essential for analytics, whereas a projection that is too large may continue to expose identifying signatures.</p>
<p>While these statistical methods are relatively straightforward, they each face inherent constraints, especially when aiming to maintain the fidelity necessary for sophisticated HAR tasks.</p>
</sec>
<sec id="s2_3_2">
<label>2.3.2</label>
<title>(b) Generation-Based Anonymization</title>
<p>GANs [<xref ref-type="bibr" rid="ref-41">41</xref>] have emerged as a promising tool for synthesizing sensor data that preserve certain target attributes while concealing sensitive ones. Menasria et al. [<xref ref-type="bibr" rid="ref-11">11</xref>] introduced Private GAN (PGAN) frameworks (PGAN1 and PGAN2), focusing on selectively safeguarding private attributes and retaining public information. By generating data from a learned distribution rather than sharing direct measurements, the approach lessens re-identification risks. In addition, anonymization methods based on the GAN with conditional AE [<xref ref-type="bibr" rid="ref-42">42</xref>] and approaches that combine GANs with microaggregation [<xref ref-type="bibr" rid="ref-43">43</xref>] have also been proposed. However, GAN-based methods often demand large-scale datasets and can be difficult to tailor for individualized user privacy.</p>
<p>Some studies have tackled anonymization by applying adversarial training (AT) in the feature space without generating waveforms [<xref ref-type="bibr" rid="ref-44">44</xref>,<xref ref-type="bibr" rid="ref-45">45</xref>]. These methods can be regarded as approaches for generating an anonymized feature space. Furthermore, anonymization methods based on diffusion models have also been proposed in recent years [<xref ref-type="bibr" rid="ref-46">46</xref>].</p>
</sec>
<sec id="s2_3_3">
<label>2.3.3</label>
<title>(c) Reconstruction-Based Anonymization</title>
<p>Malekzadeh et al. [<xref ref-type="bibr" rid="ref-12">12</xref>] proposed an Anonymizing AutoEncoder (AAE) that simultaneously degrades user identification accuracy and retains utility for a designated recognition task (e.g., HAR), and Bigelli et al. [<xref ref-type="bibr" rid="ref-13">13</xref>] extend AAE for preventing some privacy attributes. AAE functions by transforming each sensor sample using an autoencoder constrained by classification losses for user ID and activity, alongside a mean squared error (MSE) term to mitigate distortion. Although AAE generally performs well for its intended use case (i.e., training new HAR models on anonymized data), it can exhibit considerable waveform modifications (<xref ref-type="fig" rid="fig-1">Fig. 1</xref>) and lacks explicit mechanisms for preserving information relevant to tasks other than the primary classification. Moreover, anonymity under frequency-domain analysis remains insufficiently addressed.</p>
<fig id="fig-1">
<label>Figure 1</label>
<caption>
<title>Samples of waveform changes before and after conversion using the reconstruction-based method and the proposed method</title>
</caption>
<graphic mimetype="image" mime-subtype="tif" xlink:href="CMC_66270-fig-1.tif"/>
</fig>
<p>As a related approach, in image-based human activity recognition, autoencoder-based method [<xref ref-type="bibr" rid="ref-47">47</xref>] have been proposed to address reconstruction-based threats. An integrative method utilizing autoencoders has also been proposed [<xref ref-type="bibr" rid="ref-48">48</xref>].</p>
</sec>
<sec id="s2_3_4">
<label>2.3.4</label>
<title>AP for Privacy</title>
<p>AP [<xref ref-type="bibr" rid="ref-14">14</xref>] were initially studied in computer vision and speech recognition as imperceptible noise that induces misclassifications. Strategies such as Basic Iterative Method (BIM) [<xref ref-type="bibr" rid="ref-49">49</xref>], Diverse-Inputs Iterative Fast Gradient Sign Method (<inline-formula id="ieqn-4"><mml:math id="mml-ieqn-4"><mml:msup><mml:mtext>DI</mml:mtext><mml:mn>2</mml:mn></mml:msup></mml:math></inline-formula>-FGSM) [<xref ref-type="bibr" rid="ref-50">50</xref>], and Translation-Invariant FGSM (TI-FGSM) [<xref ref-type="bibr" rid="ref-51">51</xref>] refine the basic FGSM [<xref ref-type="bibr" rid="ref-52">52</xref>] approach to enhance attack strength or transferability by iterating over gradient updates or employing transformations and smoothing filters [<xref ref-type="bibr" rid="ref-53">53</xref>]. Outside of pure security contexts, these methods can be repurposed for anonymization: minor signal distortions strategically undermine identity classification while leaving much of the original data structure intact.</p>
<p>Although AP have been validated in image and audio domains, their application to time-series sensor data, particularly for privacy protection, remains an emerging area. AP-based anonymization can offer advantages over generative or statistical approaches by requiring minimal structural adjustments to raw signals.</p>
</sec>
</sec>
<sec id="s2_4">
<label>2.4</label>
<title>Positioning of the Present Work</title>
<p>This section clarifies the positioning of the proposed methods relative to existing anonymization approaches. <xref ref-type="table" rid="table-1">Table 1</xref> compares six representative methods using seven columns, each reflecting a key property of sensor-data anonymization techniques.</p>
<table-wrap id="table-1">
<label>Table 1</label>
<caption>
<title>Characteristics comparison of various anonymization methods</title>
</caption>
<table>
<colgroup>
<col/>
<col/>
<col/>
<col/>
<col/>
<col/>
<col/>
<col/>
<col/>
</colgroup>
<thead>
<tr>
<th>Method</th>
<th>Ann.</th>
<th>Stab.</th>
<th>Anon.</th>
<th>Pres.</th>
<th>Int. adj.</th>
<th>Freq.</th>
<th>Flex.</th>
<th>HAR</th>
</tr>
</thead>
<tbody>
<tr>
<td>Statistical</td>
<td>None</td>
<td>High</td>
<td>Middle</td>
<td>Middle</td>
<td><inline-formula id="ieqn-5"><mml:math id="mml-ieqn-5"><mml:mi>&#x2713;</mml:mi></mml:math></inline-formula></td>
<td>&#x2717;</td>
<td>&#x2717;</td>
<td>&#x2717;</td>
</tr>
<tr>
<td>GAN-based [<xref ref-type="bibr" rid="ref-11">11</xref>]</td>
<td>Personal</td>
<td>Low</td>
<td>High</td>
<td>Low</td>
<td>&#x2717;</td>
<td>&#x2717;</td>
<td>&#x2717;</td>
<td>&#x2717;</td>
</tr>
<tr>
<td>AT-based [<xref ref-type="bibr" rid="ref-44">44</xref>,<xref ref-type="bibr" rid="ref-45">45</xref>]</td>
<td>Personal</td>
<td>Middle</td>
<td>High</td>
<td>Low</td>
<td>&#x2717;</td>
<td>&#x2717;</td>
<td><inline-formula id="ieqn-6"><mml:math id="mml-ieqn-6"><mml:mi>&#x2713;</mml:mi></mml:math></inline-formula></td>
<td><inline-formula id="ieqn-7"><mml:math id="mml-ieqn-7"><mml:mi>&#x2713;</mml:mi></mml:math></inline-formula></td>
</tr>
<tr>
<td>AAE [<xref ref-type="bibr" rid="ref-12">12</xref>,<xref ref-type="bibr" rid="ref-13">13</xref>]</td>
<td>Personal</td>
<td>Middle</td>
<td>High</td>
<td>Low</td>
<td>&#x2717;</td>
<td>&#x2717;</td>
<td>&#x2717;</td>
<td><inline-formula id="ieqn-8"><mml:math id="mml-ieqn-8"><mml:mi>&#x2713;</mml:mi></mml:math></inline-formula></td>
</tr>
<tr>
<td><bold>AAP</bold></td>
<td>Personal</td>
<td>High</td>
<td>High</td>
<td>High</td>
<td><inline-formula id="ieqn-9"><mml:math id="mml-ieqn-9"><mml:mi>&#x2713;</mml:mi></mml:math></inline-formula></td>
<td>&#x2717;</td>
<td>&#x2717;</td>
<td><inline-formula id="ieqn-10"><mml:math id="mml-ieqn-10"><mml:mi>&#x2713;</mml:mi></mml:math></inline-formula></td>
</tr>
<tr>
<td><bold>F-AAP</bold></td>
<td>Personal</td>
<td>High</td>
<td>High</td>
<td>High</td>
<td><inline-formula id="ieqn-11"><mml:math id="mml-ieqn-11"><mml:mi>&#x2713;</mml:mi></mml:math></inline-formula></td>
<td><inline-formula id="ieqn-12"><mml:math id="mml-ieqn-12"><mml:mi>&#x2713;</mml:mi></mml:math></inline-formula></td>
<td>&#x2717;</td>
<td><inline-formula id="ieqn-13"><mml:math id="mml-ieqn-13"><mml:mi>&#x2713;</mml:mi></mml:math></inline-formula></td>
</tr>
<tr>
<td><bold>MF-AAP</bold></td>
<td>Various info.</td>
<td>Middle</td>
<td>High</td>
<td>High</td>
<td><inline-formula id="ieqn-14"><mml:math id="mml-ieqn-14"><mml:mi>&#x2713;</mml:mi></mml:math></inline-formula></td>
<td><inline-formula id="ieqn-15"><mml:math id="mml-ieqn-15"><mml:mi>&#x2713;</mml:mi></mml:math></inline-formula></td>
<td><inline-formula id="ieqn-16"><mml:math id="mml-ieqn-16"><mml:mi>&#x2713;</mml:mi></mml:math></inline-formula></td>
<td><inline-formula id="ieqn-17"><mml:math id="mml-ieqn-17"><mml:mi>&#x2713;</mml:mi></mml:math></inline-formula></td>
</tr>
</tbody>
</table>
</table-wrap>
<sec id="s2_4_1">
<label>2.4.1</label>
<title>Abbreviations and Their Meanings</title>
<p><list list-type="bullet">
<list-item>
<p><bold>Method:</bold> The name or category of each anonymization approach.</p></list-item>
<list-item>
<p><bold>Ann. (Requiring annotation):</bold> Indicates whether annotation labels are required to train the anonymization model. While GAN-based and autoencoder-based methods use personal labels to <italic>maximize</italic> the personal identification loss (for training a discriminator or autoencoder), AAP uses them to <italic>minimize</italic> the personal identification loss. In addition, both AAE and AAP rely on target labels (e.g., activity labels) to enhance human activity recognition (HAR) performance.</p></list-item>
<list-item>
<p><bold>Stab. (Stability):</bold> The extent to which an approach preserves the original waveform structure. <italic>High</italic> means minimal distortion, <italic>Middle</italic> indicates moderate change, and <italic>Low</italic> suggests a high degree of alteration.</p></list-item>
<list-item>
<p><bold>Anon. (Anonymity):</bold> The effectiveness in degrading person-identification accuracy (i.e., increasing re-identification difficulty). <italic>High</italic> implies strong anonymization (significantly reducing user-specific signals), <italic>Middle</italic> indicates partial anonymization, and <italic>Low</italic> suggests limited success in concealing identity.</p></list-item>
<list-item>
<p><bold>Pres. (Information preservation):</bold> How effectively each method retains task-relevant information in the anonymized data. <italic>High</italic> indicates minimal loss of essential features, <italic>Middle</italic> indicates moderate loss, and <italic>Low</italic> indicates that critical signals needed for downstream tasks may be severely disrupted.</p></list-item>
<list-item>
<p><bold>Int. adj. (Intensity adjustability):</bold> Whether the method offers flexible control over anonymization strength. GAN-based and autoencoder-based methods typically make re-identification more difficult <italic>only</italic> during the training phase; thus, their anonymization strength is not easily adjustable at inference time. By contrast, Statistical and AAP approaches can tune noise intensity to balance privacy and utility on demand.</p></list-item>
<list-item>
<p><bold>Freq. (Frequency-domain robustness):</bold> Whether the method remains effective against frequency-domain analysis. A check mark (<inline-formula id="ieqn-18"><mml:math id="mml-ieqn-18"><mml:mi>&#x2713;</mml:mi></mml:math></inline-formula>) signifies that the anonymization withstands transformations such as STFT, whereas a blank cell indicates vulnerability to frequency-based attacks.</p></list-item>
<list-item>
<p><bold>Flex. (Flexibility):</bold> The ability to selectively preserve or anonymize different attributes of the data. MF-AAP, for example, can flexibly determine which characteristics (e.g., gender or device position) are retained and which are suppressed.</p></list-item>
<list-item>
<p><bold>HAR:</bold> Whether or not consideration is given to maintaining behavior recognition accuracy.</p></list-item>
</list></p>
</sec>
<sec id="s2_4_2">
<label>2.4.2</label>
<title>Comparative Features of the Proposed Approach</title>
<p>As shown in <xref ref-type="table" rid="table-1">Table 1</xref>, traditional Statistical methods generally do not require unique annotation labels but do not explicitly anonymize user attributes. Although they allow parameter tuning (Int. adj. <inline-formula id="ieqn-19"><mml:math id="mml-ieqn-19"><mml:mi>&#x2713;</mml:mi></mml:math></inline-formula>), their anonymization and information preservation capabilities remain at only moderate levels (Anon. &#x003D; Middle, Pres. &#x003D; Middle). By contrast, GAN- and AT-based techniques can strongly reduce user identification risk (Anon. &#x003D; High), as with differential privacy. However, no prior work has been found that leverages GANs to maintain or improve HAR accuracy. Moreover, they demand large training datasets and specialized hyperparameter tuning for stable operation (Stab. &#x003D; Low) and tend to lose fine-grained information for multiple tasks (Pres. &#x003D; Low).</p>

<p>AAE (Anonymizing AutoEncoder) reaches high anonymity (Anon. &#x003D; High) while preserving certain targeted behaviors, but it requires strict hyperparameter tuning for stabilising model training because of using the minimax optimization such as GANs (Stab. &#x003D; Middle) and has limited capacity for retaining diverse information (Pres. &#x003D; Low). Additionally, most autoencoder-based approaches do not provide an explicit intensity parameter for fine-tuning (Int. adj. is blank), nor do they address frequency-based vulnerabilities.</p>
<p>The proposed methods address these limitations in a stepwise manner. AAP introduces AP specifically targeting user identity signals while preserving the waveform structure (Stab. &#x003D; High) and essential features for various tasks (Pres. &#x003D; High). Under the new column definition, AAP requires both personal labels and specific target labels for training (Ann. &#x003D; Personal &#x0026; Target), thereby allowing it to degrade identification accuracy while keeping task-relevant information (e.g., activity). Unlike AAE, it retains a check mark for Int. adj. by allowing users to tune parameters such as intensity of perturbations. However, basic AAP does not include explicit defenses in the frequency domain (Freq. column is blank).</p>
<p>F-AAP extends AAP by integrating frequency-domain models (Freq. <inline-formula id="ieqn-20"><mml:math id="mml-ieqn-20"><mml:mi>&#x2713;</mml:mi></mml:math></inline-formula>), enabling it to maintain high anonymity (Anon. &#x003D; High) even under STFT-based analysis, while still preserving waveform stability (Stab. &#x003D; High) and crucial task information (Pres. &#x003D; High). In terms of annotation, F-AAP remains similar to AAP (Ann. &#x003D; Personal &#x0026; Target), but now provides robust anonymization in both time and frequency domains.</p>
<p>Finally, MF-AAP broadens its training requirements to cover various user attributes alongside the main classification targets (Ann. &#x003D; Various info. &#x0026; Target). This multi-task design preserves complex task-specific features (Pres. &#x003D; High) and achieves strong anonymity (Anon. &#x003D; High), though the added complexity can slightly reduce stability of model training a little (Stab. &#x003D; Middle). Moreover, MF-AAP carries a check mark in every remaining category, including Flex. (<inline-formula id="ieqn-21"><mml:math id="mml-ieqn-21"><mml:mi>&#x2713;</mml:mi></mml:math></inline-formula>) for selectively suppressing certain user attributes (e.g., gender) while retaining others (e.g., activity). This flexibility allows practitioners to adaptively tune or reinforce features relevant to different downstream applications.</p>
<p>In summary, AAP, F-AAP, and MF-AAP collectively surpass prior methods in balancing anonymity and utility, offering explicit adjustability, multi-task preservation, and robust frequency-domain defenses. These advantages position the proposed methods as promising solutions for high-fidelity sensor-data anonymization across a wide range of use cases. Building on the above comparison, the distinct novelties of this study are: (i) a new adversarial-perturbation paradigm that dispenses with GAN/auto-encoder architectures, (ii) the first sensor-signal anonymization defence that is simultaneously robust in both time and frequency domains (F-AAP), (iii) an attribute-selective privacy&#x2013;utility controller that preserves multiple downstream tasks without retraining (MF-AAP), and (iv) comprehensive cross-dataset evidence demonstrating a new state-of-the-art privacy&#x2013;utility trade-off.</p>
</sec>
</sec>
</sec>
<sec id="s3">
<label>3</label>
<title>Privacy-Preserving Scenario</title>
<sec id="s3_1">
<label>3.1</label>
<title>Scenario and Elements</title>
<p>This section presents the overall privacy-preserving scenario assumed in this study, along with the requirements that must be satisfied in this context. As illustrated in <xref ref-type="fig" rid="fig-2">Fig. 2</xref>, the system adopts a server&#x2013;client architecture for collecting and utilizing sensor data obtained from smartphones and wearable devices. The scenario consists of the following four elements:</p>
<fig id="fig-2">
<label>Figure 2</label>
<caption>
<title>Overview of the assumed privacy-preserving scenario</title>
</caption>
<graphic mimetype="image" mime-subtype="tif" xlink:href="CMC_66270-fig-2.tif"/>
</fig>
<p><bold>User devices</bold></p>
<p>Users employ smartphones or wearable devices to measure the sensor data, attaching the corresponding activity labels before transmitting the data to the application server. Rather than sending the raw sensor data directly, the user devices perform anonymization locally. In doing so, any information enabling personal identification is blocked at the source, preventing raw data from ever reaching the server.</p>
<p><bold>Application server</bold></p>
<p>The application server aggregates and manages the anonymized data and activity labels from multiple user devices, offering services such as lifelogging or other sensor-driven applications. In addition, the server may provide the collected anonymized data to approved third parties for further utilization&#x2014;e.g., activity analysis or the training of activity-recognition models. However, since no personally identifying information is transmitted, the risk of linking data to specific individuals on the server side is minimized.</p>
<p><bold>Data consumers</bold></p>
<p>After receiving anonymized data from the server, data consumers perform various tasks such as activity classification or in-depth behavioral analysis. Additional use cases are anticipated through transfer learning or self-supervised approaches, wherein the anonymized data may be repurposed for tasks beyond basic activity recognition.</p>
<p><bold>Attacker</bold></p>
<p>It is assumed that potential adversaries may attempt to illegally acquire data from the server via methods such as malware, man-in-the-middle (MitM) attacks, or phishing. Particularly problematic is the case where attackers hold a pre-trained person-identification model based on previously leaked raw data. Even if the data on the server are anonymized, the attacker could re-identify individuals if the anonymization is insufficient. This research therefore aims to degrade identification accuracy significantly through on-device anonymization.</p>
</sec>
<sec id="s3_2">
<label>3.2</label>
<title>Risk Examples Based on the Attacker&#x2019;s Possessed Information</title>
<p>Under the conditions of this scenario, attackers may possess the following types of information, which can lead to different privacy risks:</p>
<p><bold>(a) Application server login credentials</bold></p>
<p>By impersonating legitimate users or administrators, attackers can access the anonymized data and associated activity labels on the server. However, since direct personal identifiers are absent, re-identification risk remains low unless the attacker can cross-reference external sources of raw sensor data.</p>
<p><bold>(b) Personal identification model &#x002B; (a)</bold></p>
<p>In addition to (a), by using a person-identification model trained on previously leaked raw sensor data, there is a risk that an attacker can link the sensor data in the server to specific individuals if the anonymization is insufficient. This enables them to correlate behaviors with identified users.</p>
<p><bold>(c) Raw sensor data &#x002B; personal ID &#x002B; (a)</bold></p>
<p>If the attacker already has direct access to users&#x2019; sensor data and personal IDs from some other breach, they can build or refine a personal identification model and pose essentially the same threat as in case (b). In addition, if the anonymization method has also leaked, they can reproduce the anonymized sensor data and build the user identification model supporting anonymized sensor data.</p>
</sec>
<sec id="s3_3">
<label>3.3</label>
<title>Anonymization Requirements</title>
<p>Generally, anonymization in data handling is expected to address the following five points:
<list list-type="simple">
<list-item><label>(1)</label><p>Removal or masking of personally identifying information</p></list-item>
<list-item><label>(2)</label><p>Reduction of re-identification risk</p></list-item>
<list-item><label>(3)</label><p>Preservation of data utility</p></list-item>
<list-item><label>(4)</label><p>Compliance with relevant laws and regulations</p></list-item>
<list-item><label>(5)</label><p>Transparency and accountability</p></list-item>
</list></p>
<p>In the scenario of this study, requirement (1) is already addressed on the user device side by design, and (4) and (5) fall under policy or operational guidelines. Hence, for sensor data anonymization, the primary concerns are (2) reducing re-identification risk and (3) preserving data utility.</p>
<p>Past research has proposed many anonymization methods that obscure personally identifying information while retaining features vital for tasks such as activity classification [<xref ref-type="bibr" rid="ref-12">12</xref>]. However, when the transformed data deviate substantially from the original waveform, important information for secondary use cases may be lost. For instance, if only the &#x201C;activity label&#x201D; is retained, the raw waveform&#x2019;s additional characteristics, potentially valuable for other analyses, become inaccessible. Therefore, the objective is to degrade certain specific aspects of the data (namely person-identification signals) while still preserving as much of the original data characteristics as possible. On the other hand, it should be noted that these are trade-offs.</p>
<p>Based on the above considerations, three requirements emerge for anonymization in the scenario of this study:
<list list-type="bullet">
<list-item>
<p>Transform the data such that a person-identification model trained on real (raw) data can only achieve chance-level accuracy when applied to the anonymized data.</p></list-item>
<list-item>
<p>Retain information necessary for key tasks, particularly activity recognition, so that classification performance remains sufficiently high.</p></list-item>
<list-item>
<p>Preserve diverse features to support broader use, such as other classification tasks (e.g., position estimation) beyond simple activity analysis.</p></list-item>
</list></p>
<p>By satisfying these requirements, even attackers armed with person-identification models built from leaked raw data will be significantly hampered in re-identifying individuals. Meanwhile, data consumers can still utilize the anonymized data for activity recognition and new downstream applications, thus helping to reduce user reluctance to share sensor data in an era of heightened privacy awareness.</p>
</sec>
</sec>
<sec id="s4">
<label>4</label>
<title>Proposed Method</title>
<p>This study proposes a new adversarial-perturbation-based approach to supplement the limitations of existing anonymization methods such as AAE, which often suffer from excessive waveform distortions or focus on only a specific task. For instance, in the context of person images, AP can reduce classification accuracy of a face-recognition model while preserving the visual appearance. However, because these visual changes are quite subtle, a person-recognition model might be deceived, yet humans can still identify the individual by simple inspection, hence it fails to achieve anonymization. In contrast, when data are inherently difficult to identify visually, as with sensor signals, the act of degrading the classification model&#x2019;s accuracy itself effectively serves as anonymization. Thus, in the field of activity recognition, where human observation cannot easily detect identities, AAP leverages this unique property of sensor data. No prior reports have been identified that employ AP to anonymize sensor data, suggesting that the present approach opens a new direction for anonymization research.</p>
<p>This section first introduces AAP, which applies AP in the time domain to reduce person-identification accuracy while minimizing waveform distortion, thereby explaining the fundamental process of the proposed framework. The approach is then extended to F-AAP, which combines time-domain and frequency-domain models to ensure that anonymization remains robust in the frequency domain. Finally, it is further extended to MF-AAP, which simultaneously considers multiple tasks (e.g., device-position estimation) and selectively degrades only person-identification accuracy. Across all proposed methods, the input and output formats follow those of the related study [<xref ref-type="bibr" rid="ref-12">12</xref>]. Specifically, sensor waveforms segmented into fixed-length windows by a sliding-window preprocessing step are supplied as input, and anonymized waveforms of the same length are produced as output. No additional preprocessing is applied. The concrete experimental settings are described in <xref ref-type="sec" rid="s5">Section 5</xref>.</p>
<sec id="s4_1">
<label>4.1</label>
<title>Anonymization with a Simple Adversarial Perturbation (AAP)</title>
<p>An anonymization scheme must balance privacy protection (i.e., lowering person identification accuracy) with data utility (i.e., retaining essential information). Although increasing waveform distortion can enhance anonymization, it risks destroying the inherent features of the data. AP, on the other hand, can significantly disrupt a classifier&#x2019;s inference while introducing only a minimal visible change to the data. Inspired by AP methods developed in the image domain, the technique is adapted to sensor data in order to preserve the original waveforms as much as possible while drastically reducing person-identification accuracy, and this variant is referred to as AAP.</p>
<p><xref ref-type="fig" rid="fig-3">Fig. 3</xref> illustrates the flow of AAP. The method employs IFGSM [<xref ref-type="bibr" rid="ref-49">49</xref>], which iteratively applies the AP by FGSM [<xref ref-type="bibr" rid="ref-52">52</xref>]. In advance, a person-identification model (<inline-formula id="ieqn-22"><mml:math id="mml-ieqn-22"><mml:msub><mml:mi>M</mml:mi><mml:mrow><mml:mi>i</mml:mi><mml:mi>d</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula>) is trained on the raw data (with parameters <inline-formula id="ieqn-23"><mml:math id="mml-ieqn-23"><mml:msub><mml:mi>&#x03B8;</mml:mi><mml:mrow><mml:mtext>id</mml:mtext></mml:mrow></mml:msub></mml:math></inline-formula>). At anonymization time, the loss gradient <inline-formula id="ieqn-24"><mml:math id="mml-ieqn-24"><mml:msub><mml:mi mathvariant="normal">&#x2207;</mml:mi><mml:mrow><mml:mi mathvariant="bold-italic">X</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula> with respect to the input sensor data <inline-formula id="ieqn-25"><mml:math id="mml-ieqn-25"><mml:mi mathvariant="bold-italic">X</mml:mi></mml:math></inline-formula> and the person label <inline-formula id="ieqn-26"><mml:math id="mml-ieqn-26"><mml:msub><mml:mi mathvariant="bold-italic">y</mml:mi><mml:mrow><mml:mrow><mml:mi mathvariant="normal">i</mml:mi><mml:mi mathvariant="normal">d</mml:mi></mml:mrow></mml:mrow></mml:msub></mml:math></inline-formula> is computed and incrementally added <inline-formula id="ieqn-27"><mml:math id="mml-ieqn-27"><mml:mi>t</mml:mi></mml:math></inline-formula> times to produce the anonymized data <inline-formula id="ieqn-28"><mml:math id="mml-ieqn-28"><mml:msub><mml:mi mathvariant="bold-italic">X</mml:mi><mml:mi>t</mml:mi></mml:msub></mml:math></inline-formula>. <xref ref-type="disp-formula" rid="eqn-1">Eq. (1)</xref> shows an example transformation step at iteration <inline-formula id="ieqn-29"><mml:math id="mml-ieqn-29"><mml:mi>t</mml:mi></mml:math></inline-formula>.
<disp-formula id="eqn-1"><label>(1)</label><mml:math id="mml-eqn-1" display="block"><mml:msub><mml:mi mathvariant="bold-italic">X</mml:mi><mml:mrow><mml:mi>t</mml:mi></mml:mrow></mml:msub><mml:mo>=</mml:mo><mml:msub><mml:mi mathvariant="bold-italic">X</mml:mi><mml:mrow><mml:mi>t</mml:mi><mml:mo>&#x2212;</mml:mo><mml:mn>1</mml:mn></mml:mrow></mml:msub><mml:mo>+</mml:mo><mml:mi>&#x03B1;</mml:mi><mml:mspace width="thinmathspace" /><mml:mrow><mml:mtext>sign</mml:mtext></mml:mrow><mml:mstyle scriptlevel="0"><mml:mrow><mml:mo maxsize="1.2em" minsize="1.2em">(</mml:mo></mml:mrow></mml:mstyle><mml:msub><mml:mi mathvariant="normal">&#x2207;</mml:mi><mml:mrow><mml:mi mathvariant="bold-italic">X</mml:mi></mml:mrow></mml:msub><mml:msub><mml:mi>J</mml:mi><mml:mrow><mml:msub><mml:mi>&#x03B8;</mml:mi><mml:mrow><mml:mrow><mml:mtext>id</mml:mtext></mml:mrow></mml:mrow></mml:msub></mml:mrow></mml:msub><mml:mo stretchy="false">(</mml:mo><mml:msub><mml:mi mathvariant="bold-italic">X</mml:mi><mml:mrow><mml:mi>t</mml:mi><mml:mo>&#x2212;</mml:mo><mml:mn>1</mml:mn></mml:mrow></mml:msub><mml:mo>,</mml:mo><mml:msub><mml:mi>y</mml:mi><mml:mrow><mml:mrow><mml:mtext>id</mml:mtext></mml:mrow></mml:mrow></mml:msub><mml:mo stretchy="false">)</mml:mo><mml:mstyle scriptlevel="0"><mml:mrow><mml:mo maxsize="1.2em" minsize="1.2em">)</mml:mo></mml:mrow></mml:mstyle><mml:mo>.</mml:mo></mml:math></disp-formula></p>
<fig id="fig-3">
<label>Figure 3</label>
<caption>
<title>Anonymization process by AAP. AAP takes the sensor waveform <inline-formula id="ieqn-38"><mml:math id="mml-ieqn-38"><mml:mi mathvariant="bold-italic">X</mml:mi></mml:math></inline-formula> and the person label <inline-formula id="ieqn-39"><mml:math id="mml-ieqn-39"><mml:msub><mml:mi mathvariant="bold-italic">y</mml:mi><mml:mrow><mml:mtext>id</mml:mtext></mml:mrow></mml:msub></mml:math></inline-formula> as input, computes the gradient <inline-formula id="ieqn-40"><mml:math id="mml-ieqn-40"><mml:msub><mml:mi mathvariant="normal">&#x2207;</mml:mi><mml:mrow><mml:mi mathvariant="bold-italic">X</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula> with respect to <inline-formula id="ieqn-41"><mml:math id="mml-ieqn-41"><mml:mi mathvariant="bold-italic">X</mml:mi></mml:math></inline-formula> using a pretrained person-identification model <inline-formula id="ieqn-42"><mml:math id="mml-ieqn-42"><mml:msub><mml:mi>M</mml:mi><mml:mrow><mml:mi>i</mml:mi><mml:mi>d</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula>, and adds this gradient to the original waveform as a perturbation</title>
</caption>
<graphic mimetype="image" mime-subtype="tif" xlink:href="CMC_66270-fig-3.tif"/>
</fig>
<p>Here, <inline-formula id="ieqn-30"><mml:math id="mml-ieqn-30"><mml:msub><mml:mi mathvariant="bold-italic">X</mml:mi><mml:mi>t</mml:mi></mml:msub></mml:math></inline-formula> is the anonymized data at the <inline-formula id="ieqn-31"><mml:math id="mml-ieqn-31"><mml:mi>t</mml:mi></mml:math></inline-formula>-th iteration, and <inline-formula id="ieqn-32"><mml:math id="mml-ieqn-32"><mml:msub><mml:mi>J</mml:mi><mml:mrow><mml:msub><mml:mi>&#x03B8;</mml:mi><mml:mrow><mml:mtext>id</mml:mtext></mml:mrow></mml:msub></mml:mrow></mml:msub><mml:mo stretchy="false">(</mml:mo><mml:mo>&#x22C5;</mml:mo><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula> is the loss function of the person-identification model. The final magnitude of waveform change depends on parameters <inline-formula id="ieqn-33"><mml:math id="mml-ieqn-33"><mml:mi>&#x03B1;</mml:mi></mml:math></inline-formula> and the number of iterations <inline-formula id="ieqn-34"><mml:math id="mml-ieqn-34"><mml:mi>t</mml:mi></mml:math></inline-formula>. In this context, <inline-formula id="ieqn-35"><mml:math id="mml-ieqn-35"><mml:mi>&#x03B1;</mml:mi></mml:math></inline-formula> denotes the step size added at each iteration. Unlike prior adversarial-attack studies, this work does not impose an explicit <inline-formula id="ieqn-36"><mml:math id="mml-ieqn-36"><mml:msub><mml:mi>L</mml:mi><mml:mi>p</mml:mi></mml:msub></mml:math></inline-formula> budget. Instead, the step size <inline-formula id="ieqn-37"><mml:math id="mml-ieqn-37"><mml:mi>&#x03B1;</mml:mi></mml:math></inline-formula> is selected via grid search so that the person identification F1 scores drop to chance level. Unlike autoencoder-based methods (e.g., AAE), AAP does not reconstruct the original waveform, only minor perturbations are added. This property allows the scheme to degrade classification accuracy using small noise while offering a means to fine-tune the degree of anonymization at deployment by adjusting these parameters.</p>
<p>While AAE encodes waveforms into latent variables and then reconstructs them, often yielding a significant gap between original and reconstructed data, AAP only adds minimal noise to reduce identification accuracy. Consequently, one may expect that additional information (e.g., frequency characteristics) remains more readily preserved under AAP. Subsequent experimental evaluations (see <xref ref-type="sec" rid="s5">Section 5</xref>) demonstrate that AAP offers broader data utility than AAE.</p>
</sec>
<sec id="s4_2">
<label>4.2</label>
<title>Frequency-Informed Adversarial Perturbation for Anonymization (F-AAP)</title>
<p>AAP focuses on classification models in the time domain. However, if an attacker trains a person-identification model in the frequency domain, standard AAP might fail to anonymize effectively. Since sensor data (e.g., accelerometry or biosignals) often contain unique frequency components tied to individual users, restricting anonymization efforts solely to the time domain can be insufficient.</p>
<p>F-AAP is introduced, which concurrently derives gradients from both time-domain and frequency-domain models to guide perturbations so that person-identification becomes difficult in both domains. As depicted in the left of <xref ref-type="fig" rid="fig-4">Fig. 4</xref>, the sensor data <inline-formula id="ieqn-43"><mml:math id="mml-ieqn-43"><mml:msup><mml:mi mathvariant="bold-italic">X</mml:mi><mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:mtext>T</mml:mtext><mml:mo stretchy="false">)</mml:mo></mml:mrow></mml:msup></mml:math></inline-formula> are transformed into the frequency domain <inline-formula id="ieqn-44"><mml:math id="mml-ieqn-44"><mml:msup><mml:mi mathvariant="bold-italic">X</mml:mi><mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:mtext>F</mml:mtext><mml:mo stretchy="false">)</mml:mo></mml:mrow></mml:msup></mml:math></inline-formula> via STFT, and then combine the time-domain and frequency-domain losses. <xref ref-type="disp-formula" rid="eqn-2">Eq. (2)</xref> shows that the gradients <inline-formula id="ieqn-45"><mml:math id="mml-ieqn-45"><mml:msub><mml:mi mathvariant="normal">&#x2207;</mml:mi><mml:mrow><mml:msup><mml:mi mathvariant="bold-italic">X</mml:mi><mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:mtext>T</mml:mtext><mml:mo stretchy="false">)</mml:mo></mml:mrow></mml:msup></mml:mrow></mml:msub><mml:msub><mml:mi>J</mml:mi><mml:mrow><mml:msub><mml:mi>&#x03B8;</mml:mi><mml:mrow><mml:mtext>(T,id)</mml:mtext></mml:mrow></mml:msub></mml:mrow></mml:msub></mml:math></inline-formula> and <inline-formula id="ieqn-46"><mml:math id="mml-ieqn-46"><mml:msub><mml:mi mathvariant="normal">&#x2207;</mml:mi><mml:mrow><mml:msup><mml:mi mathvariant="bold-italic">X</mml:mi><mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:mtext>F</mml:mtext><mml:mo stretchy="false">)</mml:mo></mml:mrow></mml:msup></mml:mrow></mml:msub><mml:msub><mml:mi>J</mml:mi><mml:mrow><mml:msub><mml:mi>&#x03B8;</mml:mi><mml:mrow><mml:mtext>(F,id)</mml:mtext></mml:mrow></mml:msub></mml:mrow></mml:msub></mml:math></inline-formula> are used, subsequently mapping back via ISTFT and aggregating the signs.
<disp-formula id="eqn-2"><label>(2)</label><mml:math id="mml-eqn-2" display="block"><mml:msub><mml:mi mathvariant="bold-italic">X</mml:mi><mml:mrow><mml:mi>t</mml:mi></mml:mrow></mml:msub><mml:mo>=</mml:mo><mml:msub><mml:mi mathvariant="bold-italic">X</mml:mi><mml:mrow><mml:mi>t</mml:mi><mml:mo>&#x2212;</mml:mo><mml:mn>1</mml:mn></mml:mrow></mml:msub><mml:mo>+</mml:mo><mml:mi>&#x03B1;</mml:mi><mml:munder><mml:mo>&#x2211;</mml:mo><mml:mrow><mml:mi>d</mml:mi><mml:mo>&#x2208;</mml:mo><mml:mo fence="false" stretchy="false">{</mml:mo><mml:mrow><mml:mtext>T</mml:mtext></mml:mrow><mml:mo>,</mml:mo><mml:mrow><mml:mtext>F</mml:mtext></mml:mrow><mml:mo fence="false" stretchy="false">}</mml:mo></mml:mrow></mml:munder><mml:msub><mml:mi>&#x03B4;</mml:mi><mml:mi>d</mml:mi></mml:msub><mml:mo>&#x22C5;</mml:mo><mml:mrow><mml:mtext>sign</mml:mtext></mml:mrow><mml:mstyle scriptlevel="0"><mml:mrow><mml:mo maxsize="1.2em" minsize="1.2em">(</mml:mo></mml:mrow></mml:mstyle><mml:msub><mml:mi mathvariant="normal">&#x2207;</mml:mi><mml:mrow><mml:mi mathvariant="bold-italic">X</mml:mi></mml:mrow></mml:msub><mml:msub><mml:mi>J</mml:mi><mml:mrow><mml:msubsup><mml:mi>&#x03B8;</mml:mi><mml:mrow><mml:mrow><mml:mtext>id</mml:mtext></mml:mrow></mml:mrow><mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:mi>d</mml:mi><mml:mo stretchy="false">)</mml:mo></mml:mrow></mml:msubsup></mml:mrow></mml:msub><mml:mo stretchy="false">(</mml:mo><mml:msubsup><mml:mi mathvariant="bold-italic">X</mml:mi><mml:mrow><mml:mi>t</mml:mi><mml:mo>&#x2212;</mml:mo><mml:mn>1</mml:mn></mml:mrow><mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:mi>d</mml:mi><mml:mo stretchy="false">)</mml:mo></mml:mrow></mml:msubsup><mml:mo>,</mml:mo><mml:msub><mml:mi>y</mml:mi><mml:mrow><mml:mrow><mml:mtext>id</mml:mtext></mml:mrow></mml:mrow></mml:msub><mml:mo stretchy="false">)</mml:mo><mml:mstyle scriptlevel="0"><mml:mrow><mml:mo maxsize="1.2em" minsize="1.2em">)</mml:mo></mml:mrow></mml:mstyle><mml:mo>.</mml:mo></mml:math></disp-formula></p>
<fig id="fig-4">
<label>Figure 4</label>
<caption>
<title>Anonymization processes by F-AAP (left) and MF-AAP (right)</title>
</caption>
<graphic mimetype="image" mime-subtype="tif" xlink:href="CMC_66270-fig-4.tif"/>
</fig>
<p>Here, <inline-formula id="ieqn-47"><mml:math id="mml-ieqn-47"><mml:mi>d</mml:mi><mml:mo>=</mml:mo><mml:mtext>T</mml:mtext></mml:math></inline-formula> denotes the time domain, and <inline-formula id="ieqn-48"><mml:math id="mml-ieqn-48"><mml:mi>d</mml:mi><mml:mo>=</mml:mo><mml:mtext>F</mml:mtext></mml:math></inline-formula> denotes the frequency domain; setting <inline-formula id="ieqn-49"><mml:math id="mml-ieqn-49"><mml:msub><mml:mi>&#x03B4;</mml:mi><mml:mrow><mml:mtext>T</mml:mtext></mml:mrow></mml:msub><mml:mo>=</mml:mo><mml:mn>1</mml:mn><mml:mo>,</mml:mo></mml:math></inline-formula> <inline-formula id="ieqn-50"><mml:math id="mml-ieqn-50"><mml:msub><mml:mi>&#x03B4;</mml:mi><mml:mrow><mml:mtext>F</mml:mtext></mml:mrow></mml:msub><mml:mo>=</mml:mo><mml:mn>1</mml:mn></mml:math></inline-formula> leverages both gradients, whereas setting one of them to 0 reverts to standard AAP or a single-domain approach. By integrating these two domains, F-AAP hinders attacker-driven identification whether in the time or frequency domain, while still preserving essential information in the data.</p>
</sec>
<sec id="s4_3">
<label>4.3</label>
<title>Adversarial Anonymization Considering Multiple Tasks (MF-AAP)</title>
<p>Finally, beyond neutralizing person-identification models in the time and frequency domains, certain use cases may demand preservation of other tasks&#x2019; accuracy (e.g., activity recognition, gender inference, or device-position estimation). For instance, a user may wish to obfuscate personal identity but keep activity recognition or gender prediction operational on the device.</p>
<p>To address such needs, F-AAP is extended to MF-AAP, which simultaneously handles &#x201C;tasks that require accuracy preservation&#x201D; (e.g., activity, gender, or position) and &#x201C;tasks whose accuracy should be reduced&#x201D; (i.e., person identification). As illustrated on the right of <xref ref-type="fig" rid="fig-4">Fig. 4</xref> and formalized in <xref ref-type="disp-formula" rid="eqn-3">Eq. (3)</xref>, each task is assigned a weight <inline-formula id="ieqn-51"><mml:math id="mml-ieqn-51"><mml:msub><mml:mi>&#x03C3;</mml:mi><mml:mrow><mml:mtext>task</mml:mtext></mml:mrow></mml:msub><mml:mo>&#x2208;</mml:mo><mml:mo fence="false" stretchy="false">{</mml:mo><mml:mo>+</mml:mo><mml:mn>1</mml:mn><mml:mo>,</mml:mo><mml:mspace width="thinmathspace" /><mml:mn>0</mml:mn><mml:mo>,</mml:mo><mml:mspace width="thinmathspace" /><mml:mo>&#x2212;</mml:mo><mml:mn>1</mml:mn><mml:mo fence="false" stretchy="false">}</mml:mo></mml:math></inline-formula>, for example, <inline-formula id="ieqn-52"><mml:math id="mml-ieqn-52"><mml:msub><mml:mi>&#x03C3;</mml:mi><mml:mrow><mml:mtext>id</mml:mtext></mml:mrow></mml:msub><mml:mo>=</mml:mo><mml:mo>+</mml:mo><mml:mn>1</mml:mn></mml:math></inline-formula> (intentionally lowering person-identification accuracy) and <inline-formula id="ieqn-53"><mml:math id="mml-ieqn-53"><mml:msub><mml:mi>&#x03C3;</mml:mi><mml:mrow><mml:mtext>act</mml:mtext></mml:mrow></mml:msub><mml:mo>=</mml:mo><mml:mo>&#x2212;</mml:mo><mml:mn>1</mml:mn></mml:math></inline-formula> (preserving or boosting the target task). Gradients are summed after applying these weights to produce a single perturbation that simultaneously degrades person identification while retaining accuracy for other tasks.</p>
<p><disp-formula id="eqn-3"><label>(3)</label><mml:math id="mml-eqn-3" display="block"><mml:mtable columnalign="right left right left right left right left right left right left" rowspacing="3pt" columnspacing="0em 2em 0em 2em 0em 2em 0em 2em 0em 2em 0em" displaystyle="true"><mml:mtr><mml:mtd /><mml:mtd><mml:msub><mml:mi mathvariant="bold-italic">X</mml:mi><mml:mrow><mml:mi>t</mml:mi></mml:mrow></mml:msub><mml:mo>=</mml:mo><mml:msub><mml:mi mathvariant="bold-italic">X</mml:mi><mml:mrow><mml:mi>t</mml:mi><mml:mo>&#x2212;</mml:mo><mml:mn>1</mml:mn></mml:mrow></mml:msub><mml:mo>+</mml:mo><mml:mi>&#x03B1;</mml:mi><mml:munder><mml:mo>&#x2211;</mml:mo><mml:mrow><mml:mi>d</mml:mi><mml:mo>&#x2208;</mml:mo><mml:mo fence="false" stretchy="false">{</mml:mo><mml:mrow><mml:mtext>T</mml:mtext></mml:mrow><mml:mo>,</mml:mo><mml:mrow><mml:mtext>F</mml:mtext></mml:mrow><mml:mo fence="false" stretchy="false">}</mml:mo></mml:mrow></mml:munder><mml:msub><mml:mi>&#x03B4;</mml:mi><mml:mi>d</mml:mi></mml:msub><mml:mo>&#x22C5;</mml:mo><mml:mrow><mml:mtext>sign</mml:mtext></mml:mrow><mml:mstyle scriptlevel="0"><mml:mrow><mml:mo maxsize="2.470em" minsize="2.470em">(</mml:mo></mml:mrow></mml:mstyle><mml:munder><mml:mo>&#x2211;</mml:mo><mml:mrow><mml:mrow><mml:mrow><mml:mtext>task</mml:mtext></mml:mrow></mml:mrow><mml:mo>&#x2208;</mml:mo><mml:mo fence="false" stretchy="false">{</mml:mo><mml:mrow><mml:mtext>id</mml:mtext></mml:mrow><mml:mo>,</mml:mo><mml:mrow><mml:mtext>act</mml:mtext></mml:mrow><mml:mo>,</mml:mo><mml:mo>&#x2026;</mml:mo><mml:mo fence="false" stretchy="false">}</mml:mo></mml:mrow></mml:munder><mml:msub><mml:mi>&#x03C3;</mml:mi><mml:mrow><mml:mrow><mml:mtext>task</mml:mtext></mml:mrow></mml:mrow></mml:msub><mml:mo>&#x22C5;</mml:mo><mml:msub><mml:mi mathvariant="normal">&#x2207;</mml:mi><mml:mrow><mml:mi mathvariant="bold-italic">X</mml:mi></mml:mrow></mml:msub><mml:msub><mml:mi>J</mml:mi><mml:mrow><mml:msubsup><mml:mi>&#x03B8;</mml:mi><mml:mrow><mml:mrow><mml:mtext>task</mml:mtext></mml:mrow></mml:mrow><mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:mi>d</mml:mi><mml:mo stretchy="false">)</mml:mo></mml:mrow></mml:msubsup></mml:mrow></mml:msub><mml:mo stretchy="false">(</mml:mo><mml:msubsup><mml:mi mathvariant="bold-italic">X</mml:mi><mml:mrow><mml:mi>t</mml:mi><mml:mo>&#x2212;</mml:mo><mml:mn>1</mml:mn></mml:mrow><mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:mi>d</mml:mi><mml:mo stretchy="false">)</mml:mo></mml:mrow></mml:msubsup><mml:mo>,</mml:mo><mml:msub><mml:mi>y</mml:mi><mml:mrow><mml:mrow><mml:mtext>task</mml:mtext></mml:mrow></mml:mrow></mml:msub><mml:mo stretchy="false">)</mml:mo><mml:mstyle scriptlevel="0"><mml:mrow><mml:mo maxsize="2.470em" minsize="2.470em">)</mml:mo></mml:mrow></mml:mstyle><mml:mo>.</mml:mo></mml:mtd></mml:mtr></mml:mtable></mml:math></disp-formula></p>
<p>Hence, MF-AAP can preserve the performance of tasks like activity classification while deliberately reducing only person-identification accuracy. Because one can set <inline-formula id="ieqn-54"><mml:math id="mml-ieqn-54"><mml:msub><mml:mi>&#x03C3;</mml:mi><mml:mrow><mml:mi>t</mml:mi><mml:mi>a</mml:mi><mml:mi>s</mml:mi><mml:mi>k</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula> for each task independently, users can flexibly choose which information to protect and which to retain allowing them to tailor the anonymization to different deployment scenarios.</p>
</sec>
</sec>
<sec id="s5">
<label>5</label>
<title>Evaluation Experiment</title>
<p>In this section, the three proposed methods (AAP, F-AAP, and MF-AAP) are experimentally evaluated against the following research questions (RQs) to address the gaps identified in the Introduction. RQ1 tests whether a perturbation (AAP) outperforms the prevailing AAE baseline in the privacy-utility trade-off; RQ2 examines whether adding a frequency-domain surrogate (F-AAP) preserves anonymity when an attacker operates in the spectral domain; and RQ3 validates that a multi-task extension (MF-AAP) can suppress only person-ID accuracy while preserving utility for other tasks such as activity and position recognition. Privacy is quantified by the macro-F1 score of person identification, whereas utility is measured by F1 (classification) or MSE (regression) on the downstream tasks.
<list list-type="bullet">
<list-item>
<p><bold>RQ1:</bold> Does the AP-based anonymization approach (AAP) outperform existing methods (e.g., AAE) in terms of both anonymization effectiveness and information preservation?</p></list-item>
<list-item>
<p><bold>RQ2:</bold> Is F-AAP effective at achieving robust anonymization in the frequency domain?</p></list-item>
<list-item>
<p><bold>RQ3:</bold> Can MF-AAP selectively suppress only person identification accuracy while preserving performance on other tasks?</p></list-item>
</list></p>
<sec id="s5_1">
<label>5.1</label>
<title>Experimental Setup</title>
<sec id="s5_1_1">
<label>5.1.1</label>
<title>Datasets and Pre-Processing</title>
<p>Three publicly available sensor datasets commonly employed in human activity and identity recognition are utilized:
<list list-type="bullet">
<list-item>
<p><bold>Motion Sense</bold> [<xref ref-type="bibr" rid="ref-15">15</xref>]: 24 subjects (gender-balanced), 6 activity classes.</p></list-item>
<list-item>
<p><bold>MHEALTH</bold> [<xref ref-type="bibr" rid="ref-16">16</xref>]: 10 subjects, 12 activity classes, sensors placed at 3 different body positions.</p></list-item>
<list-item>
<p><bold>UniMiB SHAR</bold> [<xref ref-type="bibr" rid="ref-17">17</xref>]: 30 subjects, 17 activity classes (9 daily-life and 8 fall-related activities).</p></list-item>
</list></p>
<p>All datasets contain sensor signals sampled at 50 Hz. Sliding windows (window size &#x003D; 128, stride &#x003D; 128) are applied to segment the data, followed by standardization. To assess anonymization effectiveness in both the time and frequency domains, the segmented data are transformed into spectrograms using STFT. Complex-valued spectrograms are represented by separately considering real and imaginary parts, effectively doubling the number of input channels.</p>
<p>In this paper, data from different domains are denoted by &#x201C;T&#x201D; for the time domain and &#x201C;F&#x201D; for the frequency domain. For example, the notations &#x201C;Raw(T)&#x201D;, &#x201C;Raw(F)&#x201D;, and &#x201C;AAE(F)&#x201D; are employed. Here, Raw(F) refers to data obtained by applying STFT to Raw(T). In contrast, AAE(F) does not denote STFT of AAE(T); rather, it represents data anonymized using an AAE model that has been trained in the frequency domain. The same definition applies to AAP(F).</p>
</sec>
<sec id="s5_1_2">
<label>5.1.2</label>
<title>Evaluation Tasks</title>
<p>Multiple classification tasks are defined to comprehensively evaluate anonymization and information retention capabilities:
<list list-type="bullet">
<list-item>
<p><bold>Person Identification (Person ID):</bold> Identifying subjects from sensor data.</p></list-item>
<list-item>
<p><bold>Activity Recognition (Activity):</bold> Classifying general activity types.</p></list-item>
<list-item>
<p><bold>Sensor Position Estimation (Position):</bold> Determining the sensor&#x2019;s location on the body.</p></list-item>
<list-item>
<p><bold>Gender Recognition (Gender):</bold> Classifying subjects&#x2019; gender.</p></list-item>
<list-item>
<p><bold>Detailed Activity Recognition (Detailed Act):</bold> Classifying finely-grained activity categories.</p></list-item>
</list></p>
<p>The exact tasks and class numbers differ according to dataset characteristics.</p>
</sec>
<sec id="s5_1_3">
<label>5.1.3</label>
<title>Models and Training Procedure</title>
<p>A VGG-based architecture (VGG10) [<xref ref-type="bibr" rid="ref-54">54</xref>] is mainly employed as the primary evaluation model for all classification tasks, due to its established effectiveness and simplicity. To assess model transferability, additional experiments are conducted using a ResNet10 architecture [<xref ref-type="bibr" rid="ref-55">55</xref>], known for its robustness in deep learning literature.</p>
<p>The datasets are divided into training and test subsets (70% train, 30% test), ensuring balanced distributions of subjects and activities. The Adam optimizer with an initial learning rate of 0.001 is used for model optimization, and a cosine annealing scheduler progressively decreases the learning rate. The training runs for 500 epochs with a batch size of 128. Cross-entropy loss is used for training, with class-specific weighting to mitigate class imbalance effects. These hyperparameters were selected based on preliminary experiments.</p>
<p>The classification performance of AAP depends on both the constant <inline-formula id="ieqn-55"><mml:math id="mml-ieqn-55"><mml:mi>&#x03B1;</mml:mi></mml:math></inline-formula> values and the number of perturbation iterations. In these experiments, the F1 score under settings where the person identification accuracy falls to or below the chance level are reported. To select this operating point, a grid search is performed over <inline-formula id="ieqn-56"><mml:math id="mml-ieqn-56"><mml:mi>&#x03B1;</mml:mi><mml:mo>&#x2208;</mml:mo><mml:mo fence="false" stretchy="false">{</mml:mo><mml:mn>0.0125</mml:mn><mml:mo>,</mml:mo><mml:mn>0.025</mml:mn><mml:mo>,</mml:mo><mml:mo>&#x2026;</mml:mo><mml:mo>,</mml:mo><mml:mn>0.25</mml:mn><mml:mo fence="false" stretchy="false">}</mml:mo></mml:math></inline-formula>, then choose the smallest <inline-formula id="ieqn-57"><mml:math id="mml-ieqn-57"><mml:mi>&#x03B1;</mml:mi></mml:math></inline-formula> at which person-identification F1 scores dropped to or below the chance rate (e.g., 12.5% for eight classes), and finally evaluated all downstream tasks (activity, device-position, etc.) using that <inline-formula id="ieqn-58"><mml:math id="mml-ieqn-58"><mml:mi>&#x03B1;</mml:mi></mml:math></inline-formula>, thus maximizing utility while satisfying the privacy constraint. The number of perturbation iterations is fixed at <inline-formula id="ieqn-59"><mml:math id="mml-ieqn-59"><mml:mi>t</mml:mi><mml:mo>=</mml:mo><mml:mn>15</mml:mn></mml:math></inline-formula>. The step size <inline-formula id="ieqn-60"><mml:math id="mml-ieqn-60"><mml:mi>&#x03B1;</mml:mi></mml:math></inline-formula> is tuned in a sensitivity analysis and is held constant across all datasets in both the time and frequency domains.</p>
</sec>
<sec id="s5_1_4">
<label>5.1.4</label>
<title>Evaluation Metrics</title>
<p>Classification performance is evaluated using the mean F1 score averaged over five runs with different random seeds. The F1 score is a balanced metric based on the harmonic mean of precision and recall, well-suited to evaluate performance under class imbalance. To quantify changes introduced by anonymization, MSE between original and anonymized waveforms are calculated. Additionally, domain robustness (time/frequency) is evaluated using specialized metrics such as the id score and act score, detailed further in subsequent sections. These comprehensive evaluations allow us to compare the proposed approaches against the existing method (AAE) in terms of anonymization effectiveness and information preservation.</p>
</sec>
</sec>
<sec id="s5_2">
<label>5.2</label>
<title>RQ1: Evaluation of the Effectiveness of AAP</title>
<sec id="s5_2_1">
<label>5.2.1</label>
<title>Experimental Setup</title>
<p>In this section, the ability of AAP to simultaneously maintain high anonymity and improve information retention compared with the existing method (AAE) is evaluated. Anonymity is quantified by the degradation in person-identification performance, while information retention is measured by (i) the preservation of classification accuracy on other tasks (e.g., activity, gender, and sensor-position recognition) and (ii) the magnitude of waveform change (quantified by the MSE between the original and anonymized signals). These metrics are compared comprehensively to assess the effectiveness of AAP.</p>
<p>The evaluation procedure is as follows:
<list list-type="simple">
<list-item><label>1.</label><p>For each dataset (Motion Sense, MHEALTH, and UniMiB SHAR), generate anonymized data by AAE and AAP.</p></list-item>
<list-item><label>2.</label><p>Measure the classification performance (F1 score) of models built using VGG10 on these datasets (raw, AAE, and AAP).</p></list-item>
<list-item><label>3.</label><p>Quantify the amount of waveform change by computing the MSE between the raw and anonymized data.</p></list-item>
</list></p>
</sec>
<sec id="s5_2_2">
<label>5.2.2</label>
<title>Evaluation via Classification Models</title>
<p><xref ref-type="table" rid="table-2">Table 2</xref> shows the results. All models were trained using data in the time domain. The three leftmost columns denote the target estimation tasks, and the ten rightmost columns present the corresponding estimation results (mean F1 scores). The model architectures used are VGG10 and ResNet10, with VGG10 specifically employed for anonymization. &#x201C;Raw,&#x201D; &#x201C;RP [<xref ref-type="bibr" rid="ref-40">40</xref>],&#x201D; &#x201C;NOS2R2 [<xref ref-type="bibr" rid="ref-36">36</xref>],&#x201D; &#x201C;AAE [<xref ref-type="bibr" rid="ref-12">12</xref>],&#x201D; &#x201C;AAP,&#x201D; &#x201C;F-AAP,&#x201D; and &#x201C;MF-AAP&#x201D; in the test data column indicate the test data and the anonymization methods applied.</p>
<table-wrap id="table-2">
<label>Table 2</label>
<caption>
<title>Comparison of anonymization performance on time-domain data [%]. In this scenario, the attacker has each model trained by time-domain sensor data</title>
</caption>
<table>
<colgroup>
<col align="center"/>
<col align="center"/>
<col align="center"/>
<col align="center"/>
<col align="center"/>
<col align="center"/>
<col align="center"/>
<col align="center"/>
<col align="center"/>
<col align="center"/>
<col align="center"/>
<col align="center"/>
<col align="center"/>
<col align="center"/>
<col align="center"/>
</colgroup>
<thead>
<tr>
<th colspan="3">Model architecture</th>
<th colspan="7">VGG10</th>
<th colspan="5">ResNet10</th>
</tr>
<tr>
<th align="center" colspan="3">Test data</th>
<th align="center">Raw</th>
<th align="center">RP<break/> [<xref ref-type="bibr" rid="ref-40">40</xref>]</th>
<th align="center">NOS2R2<break/> [<xref ref-type="bibr" rid="ref-36">36</xref>]</th>
<th align="center">AAE<break/> [<xref ref-type="bibr" rid="ref-12">12</xref>]</th>
<th align="center">AAP</th>
<th align="center">F-AAP</th>
<th align="center">MF-AAP</th>
<th align="center">Raw</th>
<th align="center">AAE<break/> [<xref ref-type="bibr" rid="ref-12">12</xref>]</th>
<th align="center">AAP</th>
<th align="center">F-AAP</th>
<th align="center">MF-AAP</th>
</tr>
<tr>
<th align="center">Test data</th>
<th align="center">Dataset</th>
<th align="center">Class</th>
<th colspan="7"></th>
<th colspan="5"></th>
</tr>
</thead>
<tbody>
<tr>
<td rowspan="3">Person</td>
<td>Motion sense</td>
<td>24</td>
<td>56.7</td>
<td>0.6</td>
<td>3.3</td>
<td>1.8</td>
<td>2.4</td>
<td>3.7</td>
<td>3.4</td>
<td>58.5</td>
<td>1.6</td>
<td>3.3</td>
<td>4.1</td>
<td>4.0</td>
</tr>
<tr>
<td>mHealth</td>
<td>10</td>
<td>85.1</td>
<td>2.5</td>
<td>7.7</td>
<td>4.3</td>
<td>2.5</td>
<td>2.5</td>
<td>4.8</td>
<td>86.8</td>
<td>5.3</td>
<td>8.8</td>
<td>9.3</td>
<td>9.2</td>
</tr>
<tr>
<td>UniMiB</td>
<td>30</td>
<td>78.5</td>
<td>0.5</td>
<td>2.7</td>
<td>0.5</td>
<td>2.6</td>
<td>2.8</td>
<td>1.7</td>
<td>71.2</td>
<td>0.8</td>
<td>3.1</td>
<td>3.2</td>
<td>2.6</td>
</tr>
<tr>
<td rowspan="3">Activity</td>
<td>Motion Sense</td>
<td>6</td>
<td>80.2</td>
<td>6.8</td>
<td>40.9</td>
<td>40.6</td>
<td>79.0</td>
<td>79.7</td>
<td>99.6</td>
<td>81.8</td>
<td>37.7</td>
<td>63.6</td>
<td>64.7</td>
<td>74.6</td>
</tr>
<tr>
<td>mHealth</td>
<td>12</td>
<td>82.8</td>
<td>1.6</td>
<td>20.0</td>
<td>10.9</td>
<td>71.8</td>
<td>70.0</td>
<td>90.5</td>
<td>80.4</td>
<td>9.7</td>
<td>59.4</td>
<td>61.0</td>
<td>69.2</td>
</tr>
<tr>
<td>UniMiB</td>
<td>2</td>
<td>97.3</td>
<td>28.6</td>
<td>81.5</td>
<td>26.2</td>
<td>96.8</td>
<td>96.7</td>
<td>100.0</td>
<td>97.8</td>
<td>58.5</td>
<td>92.9</td>
<td>92.7</td>
<td>94.5</td>
</tr>
<tr>
<td>Gender</td>
<td>Motion sense</td>
<td>2</td>
<td>63.2</td>
<td>36.8</td>
<td>56.2</td>
<td>49.6</td>
<td>60.8</td>
<td>59.7</td>
<td>97.0</td>
<td>62.5</td>
<td>52.5</td>
<td>59.2</td>
<td>56.6</td>
<td>71.2</td>
</tr>
<tr>
<td>Position</td>
<td>mHealth</td>
<td>3</td>
<td>90.0</td>
<td>19.7</td>
<td>37.3</td>
<td>42.8</td>
<td>86.9</td>
<td>87.1</td>
<td>98.3</td>
<td>89.6</td>
<td>36.1</td>
<td>82.3</td>
<td>84.8</td>
<td>92.1</td>
</tr>
<tr>
<td>Detailed Act.</td>
<td>UniMiB</td>
<td>17</td>
<td>68.7</td>
<td>0.8</td>
<td>22.5</td>
<td>1.8</td>
<td>63.4</td>
<td>61.6</td>
<td>99.5</td>
<td>63.5</td>
<td>1.8</td>
<td>35.8</td>
<td>35.1</td>
<td>44.7</td>
</tr>
</tbody>
</table>
</table-wrap>
<p>Using VGG10, identical to the anonymisation network, person-identification F1 scores drop below chance across all datasets, verifying effective identity removal; raw signals had yielded 50%&#x2013;80% accuracy. Activity-recognition performance, however, reveals clear differences among methods. Traditional statistical transformations, RP [<xref ref-type="bibr" rid="ref-40">40</xref>] and NOS2R2 Gaussian noise [<xref ref-type="bibr" rid="ref-36">36</xref>], and the auto-encoder AAE [<xref ref-type="bibr" rid="ref-12">12</xref>] markedly degrade recognition accuracy. Each of these techniques induces a substantial distributional shift: RP rotates and compresses feature geometry, NOS2R2 injects broadband noise, and AAE generates a new latent space that assumes subsequent retraining on anonymised data. Models fitted to the original distribution therefore fail to extract useful patterns, producing large accuracy losses unless costly retraining is performed.</p>
<p>AAP, by contrast, adds minimal task-aware noise and preserves the structure on which existing classifiers rely. Across datasets, activity-recognition accuracy with AAP remains within 0.5&#x2013;11% of the baseline while identity prediction stays at random level. On the UniMiB dataset, for example, detailed-activity classification falls to 1.8% with AAE but still reaches 63.4% under AAP. These results demonstrate that AAP achieves a favourable privacy&#x2013;utility compromise: identity cues are suppressed, yet behaviourally relevant information is largely retained, and no model retraining is required.</p>
<p>Next, to evaluate robustness against changes in model architecture, the results obtained with ResNet10 are considered. Similar to VGG10, the person-identification accuracy consistently falls below chance level across all datasets. However, it was observed that the perturbation magnitude parameter <inline-formula id="ieqn-61"><mml:math id="mml-ieqn-61"><mml:mi>&#x03B1;</mml:mi></mml:math></inline-formula> required for AAP tends to be higher compared than in the case with VGG10. In terms of activity recognition accuracy, trends similar to those observed with VGG10 were evident, with AAP consistently outperforming AAE. Nonetheless, due to the increased perturbation magnitude, performance with ResNet10 slightly decreased compared to that obtained with VGG10. This trend is similarly observed in other labels. Therefore, the proposed method demonstrates robustness against variations in model architecture, although increased perturbations slightly degrade information retention performance. The proposed perturbations are optimized on a per-dataset basis. Future work will explore domain-adversarial objectives and meta-learning schemes to improve cross-dataset transfer.</p>
</sec>
<sec id="s5_2_3">
<label>5.2.3</label>
<title>Evaluation of Waveform Preservation</title>
<p>In addition to evaluating classification performance, waveform preservation is assessed by comparing the MSE values (<xref ref-type="table" rid="table-3">Table 3</xref>) and visualizing waveform changes (<xref ref-type="fig" rid="fig-5">Fig. 5</xref>), both performed on time-domain data. The MSE values indicate that AAP produces considerably lower fluctuations than AAE across all datasets, which supports the improved classification performance observed earlier. Similarly, the visual results confirm that the variation from the original waveform is minimal. These results demonstrate that the proposed method effectively disrupts person recognition by classifiers while preserving the essential characteristics of the original signal.</p>
<table-wrap id="table-3">
<label>Table 3</label>
<caption>
<title>MSE between the original and anonymized signals for VGG10 model in time-domain data <inline-formula id="ieqn-62"><mml:math id="mml-ieqn-62"><mml:mo stretchy="false">(</mml:mo><mml:mrow><mml:mi mathvariant="normal">m</mml:mi></mml:mrow><mml:mrow><mml:mo>/</mml:mo></mml:mrow><mml:msup><mml:mrow><mml:mi mathvariant="normal">s</mml:mi></mml:mrow><mml:mn>2</mml:mn></mml:msup><mml:msup><mml:mo stretchy="false">)</mml:mo><mml:mn>2</mml:mn></mml:msup></mml:math></inline-formula><break/></title>
</caption>
<table>
<colgroup>
<col/>
<col/>
<col/>
<col/>
<col/>
</colgroup>
<thead>
<tr>
<th></th>
<th>AAE</th>
<th>AAP</th>
<th>F-AAP</th>
<th>MF-AAP</th>
</tr>
</thead>
<tbody>
<tr>
<td>Motion sense</td>
<td>0.7587</td>
<td>0.0443</td>
<td>0.0486</td>
<td>0.0979</td>
</tr>
<tr>
<td>mHealth</td>
<td>0.7761</td>
<td>0.0206</td>
<td>0.0314</td>
<td>0.0511</td>
</tr>
<tr>
<td>UniMiB</td>
<td>0.9106</td>
<td>0.0194</td>
<td>0.0317</td>
<td>0.0544</td>
</tr>
</tbody>
</table>
</table-wrap><fig id="fig-5">
<label>Figure 5</label>
<caption>
<title>Waveform changes before and after anonymization</title>
</caption>
<graphic mimetype="image" mime-subtype="tif" xlink:href="CMC_66270-fig-5.tif"/>
</fig>
<p>In summary, the experimental results indicate that AAP not only effectively degrades person-identification accuracy but also preserves waveform characteristics, allowing models trained on raw data to be used directly without retraining. This leads to a more versatile anonymization approach compared to AAE.</p>
</sec>
</sec>
<sec id="s5_3">
<label>5.3</label>
<title>RQ2: Effectiveness in Frequency Domain</title>
<p>Next, anonymization performance in the frequency domain is discussed. To the best of current knowledge, existing anonymization studies for activity recognition have not considered scenarios in which an attacker converts sensor waveforms into the frequency domain to conduct person-identification attacks. Thus, the present study investigates person-identification accuracy and activity-recognition accuracy when time-series sensor waveforms are transformed into the frequency domain using STFT.</p>
<p>The experimental results are presented in <xref ref-type="table" rid="table-4">Table 4</xref>. Experimental conditions are identical to those described in the previous section, except that the attacker&#x2019;s model targets frequency-domain data, requiring preprocessing to convert time-series sensor waveforms into the frequency domain before inputting them into the model. Examining the person-identification accuracy, it is observed that performance for all methods remains around the chance level. However, because AAP considers only the time domain, achieving anonymization below the chance level requires significantly increasing the perturbation magnitude parameter <inline-formula id="ieqn-63"><mml:math id="mml-ieqn-63"><mml:mi>&#x03B1;</mml:mi></mml:math></inline-formula>. Consequently, although the performance of AAP remains superior to AAE, accuracy in activity recognition and other estimation tasks decreases compared to the results shown in <xref ref-type="table" rid="table-2">Table 2</xref>. In contrast, F-AAP, which explicitly accounts for the frequency domain, maintains strong anonymization performance even with smaller <inline-formula id="ieqn-64"><mml:math id="mml-ieqn-64"><mml:mi>&#x03B1;</mml:mi></mml:math></inline-formula> values, thus effectively preserving accuracy in activity recognition and other tasks. Nevertheless, it was also found that the effectiveness of F-AAP diminishes when the model architecture changes, such as in the case of ResNet10.</p>
<table-wrap id="table-4">
<label>Table 4</label>
<caption>
<title>Comparison of anonymization performance on frequency-domain data [%]. In this scenario, the attacker has each model trained by frequency-domain sensor data</title>
</caption>
<table>
<colgroup>
<col align="center"/>
<col align="center"/>
<col align="center"/>
<col align="center"/>
<col align="center"/>
<col align="center"/>
<col align="center"/>
<col align="center"/>
<col align="center"/>
<col align="center"/>
<col align="center"/>
<col align="center"/>
<col align="center"/>
</colgroup>
<thead>
<tr>
<th colspan="3">Model architecture</th>
<th colspan="5">VGG 10</th>
<th colspan="5">ResNet 10</th>
</tr>
<tr>
<th colspan="3">Test data</th>
<th align="center">Raw</th>
<th align="center">AAE</th>
<th align="center">AAP</th>
<th align="center">F-AAP</th>
<th align="center">MF-AAP</th>
<th align="center">Raw</th>
<th align="center">AAE</th>
<th align="center">AAP</th>
<th align="center">F-AAP</th>
<th align="center">MF-AAP</th>
</tr>
<tr>
<th align="center">Target</th>
<th align="center">Dataset</th>
<th align="center">Class</th>
<th colspan="5"></th>
<th colspan="5"></th>
</tr>
</thead>
<tbody>
<tr>
<td></td>
<td>Motion sense</td>
<td>24</td>
<td>54.9</td>
<td>0.3</td>
<td>4.1</td>
<td>3.4</td>
<td>3.9</td>
<td>55.8</td>
<td>0.7</td>
<td>3.9</td>
<td>3.9</td>
<td>3.9</td>
</tr>
<tr>
<td>Person</td>
<td>mHealth</td>
<td>10</td>
<td>83.6</td>
<td>5.4</td>
<td>9.2</td>
<td>4.8</td>
<td>6.2</td>
<td>79.6</td>
<td>4.5</td>
<td>9.7</td>
<td>9.7</td>
<td>0.0</td>
</tr>
<tr>
<td></td>
<td>UniMiB</td>
<td>30</td>
<td>70.8</td>
<td>0.2</td>
<td>3.2</td>
<td>1.6</td>
<td>2.9</td>
<td>67.9</td>
<td>0.2</td>
<td>3.2</td>
<td>3.1</td>
<td>3.3</td>
</tr>
<tr>
<td></td>
<td>Motion sense</td>
<td>6</td>
<td>85.8</td>
<td>4.7</td>
<td>23.2</td>
<td>83.9</td>
<td>93.2</td>
<td>84.3</td>
<td>7.4</td>
<td>31.7</td>
<td>41.8</td>
<td>48.7</td>
</tr>
<tr>
<td>Activity</td>
<td>mHealth</td>
<td>12</td>
<td>74.9</td>
<td>6.6</td>
<td>38.4</td>
<td>67.9</td>
<td>96.4</td>
<td>79.3</td>
<td>5.5</td>
<td>47.8</td>
<td>49.6</td>
<td>56.7</td>
</tr>
<tr>
<td></td>
<td>UniMiB</td>
<td>2</td>
<td>99.2</td>
<td>37.1</td>
<td>91.9</td>
<td>98.8</td>
<td>99.9</td>
<td>99.3</td>
<td>28.6</td>
<td>91.2</td>
<td>93.4</td>
<td>95.6</td>
</tr>
<tr>
<td>Gender</td>
<td>Motion sense</td>
<td>2</td>
<td>63.2</td>
<td>41.8</td>
<td>54.3</td>
<td>58.4</td>
<td>96.5</td>
<td>60.4</td>
<td>35.0</td>
<td>55.8</td>
<td>55.2</td>
<td>74.5</td>
</tr>
<tr>
<td>Position</td>
<td>mHealth</td>
<td>3</td>
<td>89.0</td>
<td>22.0</td>
<td>77.0</td>
<td>88.6</td>
<td>99.1</td>
<td>89.9</td>
<td>21.4</td>
<td>80.0</td>
<td>80.4</td>
<td>85.2</td>
</tr>
<tr>
<td>Detailed Act.</td>
<td>UniMiB</td>
<td>17</td>
<td>63.5</td>
<td>1.2</td>
<td>14.3</td>
<td>51.0</td>
<td>97.6</td>
<td>62.4</td>
<td>0.7</td>
<td>12.3</td>
<td>26.3</td>
<td>35.5</td>
</tr>
</tbody>
</table>
</table-wrap>
<p>These observations indicate that F-AAP effectively maintains anonymization performance against person-identification attacks in the frequency domain while mitigating adverse impacts on the accuracy of activity recognition and other tasks. However, robustness to differences in model architecture remains a challenge that should be addressed in future work.</p>
</sec>
<sec id="s5_4">
<label>5.4</label>
<title>RQ3: Selectively Suppress Person Identification Accuracy</title>
<p>The previously evaluated methods, AAP and F-AAP, require only the person labels during anonymization. Although these methods are easy to implement, their capability for information retention is limited. In contrast, the proposed method, MF-AAP, requires additional labels (e.g., activity, gender, etc.) in anonymization. However, this requirement enables selective control over information retention or suppression. Thus, this experiment investigates the effects of introducing perturbations designed to suppress person-identification performance while simultaneously enhancing the recognition performance of other attributes.</p>
<p>The results of this investigation are presented under the MF-AAP columns in <xref ref-type="table" rid="table-2">Tables 2</xref> and <xref ref-type="table" rid="table-4">4</xref>. Regardless of the model architecture or the target domain, the performance of person identification could be consistently suppressed below the chance level through adjustments of the parameter <inline-formula id="ieqn-65"><mml:math id="mml-ieqn-65"><mml:mi>&#x03B1;</mml:mi></mml:math></inline-formula>. Furthermore, examination of activity recognition and other estimation accuracies shows performance improvements across all conditions. Notably, this improvement is particularly prominent for VGG10, which is the anonymization model itself, where most attributes achieved recognition accuracies exceeding 90%. Therefore, the results clearly demonstrate that MF-AAP can intentionally control both the enhancement and suppression of classification performance.</p>

<p>This phenomenon can be interpreted as embedding label information into the original data. AAP and F-AAP achieve anonymization by estimating person labels from input data and adding perturbations in the opposite direction of the gradient calculated with respect to those inputs. Although activity recognition and other labels are not explicitly utilized in the anonymization process, information retention is pursued by minimizing the perturbation magnitude. Conversely, MF-AAP employs multiple labels during anonymization and introduces perturbations using both forward and inverse gradients. Adding forward gradients to the input introduces slight perturbations that improve classification performance, effectively embedding label-specific features into the original data.</p>
</sec>
</sec>
<sec id="s6">
<label>6</label>
<title>Discussion</title>
<sec id="s6_1">
<label>6.1</label>
<title>Effects of <inline-formula id="ieqn-66"><mml:math id="mml-ieqn-66"><mml:mi mathvariant="bold-italic">&#x03B1;</mml:mi></mml:math></inline-formula></title>
<p>As a key feature of AAP, the intensity of the perturbation (<inline-formula id="ieqn-67"><mml:math id="mml-ieqn-67"><mml:mi>&#x03B1;</mml:mi></mml:math></inline-formula>) can be adjusted to control the degree of anonymization (Int. adj.). In the experiments thus far, <inline-formula id="ieqn-68"><mml:math id="mml-ieqn-68"><mml:mi>&#x03B1;</mml:mi></mml:math></inline-formula> is tuned so that person identification performance is forced to fall below the chance level. This section investigates how increasing or decreasing <inline-formula id="ieqn-69"><mml:math id="mml-ieqn-69"><mml:mi>&#x03B1;</mml:mi></mml:math></inline-formula> affects overall performance. The following score is introduced as a new metric:
<disp-formula id="eqn-4"><label>(4)</label><mml:math id="mml-eqn-4" display="block"><mml:mi>S</mml:mi><mml:mo>=</mml:mo><mml:mfrac><mml:mrow><mml:msub><mml:mi>s</mml:mi><mml:mrow><mml:mrow><mml:mtext>aap</mml:mtext></mml:mrow></mml:mrow></mml:msub><mml:mo>&#x2212;</mml:mo><mml:mi>c</mml:mi></mml:mrow><mml:mrow><mml:msub><mml:mi>s</mml:mi><mml:mrow><mml:mrow><mml:mtext>raw</mml:mtext></mml:mrow></mml:mrow></mml:msub><mml:mo>&#x2212;</mml:mo><mml:mi>c</mml:mi></mml:mrow></mml:mfrac></mml:math></disp-formula></p>
<p>Here, <italic>S</italic> is calculated for each estimation target (Person, Activity, and others) based on its chance rate <inline-formula id="ieqn-70"><mml:math id="mml-ieqn-70"><mml:mi>c</mml:mi></mml:math></inline-formula>, representing the relative ratio to the score <inline-formula id="ieqn-71"><mml:math id="mml-ieqn-71"><mml:msub><mml:mi>s</mml:mi><mml:mrow><mml:mi>r</mml:mi><mml:mi>a</mml:mi><mml:mi>w</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula> achieved using raw data as the upper bound. Because a higher value is more desirable, <inline-formula id="ieqn-72"><mml:math id="mml-ieqn-72"><mml:msubsup><mml:mi>S</mml:mi><mml:mrow><mml:mrow><mml:mi mathvariant="normal">p</mml:mi><mml:mi mathvariant="normal">e</mml:mi><mml:mi mathvariant="normal">r</mml:mi><mml:mi mathvariant="normal">s</mml:mi><mml:mi mathvariant="normal">o</mml:mi><mml:mi mathvariant="normal">n</mml:mi></mml:mrow></mml:mrow><mml:mo>&#x2032;</mml:mo></mml:msubsup><mml:mo>=</mml:mo><mml:mn>1.0</mml:mn><mml:mo>&#x2212;</mml:mo><mml:msub><mml:mi>S</mml:mi><mml:mrow><mml:mrow><mml:mi mathvariant="normal">p</mml:mi><mml:mi mathvariant="normal">e</mml:mi><mml:mi mathvariant="normal">r</mml:mi><mml:mi mathvariant="normal">s</mml:mi><mml:mi mathvariant="normal">o</mml:mi><mml:mi mathvariant="normal">n</mml:mi></mml:mrow></mml:mrow></mml:msub></mml:math></inline-formula> is defined only for the person-identification task. Finally, each score is clamped between 0.0 and 1.0.</p>
<p><xref ref-type="fig" rid="fig-6">Fig. 6</xref> presents how the scores of each method change with different <inline-formula id="ieqn-73"><mml:math id="mml-ieqn-73"><mml:mi>&#x03B1;</mml:mi></mml:math></inline-formula> values. For comparison, AAE is also plotted; however, because AAE does not allow adjusting the anonymization level after training, its value remains constant. Since the model architecture used here is ResNet10, these results illustrate the case where the evaluation model (ResNet10) differs from the model architecture employed in the anonymization (VGG10). From the figure, it is evident that, while AAE serves as a baseline with strong anonymization performance, it substantially degrades the estimation accuracy for Activity and Other, indicating significant information loss. In contrast, the proposed methods show that by setting <inline-formula id="ieqn-74"><mml:math id="mml-ieqn-74"><mml:mi>&#x03B1;</mml:mi></mml:math></inline-formula> in the range of approximately 0.2&#x2013;0.7, one can achieve comparable anonymization performance to AAE while still preserving performance on the other tasks.</p>
<fig id="fig-6">
<label>Figure 6</label>
<caption>
<title>Comparison of target estimation score using ResNet10 in time-domain data across the mHealth, Motion Sense, and UniMiB datasets. Colors denote the different targets, and line styles indicate the applied methods (AAE, AAP, F-AAP, and MF-AAP)</title>
</caption>
<graphic mimetype="image" mime-subtype="tif" xlink:href="CMC_66270-fig-6.tif"/>
</fig>
<p>When comparing the characteristics among the methods, AAP, F-AAP, and MF-AAP respond to changes in <inline-formula id="ieqn-75"><mml:math id="mml-ieqn-75"><mml:mi>&#x03B1;</mml:mi></mml:math></inline-formula> in descending order of sensitivity. For instance, in the Motion Sense dataset, person identification accuracy saturates around <inline-formula id="ieqn-76"><mml:math id="mml-ieqn-76"><mml:mi>&#x03B1;</mml:mi><mml:mo>=</mml:mo><mml:mn>0.07</mml:mn></mml:math></inline-formula> for AAP, <inline-formula id="ieqn-77"><mml:math id="mml-ieqn-77"><mml:mi>&#x03B1;</mml:mi><mml:mo>=</mml:mo><mml:mn>0.13</mml:mn></mml:math></inline-formula> for F-AAP, and <inline-formula id="ieqn-78"><mml:math id="mml-ieqn-78"><mml:mi>&#x03B1;</mml:mi><mml:mo>=</mml:mo><mml:mn>0.16</mml:mn></mml:math></inline-formula> for MF-AAP. In each case, the anonymization performance is comparable to that of AAE, and in many instances, even when <inline-formula id="ieqn-79"><mml:math id="mml-ieqn-79"><mml:mi>&#x03B1;</mml:mi></mml:math></inline-formula> is further increased, these methods still retain more information than AAE.</p>
</sec>
<sec id="s6_2">
<label>6.2</label>
<title>Task-Interdependencies Analysis</title>
<p>Based on the preceding results, interdependencies among the subtasks are examined. First, the F1 scores obtained with Raw and AAP inputs in <xref ref-type="table" rid="table-4">Table 4</xref> are compared. Relevant rows are extracted and reorganized in <xref ref-type="table" rid="table-5">Table 5</xref>, which lists the absolute drop <inline-formula id="ieqn-80"><mml:math id="mml-ieqn-80"><mml:mi mathvariant="normal">&#x0394;</mml:mi><mml:msub><mml:mi>F</mml:mi><mml:mrow><mml:mn>1</mml:mn></mml:mrow></mml:msub></mml:math></inline-formula> and the relative reduction <inline-formula id="ieqn-81"><mml:math id="mml-ieqn-81"><mml:mrow><mml:mrow><mml:mtext>RR</mml:mtext></mml:mrow></mml:mrow><mml:mo>=</mml:mo><mml:mi mathvariant="normal">&#x0394;</mml:mi><mml:msub><mml:mi>F</mml:mi><mml:mrow><mml:mn>1</mml:mn></mml:mrow></mml:msub><mml:mrow><mml:mo>/</mml:mo></mml:mrow><mml:msub><mml:mi>F</mml:mi><mml:mrow><mml:mn>1</mml:mn><mml:mo>,</mml:mo><mml:mrow><mml:mi mathvariant="normal">R</mml:mi><mml:mi mathvariant="normal">a</mml:mi><mml:mi mathvariant="normal">w</mml:mi></mml:mrow></mml:mrow></mml:msub></mml:math></inline-formula>. In the Motion Sense dataset, Activity suffers a substantial decrease of 62.6%, whereas Gender declines by only 8.9%. A similar pattern appears for Activity versus Position in mHealth. Conversely, on UniMiB the degradation in coarse activity recognition is minor (<inline-formula id="ieqn-82"><mml:math id="mml-ieqn-82"><mml:mo>&#x2212;</mml:mo><mml:mn>7.3</mml:mn></mml:math></inline-formula>%), while fine&#x2013;grained actions (Detailed Act.) deteriorate by 49.2%.</p>
<table-wrap id="table-5">
<label>Table 5</label>
<caption>
<title>Comparison of performance degradation on frequency-domain data (values in %). Based on <xref ref-type="table" rid="table-4">Table 4</xref>. <inline-formula id="ieqn-83"><mml:math id="mml-ieqn-83"><mml:mi mathvariant="normal">&#x0394;</mml:mi><mml:msub><mml:mi>F</mml:mi><mml:mn>1</mml:mn></mml:msub></mml:math></inline-formula> is the F1 score drop from Raw to AAP; RR is the relative reduction, <inline-formula id="ieqn-84"><mml:math id="mml-ieqn-84"><mml:mi mathvariant="normal">&#x0394;</mml:mi><mml:msub><mml:mi>F</mml:mi><mml:mn>1</mml:mn></mml:msub><mml:mrow><mml:mo>/</mml:mo></mml:mrow><mml:msub><mml:mi>F</mml:mi><mml:mrow><mml:mn>1</mml:mn><mml:mo>,</mml:mo><mml:mi>R</mml:mi><mml:mi>a</mml:mi><mml:mi>w</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula> (%). MI denotes the mutual information (bit) between the predicted class labels obtained on the Raw data</title>
</caption>
<table>
<colgroup>
<col/>
<col/>
<col/>
<col/>
<col/>
<col/>
<col/>
<col/>
<col/>
<col/>
<col/>
</colgroup>
<thead>
<tr>
<th></th>
<th></th>
<th colspan="4">Activity</th>
<th colspan="4">Another</th>
<th>MI</th>
</tr>
<tr>
<th></th>
<th></th>
<th>Raw</th>
<th>AAP</th>
<th><inline-formula id="ieqn-85"><mml:math id="mml-ieqn-85"><mml:mi mathvariant="bold">&#x0394;</mml:mi><mml:msub><mml:mi mathvariant="bold-italic">F</mml:mi><mml:mrow><mml:mn mathvariant="bold">1</mml:mn></mml:mrow></mml:msub></mml:math></inline-formula></th>
<th>RR</th>
<th>Raw</th>
<th>AAP</th>
<th><inline-formula id="ieqn-86"><mml:math id="mml-ieqn-86"><mml:mi mathvariant="bold">&#x0394;</mml:mi><mml:msub><mml:mi mathvariant="bold-italic">F</mml:mi><mml:mrow><mml:mn mathvariant="bold">1</mml:mn></mml:mrow></mml:msub></mml:math></inline-formula></th>
<th>RR</th>
<th>[bit]</th>
</tr>
</thead>
<tbody>
<tr>
<td>Motion sense</td>
<td>Activity vs. Gender</td>
<td>85.8</td>
<td>23.2</td>
<td>&#x2212;62.6</td>
<td>&#x2212;73.0</td>
<td>63.2</td>
<td>54.3</td>
<td>&#x2212;8.9</td>
<td>&#x2212;14.1</td>
<td>0.010</td>
</tr>
<tr>
<td>mHealth</td>
<td>Activity vs. Position</td>
<td>74.9</td>
<td>38.4</td>
<td>&#x2212;36.5</td>
<td>&#x2212;48.7</td>
<td>89.0</td>
<td>77.0</td>
<td>&#x2212;12.0</td>
<td>&#x2212;13.5</td>
<td>0.044</td>
</tr>
<tr>
<td>UniMiB</td>
<td>Activity vs. Detailed Act.</td>
<td>99.2</td>
<td>91.9</td>
<td>&#x2212;7.3</td>
<td>&#x2212;7.4</td>
<td>63.5</td>
<td>14.3</td>
<td>&#x2212;49.2</td>
<td>&#x2212;77.5</td>
<td>0.543</td>
</tr>
</tbody>
</table>
</table-wrap>
<p>Next, the findings are interpreted through mutual information (MI). The MI column in <xref ref-type="table" rid="table-5">Table 5</xref> reports the bit-wise MI between the predicted labels of each task on the unperturbed (Raw) data. The MI for the Activity&#x2013;Gender and Activity&#x2013;Position pairs is very low (0.01&#x2013;0.044 bit), indicating near-independence. In contrast, the Activity&#x2013;Detailed Act. pair exhibits a high MI of 0.543 bit, revealing strong information overlap. These quantitative results align with intuition: coarse activity labels share little information with gender or sensor placement, whereas fine-grained action classes inherently overlap with the broader activity categories.</p>

</sec>
<sec id="s6_3">
<label>6.3</label>
<title>Computational Efficiency</title>
<p>First, we examine the architectural differences among the anonymization methods.
<list list-type="bullet">
<list-item>
<p><bold>AAE</bold> consists of an encoder-decoder pair, two identity-recognition subnetworks (one attached to the encoder, one to the decoder), and one activity recognition subnetwork.</p></list-item>
<list-item>
<p>The <bold>plain AAP</bold> variant contains only one identity-recognition network.</p></list-item>
<list-item>
<p><bold>F-AAP</bold> employs two identity-recognition networks, one for the time-domain input and one for the frequency-domain input.</p></list-item>
<list-item>
<p><bold>MF-AAP</bold> holds twice as many subnetworks as the number of downstream tasks.</p></list-item>
</list></p>
<p>Next, we consider the computational steps required at inference time (i.e., during anonymization).
<list list-type="bullet">
<list-item>
<p>For <bold>AAE</bold>, a single forward pass through the encoder and then the decoder is sufficient.</p></list-item>
<list-item>
<p><bold>AAP</bold> must execute a forward pass and a backward pass through its identity model for every iteration of the perturbation update.</p></list-item>
<list-item>
<p><bold>F-AAP</bold> adds forward-backward passes in both the time and frequency domains plus the cost of STFT and inverse STFT.</p></list-item>
<list-item>
<p>In <bold>MF-AAP</bold>, the number of model inferences scales with the number of tasks.</p></list-item>
</list></p>
<p>These observations are summarized in <xref ref-type="table" rid="table-6">Table 6</xref>. Assuming that a backward pass costs roughly twice as many FLOPs as a forward pass, the theoretical requirements become AAE: <inline-formula id="ieqn-87"><mml:math id="mml-ieqn-87"><mml:mn>81.5</mml:mn></mml:math></inline-formula> MFLOPs, AAP: <inline-formula id="ieqn-88"><mml:math id="mml-ieqn-88"><mml:mn>99.5</mml:mn><mml:mtext>&#x00A0;</mml:mtext><mml:mi>t</mml:mi></mml:math></inline-formula> MFLOPs, where <inline-formula id="ieqn-89"><mml:math id="mml-ieqn-89"><mml:mi>t</mml:mi></mml:math></inline-formula> denotes the number of iterations. The Latency [s] row in <xref ref-type="table" rid="table-6">Table 6</xref> reports the actual anonymization time measured on the mHealth test set. All experiments were run on a machine equipped with an Intel Core i9&#x2013;13900KF, 32 GB RAM, and an NVIDIA RTX 4090 GPU.</p>
<table-wrap id="table-6">
<label>Table 6</label>
<caption>
<title>Comparison of computational costs for each anonymization method</title>
</caption>
<table>
<colgroup>
<col/>
<col/>
<col/>
<col/>
<col/>
</colgroup>
<thead>
<tr>
<th>Metric</th>
<th>AAE</th>
<th>AAP</th>
<th>F-AAP</th>
<th>MF-AAP</th>
</tr>
</thead>
<tbody>
<tr>
<td># iterations</td>
<td>1</td>
<td><inline-formula id="ieqn-90"><mml:math id="mml-ieqn-90"><mml:mi>t</mml:mi><mml:mo>=</mml:mo><mml:mn>15</mml:mn></mml:math></inline-formula></td>
<td><inline-formula id="ieqn-91"><mml:math id="mml-ieqn-91"><mml:mi>t</mml:mi><mml:mo>=</mml:mo><mml:mn>15</mml:mn></mml:math></inline-formula></td>
<td><inline-formula id="ieqn-92"><mml:math id="mml-ieqn-92"><mml:mi>t</mml:mi><mml:mo>=</mml:mo><mml:mn>15</mml:mn></mml:math></inline-formula></td>
</tr>
<tr>
<td>MFLOPs</td>
<td>81.5</td>
<td><inline-formula id="ieqn-93"><mml:math id="mml-ieqn-93"><mml:mn>99.5</mml:mn><mml:mtext>&#xA0;</mml:mtext><mml:mrow><mml:mi>t</mml:mi></mml:mrow></mml:math></inline-formula></td>
<td>&#x2013;</td>
<td>&#x2013;</td>
</tr>
<tr>
<td>Latency [s]</td>
<td>0.09</td>
<td>0.38</td>
<td>15.97</td>
<td>16.78</td>
</tr>
</tbody>
</table>
</table-wrap>
<p>From the table we observe that, although AAP takes about four times longer than AAE, the gap is far smaller than the FLOP counts alone would suggest. Conversely, the running time of F-AAP and MF-AAP is dominated by the additional STFT/ISTFT transforms, leading to a substantial increase in total computation time.</p>
</sec>
<sec id="s6_4">
<label>6.4</label>
<title>Limitations</title>
<sec id="s6_4_1">
<label>6.4.1</label>
<title>Scenario in Which the Anonymization Method and Raw Data Are Leaked</title>
<p>In the previous section, the privacy risk under scenario (b), in which a personal identification model and scenario (a) application-server login credentials were compromised, was evaluated, and it was demonstrated that the proposed anonymization approach could adequately preserve useful information while protecting privacy (<xref ref-type="sec" rid="s3_2">Section 3.2</xref>). This section further examines scenario (c), in which raw sensor data and personal IDs are also leaked. When only scenario (c) is compromised, the attacker can implement a personal identification model trained on raw data, resulting in a risk level similar to scenario (b). However, if the anonymization method is independently leaked from another source, the attacker may be able to reconstruct the anonymized sensor data.</p>
<p>To quantify this risk, performance in a setting where the attacker has access to a portion of labeled anonymized sensor data is compared. <xref ref-type="table" rid="table-7">Table 7</xref> presents the results, indicating that if a model trained on anonymized data is also exposed, none of the proposed methods can effectively maintain anonymization. Moreover, person identification becomes even easier than with the raw data alone, primarily because the proposed anonymization leverages adversarial training [<xref ref-type="bibr" rid="ref-52">52</xref>]. While AAE also allows for some degree of person identification under these circumstances, it does so to a lesser extent than the methods. Therefore, these findings suggest that developing anonymization techniques robust against leaks of anonymized waveforms remains an important open challenge.</p>
<table-wrap id="table-7">
<label>Table 7</label>
<caption>
<title>Comparison of anonymization performance on time-domain sensor data when the anonymized dataset were leaked</title>
</caption>
<table>
<colgroup>
<col/>
<col/>
<col/>
<col/>
<col/>
<col/>
<col/>
<col/>
<col/>
</colgroup>
<thead>
<tr>
<th colspan="3">Model architecture</th>
<th colspan="3">VGG10</th>
<th colspan="3">ResNet10</th>
</tr>
<tr>
<th colspan="3">Train &#x0026; test data</th>
<th>AAE</th>
<th>AAP</th>
<th>MF-AAP</th>
<th>AAE</th>
<th>AAP</th>
<th>MF-AAP</th>
</tr>
<tr>
<th>Target</th>
<th>Dataset</th>
<th>Class</th>
<th colspan="3"></th>
<th colspan="3"></th>
</tr>
</thead>
<tbody>
<tr>
<td></td>
<td>Motion sense</td>
<td>24</td>
<td>48.6</td>
<td>81.7</td>
<td>84.2</td>
<td>47.6</td>
<td>81.1</td>
<td>82.8</td>
</tr>
<tr>
<td>Person</td>
<td>mHealth</td>
<td>10</td>
<td>57.8</td>
<td>93.6</td>
<td>93.9</td>
<td>60.7</td>
<td>88.0</td>
<td>89.2</td>
</tr>
<tr>
<td></td>
<td>UniMiB</td>
<td>30</td>
<td>50.6</td>
<td>88.5</td>
<td>74.7</td>
<td>47.1</td>
<td>83.2</td>
<td>69.6</td>
</tr>
<tr>
<td></td>
<td>Motion sense</td>
<td>6</td>
<td>96.8</td>
<td>81.3</td>
<td>95.1</td>
<td>96.7</td>
<td>81.7</td>
<td>94.2</td>
</tr>
<tr>
<td>Activity</td>
<td>mHealth</td>
<td>12</td>
<td>81.2</td>
<td>70.8</td>
<td>100.0</td>
<td>80.8</td>
<td>80.2</td>
<td>100.0</td>
</tr>
<tr>
<td></td>
<td>UniMiB</td>
<td>2</td>
<td>96.3</td>
<td>96.6</td>
<td>98.9</td>
<td>96.5</td>
<td>96.1</td>
<td>97.8</td>
</tr>
<tr>
<td>Gender</td>
<td>Motion sense</td>
<td>2</td>
<td>66.0</td>
<td>65.7</td>
<td>82.3</td>
<td>67.3</td>
<td>64.2</td>
<td>82.9</td>
</tr>
<tr>
<td>Position</td>
<td>mHealth</td>
<td>3</td>
<td>87.3</td>
<td>89.0</td>
<td>100.0</td>
<td>86.6</td>
<td>88.4</td>
<td>100.0</td>
</tr>
<tr>
<td>Detailed Act.</td>
<td>UniMiB</td>
<td>17</td>
<td>52.0</td>
<td>57.4</td>
<td>79.7</td>
<td>51.1</td>
<td>50.4</td>
<td>63.4</td>
</tr>
</tbody>
</table>
</table-wrap>
</sec>
<sec id="s6_4_2">
<label>6.4.2</label>
<title>Other Attacks</title>
<p>Since the proposed method conceals information by adding the inverse gradient of the person-identification loss to sensor data, it is primarily tailored to obscuring features associated with a known label (e.g., person identity). Consequently, it may be vulnerable to side-channel attacks that can infer sensitive information without explicitly identifying the individual. For example, in keystroke inference [<xref ref-type="bibr" rid="ref-56">56</xref>], an attacker might extract touchscreen inputs from motion-sensor data. The proposed approach would require explicit label information for these keystrokes (i.e., keys pressed) to compute the inverse gradient for anonymization, which becomes prohibitively expensive to implement in practice. Moreover, if a method infers user location from motion-sensor data without using GPS information [<xref ref-type="bibr" rid="ref-57">57</xref>], effective label assignment could be infeasible. In such cases, the proposed approach cannot be applied, underscoring a broader limitation when label annotation is either incomplete or difficult to obtain.</p>
</sec>
</sec>
</sec>
<sec id="s7">
<label>7</label>
<title>Conclusion</title>
<p>This study presented a novel sensor-data anonymization framework leveraging AP for privacy protection in wearable sensing applications. Unlike autoencoder-based methods such as the AAE, the proposed approach adds minimal, targeted noise to raw waveforms, thereby suppressing person-identification accuracy while retaining greater task-relevant information. Frequency-informed (F-AAP) and multi-task (MF-AAP) extensions are further introduced to address threats from frequency-domain analysis and to selectively preserve specific classification tasks (e.g., activity recognition and gender estimation). Extensive evaluations on three public datasets demonstrated that the proposed methods can degrade identification performance to near-chance levels even against unseen model architectures, while substantially preserving or enhancing performance on other tasks. Moreover, experimental results indicate that critical waveform characteristics remain relatively intact, facilitating the reuse of established downstream models trained on raw data. These findings suggest that AP-based anonymization offers a compelling and flexible alternative to conventional approaches, meeting the increasing need for effective privacy protection without sacrificing diverse analytical utility.</p>
</sec>
</body>
<back>
<ack>
<p>The authors are grateful to all the editors and anonymous reviewers for their comments and suggestions. This manuscript&#x2019;s English translation and proofreading were assisted by ChatGPT, a large language model developed by OpenAI. All responsibility for the content of this paper rests solely with the authors.</p>
</ack>
<sec>
<title>Funding Statement</title>
<p>This work was supported in part by the Japan Society for the Promotion of Science (JSPS) KAKENHI Grant-in-Aid for Scientific Research (C) under Grants 23K11164.</p>
</sec>
<sec>
<title>Author Contributions</title>
<p>The authors confirm contribution to the paper as follows: Conceptualization, Tatsuhito Hasegawa; methodology, Kyosuke Fujino; software, Kyosuke Fujino; validation, Tatsuhito Hasegawa and Kyosuke Fujino; formal analysis, Tatsuhito Hasegawa and Kyosuke Fujino; investigation, Kyosuke Fujino; resources, Tatsuhito Hasegawa; data curation, Kyosuke Fujino; writing&#x2014;original draft preparation, Kyosuke Fujino; writing&#x2014;review and editing, Tatsuhito Hasegawa; visualization, Tatsuhito Hasegawa and Kyosuke Fujino; supervision, Tatsuhito Hasegawa; project administration, Tatsuhito Hasegawa; funding acquisition, Tatsuhito Hasegawa. All authors reviewed the results and approved the final version of the manuscript.</p>
</sec>
<sec sec-type="data-availability">
<title>Availability of Data and Materials</title>
<p>The data that support the findings of this study are openly available in following repositories: Motion Sense Dataset [<xref ref-type="bibr" rid="ref-15">15</xref>]: <ext-link ext-link-type="uri" xlink:href="https://github.com/mmalekzadeh/motion-sense">https://github.com/mmalekzadeh/motion-sense</ext-link> (accessed on 28 May 2025). mHealth [<xref ref-type="bibr" rid="ref-16">16</xref>]: <ext-link ext-link-type="uri" xlink:href="https://archive.ics.uci.edu/dataset/319/mhealth+dataset">https://archive.ics.uci.edu/dataset/319/mhealth&#x002B;dataset</ext-link> (accessed on 28 May 2025). UniMiB SHAR Dataset [<xref ref-type="bibr" rid="ref-17">17</xref>]: <ext-link ext-link-type="uri" xlink:href="http://www.sal.disco.unimib.it/technologies/unimib-shar/">http://www.sal.disco.unimib.it/technologies/unimib-shar/</ext-link> (accessed on 28 May 2025).</p>
</sec>
<sec>
<title>Ethics Approval</title>
<p>This study did not require ethics approval as it only used publicly available anonymized datasets, and no new data were collected from human subjects.</p>
</sec>
<sec sec-type="COI-statement">
<title>Conflicts of Interest</title>
<p>The authors declare no conflicts of interest to report regarding the present study.</p>
</sec>
<glossary content-type="abbreviations" id="glossary-1">
<title>Abbreviations</title>
<def-list>
<def-item>
<term>AAE</term>
<def>
<p>Anonymizing autoencoder</p>
</def>
</def-item>
<def-item>
<term>AP</term>
<def>
<p>Adversarial perturbations</p>
</def>
</def-item>
<def-item>
<term>AAP</term>
<def>
<p>Anonimizing adversarial perturbations</p>
</def>
</def-item>
<def-item>
<term>F-AAP</term>
<def>
<p>Frequency-informed AAP</p>
</def>
</def-item>
<def-item>
<term>MF-AAP</term>
<def>
<p>Multi-task frequency-informed AAP</p>
</def>
</def-item>
<def-item>
<term>HAR</term>
<def>
<p>Human activity recognition</p>
</def>
</def-item>
<def-item>
<term>RP</term>
<def>
<p>Random projection</p>
</def>
</def-item>
<def-item>
<term>GAN</term>
<def>
<p>Generative adversarial networks</p>
</def>
</def-item>
<def-item>
<term>PGAN</term>
<def>
<p>Private GAN</p>
</def>
</def-item>
<def-item>
<term>MSE</term>
<def>
<p>Mean squared error</p>
</def>
</def-item>
<def-item>
<term>RQ</term>
<def>
<p>Research question</p>
</def>
</def-item>
<def-item>
<term>STFT</term>
<def>
<p>Short-time Fourier transform</p>
</def>
</def-item>
</def-list>
</glossary>
<ref-list content-type="authoryear">
<title>References</title>
<ref id="ref-1"><label>[1]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Mamdiwar</surname> <given-names>SD</given-names></string-name>, <string-name><surname>R.</surname> <given-names>A</given-names></string-name>, <string-name><surname>Shakruwala</surname> <given-names>Z</given-names></string-name>, <string-name><surname>Chadha</surname> <given-names>U</given-names></string-name>, <string-name><surname>Srinivasan</surname> <given-names>K</given-names></string-name>, <string-name><surname>Chang</surname> <given-names>CY</given-names></string-name></person-group>. <article-title>Recent advances on IoT-assisted wearable sensor systems for healthcare monitoring</article-title>. <source>Biosensors</source>. <year>2021</year>;<volume>11</volume>(<issue>10</issue>):<fpage>372</fpage>. doi:<pub-id pub-id-type="doi">10.3390/bios11100372</pub-id>; <pub-id pub-id-type="pmid">34677328</pub-id></mixed-citation></ref>
<ref id="ref-2"><label>[2]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Li</surname> <given-names>C</given-names></string-name>, <string-name><surname>Bian</surname> <given-names>Y</given-names></string-name>, <string-name><surname>Zhao</surname> <given-names>Z</given-names></string-name>, <string-name><surname>Liu</surname> <given-names>Y</given-names></string-name>, <string-name><surname>Guo</surname> <given-names>Y</given-names></string-name></person-group>. <article-title>Advances in biointegrated wearable and implantable optoelectronic devices for cardiac healthcare</article-title>. <source>Cyb Bionic Syst</source>. <year>2024</year>;<volume>5</volume>(<issue>33</issue>):<fpage>0172</fpage>. doi:<pub-id pub-id-type="doi">10.34133/cbsystems.0172</pub-id>; <pub-id pub-id-type="pmid">39431246</pub-id></mixed-citation></ref>
<ref id="ref-3"><label>[3]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Xing</surname> <given-names>Y</given-names></string-name>, <string-name><surname>Yang</surname> <given-names>K</given-names></string-name>, <string-name><surname>Lu</surname> <given-names>A</given-names></string-name>, <string-name><surname>Mackie</surname> <given-names>K</given-names></string-name>, <string-name><surname>Guo</surname> <given-names>F</given-names></string-name></person-group>. <article-title>Sensors and devices guided by artificial intelligence for personalized pain medicine</article-title>. <source>Cyb Bionic Syst</source>. <year>2024</year>;<volume>5</volume>:<fpage>0160</fpage>. doi:<pub-id pub-id-type="doi">10.34133/cbsystems.0160</pub-id>; <pub-id pub-id-type="pmid">39282019</pub-id></mixed-citation></ref>
<ref id="ref-4"><label>[4]</label><mixed-citation publication-type="book"><person-group person-group-type="author"><string-name><surname>Lam Po Tang</surname> <given-names>S</given-names></string-name></person-group>. <chapter-title>8&#x2014;Wearable sensors for sports performance</chapter-title>. In: <person-group person-group-type="editor"><string-name><surname>Shishoo</surname> <given-names>R</given-names></string-name></person-group>, editor. <source>Textiles for sportswear. Woodhead publishing series in textiles</source>. <publisher-loc>Sawston, UK</publisher-loc>: <publisher-name>Woodhead Publishing</publisher-name>; <year>2015</year>. p. <fpage>169</fpage>&#x2013;<lpage>96</lpage>. doi:<pub-id pub-id-type="doi">10.1016/B978-1-78242-229-7.00008-4</pub-id>.</mixed-citation></ref>
<ref id="ref-5"><label>[5]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Mencarini</surname> <given-names>E</given-names></string-name>, <string-name><surname>Rapp</surname> <given-names>A</given-names></string-name>, <string-name><surname>Tirabeni</surname> <given-names>L</given-names></string-name>, <string-name><surname>Zancanaro</surname> <given-names>M</given-names></string-name></person-group>. <article-title>Designing wearable systems for sports: a review of trends and opportunities in human-computer interaction</article-title>. <source>IEEE Trans Hum Mach Syst</source>. <year>2019</year>;<volume>49</volume>(<issue>4</issue>):<fpage>314</fpage>&#x2013;<lpage>25</lpage>. doi:<pub-id pub-id-type="doi">10.1109/thms.2019.2919702</pub-id>.</mixed-citation></ref>
<ref id="ref-6"><label>[6]</label><mixed-citation publication-type="book"><person-group person-group-type="author"><string-name><surname>Motti</surname> <given-names>VG</given-names></string-name>, <string-name><surname>Caine</surname> <given-names>K</given-names></string-name></person-group>. <chapter-title>Users&#x2019; privacy concerns about wearables: impact of form factor, sensors and type of data collected</chapter-title>. In: <source>Financial Cryptography and Data Security: FC 2015</source>. <edition>1st</edition> ed. <publisher-loc>Berlin/Heidelberg, Germany</publisher-loc>: <publisher-name>Springer</publisher-name>; <year>2015</year>. p. <fpage>231</fpage>&#x2013;<lpage>44</lpage> doi:<pub-id pub-id-type="doi">10.1007/978-3-662-48051-9_17</pub-id>.</mixed-citation></ref>
<ref id="ref-7"><label>[7]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Xu</surname> <given-names>Z</given-names></string-name>, <string-name><surname>He</surname> <given-names>D</given-names></string-name>, <string-name><surname>Vijayakumar</surname> <given-names>P</given-names></string-name>, <string-name><surname>Gupta</surname> <given-names>BB</given-names></string-name>, <string-name><surname>Shen</surname> <given-names>J</given-names></string-name></person-group>. <article-title>Certificateless public auditing scheme with data privacy and dynamics in group user model of cloud-assisted medical WSNs</article-title>. <source>IEEE J Biomed Health Inform</source>. <year>2023</year>;<volume>27</volume>(<issue>5</issue>):<fpage>2334</fpage>&#x2013;<lpage>44</lpage>. doi:<pub-id pub-id-type="doi">10.1109/jbhi.2021.3128775</pub-id>; <pub-id pub-id-type="pmid">34788225</pub-id></mixed-citation></ref>
<ref id="ref-8"><label>[8]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Huhn</surname> <given-names>S</given-names></string-name>, <string-name><surname>Axt</surname> <given-names>M</given-names></string-name>, <string-name><surname>Gunga</surname> <given-names>HC</given-names></string-name>, <string-name><surname>Maggioni</surname> <given-names>MA</given-names></string-name>, <string-name><surname>Munga</surname> <given-names>S</given-names></string-name>, <string-name><surname>Obor</surname> <given-names>D</given-names></string-name>, <etal>et al</etal></person-group>. <article-title>The impact of wearable technologies in health research: scoping review</article-title>. <source>JMIR Mhealth Uhealth</source>. <year>2022</year>;<volume>10</volume>(<issue>1</issue>):<fpage>e34384</fpage>; <pub-id pub-id-type="pmid">35076409</pub-id></mixed-citation></ref>
<ref id="ref-9"><label>[9]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><surname>Sarker</surname> <given-names>H</given-names></string-name>, <string-name><surname>Sharmin</surname> <given-names>M</given-names></string-name>, <string-name><surname>Ali</surname> <given-names>AA</given-names></string-name>, <string-name><surname>Rahman</surname> <given-names>MM</given-names></string-name>, <string-name><surname>Bari</surname> <given-names>R</given-names></string-name>, <string-name><surname>Hossain</surname> <given-names>SM</given-names></string-name>, <etal>et al</etal></person-group>. <article-title>Assessing the availability of users to engage in just-in-time intervention in the natural environment</article-title>. In: <conf-name>Proceedings of the 2014 ACM International Joint Conference on Pervasive and Ubiquitous Computing</conf-name>; <year>2014 Sep 13&#x2013;17</year>; <publisher-loc>Seattle, DC, USA</publisher-loc>. p. <fpage>909</fpage>&#x2013;<lpage>20</lpage>.</mixed-citation></ref>
<ref id="ref-10"><label>[10]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><surname>Fujimoto</surname> <given-names>R</given-names></string-name>, <string-name><surname>Nakamura</surname> <given-names>Y</given-names></string-name>, <string-name><surname>Arakawa</surname> <given-names>Y</given-names></string-name></person-group>. <article-title>Differential privacy with weighted for privacy-preservation in human activity recognition</article-title>. In: <conf-name>2023 IEEE International Conference on Pervasive Computing and Communications Workshops and other Affiliated Events, PerCom Workshops 2023</conf-name>; <publisher-loc>Atlanta, GA, USA</publisher-loc>. <year>2023</year>. p. <fpage>634</fpage>&#x2013;<lpage>9</lpage>.</mixed-citation></ref>
<ref id="ref-11"><label>[11]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Menasria</surname> <given-names>S</given-names></string-name>, <string-name><surname>Lu</surname> <given-names>M</given-names></string-name>, <string-name><surname>Dahou</surname> <given-names>A</given-names></string-name></person-group>. <article-title>PGAN framework for synthesizing sensor data privately</article-title>. <source>J Inf Secur Appl</source>. <year>2022</year>;<volume>67</volume>(<issue>2</issue>):<fpage>103204</fpage>. doi:<pub-id pub-id-type="doi">10.1016/j.jisa.2022.103204</pub-id>.</mixed-citation></ref>
<ref id="ref-12"><label>[12]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><surname>Malekzadeh</surname> <given-names>M</given-names></string-name>, <string-name><surname>Clegg</surname> <given-names>RG</given-names></string-name>, <string-name><surname>Cavallaro</surname> <given-names>A</given-names></string-name>, <string-name><surname>Haddadi</surname> <given-names>H</given-names></string-name></person-group>. <article-title>Mobile sensor data anonymization</article-title>. In: <conf-name>Proceedings of the International Conference on Internet of Things Design and Implementation</conf-name>. <comment>IoTDI &#x2019;19. ACM; Montreal, QC, Canada; 2019 Apr 15&#x2013;18;</comment> p. <fpage>49</fpage>&#x2013; <lpage>58</lpage>. doi:<pub-id pub-id-type="doi">10.1145/3302505.3310068</pub-id>.</mixed-citation></ref>
<ref id="ref-13"><label>[13]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Bigelli</surname> <given-names>L</given-names></string-name>, <string-name><surname>Contoli</surname> <given-names>C</given-names></string-name>, <string-name><surname>Freschi</surname> <given-names>V</given-names></string-name>, <string-name><surname>Lattanzi</surname> <given-names>E</given-names></string-name></person-group>. <article-title>Privacy preservation in sensor-based human activity recognition through autoencoders for low-power IoT devices</article-title>. <source>Internet of Things</source>. <year>2024</year>;<volume>26</volume>(<issue>6</issue>):<fpage>101189</fpage>. doi:<pub-id pub-id-type="doi">10.1016/j.iot.2024.101189</pub-id>.</mixed-citation></ref>
<ref id="ref-14"><label>[14]</label><mixed-citation publication-type="other"><person-group person-group-type="author"><string-name><surname>Szegedy</surname> <given-names>C</given-names></string-name>, <string-name><surname>Zaremba</surname> <given-names>W</given-names></string-name>, <string-name><surname>Sutskever</surname> <given-names>I</given-names></string-name>, <string-name><surname>Bruna</surname> <given-names>J</given-names></string-name>, <string-name><surname>Erhan</surname> <given-names>D</given-names></string-name>, <string-name><surname>Goodfellow</surname> <given-names>I</given-names></string-name>, <etal>et al</etal></person-group>. <article-title>Intriguing properties of neural networks</article-title>. <comment>arXiv:1312.6199. 2013</comment>.</mixed-citation></ref>
<ref id="ref-15"><label>[15]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><surname>Malekzadeh</surname> <given-names>M</given-names></string-name>, <string-name><surname>Clegg</surname> <given-names>RG</given-names></string-name>, <string-name><surname>Cavallaro</surname> <given-names>A</given-names></string-name>, <string-name><surname>Haddadi</surname> <given-names>H</given-names></string-name></person-group>. <article-title>Protecting sensory data against sensitive inferences</article-title>. In: <conf-name>Proceedings of the 1st Workshop on Privacy by Design in Distributed Systems</conf-name>; <year>2018 Apr 23&#x2013;26</year>; <publisher-loc>Porto, Portugal</publisher-loc>. p. <fpage>1</fpage>&#x2013;<lpage>6</lpage>. doi:<pub-id pub-id-type="doi">10.1145/3195258.3195260</pub-id>.</mixed-citation></ref>
<ref id="ref-16"><label>[16]</label><mixed-citation publication-type="book"><person-group person-group-type="author"><string-name><surname>Banos</surname> <given-names>O</given-names></string-name>, <string-name><surname>Garcia</surname> <given-names>R</given-names></string-name>, <string-name><surname>Holgado-Terriza</surname> <given-names>JA</given-names></string-name>, <string-name><surname>Damas</surname> <given-names>M</given-names></string-name>, <string-name><surname>Pomares</surname> <given-names>H</given-names></string-name>, <string-name><surname>Rojas</surname> <given-names>I</given-names></string-name>, <etal>et al</etal></person-group>. <chapter-title>mHealthDroid: a novel framework for agile development of mobile health applications</chapter-title>. In: <person-group person-group-type="editor"><string-name><surname>Pecchia</surname> <given-names>L</given-names></string-name>, <string-name><surname>Chen</surname> <given-names>LL</given-names></string-name>, <string-name><surname>Nugent</surname> <given-names>C</given-names></string-name>, <string-name><surname>Bravo</surname> <given-names>J</given-names></string-name></person-group>, editors. <source>Ambient assisted living and daily activities</source>. <publisher-loc>Cham, Switzerland</publisher-loc>: <publisher-name>Springer International Publishing</publisher-name>; <year>2014</year>. p. <fpage>91</fpage>&#x2013;<lpage>8</lpage>. doi:<pub-id pub-id-type="doi">10.1007/978-3-319-13105-4_14</pub-id>.</mixed-citation></ref>
<ref id="ref-17"><label>[17]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Micucci</surname> <given-names>D</given-names></string-name>, <string-name><surname>Mobilio</surname> <given-names>M</given-names></string-name>, <string-name><surname>Napoletano</surname> <given-names>P</given-names></string-name></person-group>. <article-title>UniMiB SHAR: a dataset for human activity recognition using acceleration data from smartphones</article-title>. <source>Appl Sci</source>. <year>2017</year>;<volume>7</volume>(<issue>10</issue>):<fpage>1101</fpage>. doi:<pub-id pub-id-type="doi">10.3390/app7101101</pub-id>.</mixed-citation></ref>
<ref id="ref-18"><label>[18]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Xu</surname> <given-names>X</given-names></string-name>, <string-name><surname>Han</surname> <given-names>M</given-names></string-name>, <string-name><surname>Nagarajan</surname> <given-names>SM</given-names></string-name>, <string-name><surname>Anandhan</surname> <given-names>P</given-names></string-name></person-group>. <article-title>Industrial Internet of Things for smart manufacturing applications using hierarchical trustful resource assignment</article-title>. <source>Comput Commun</source>. <year>2020</year>;<volume>160</volume>(<issue>2</issue>):<fpage>423</fpage>&#x2013;<lpage>30</lpage>. doi:<pub-id pub-id-type="doi">10.1016/j.comcom.2020.06.004</pub-id>.</mixed-citation></ref>
<ref id="ref-19"><label>[19]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Talebkhah</surname> <given-names>M</given-names></string-name>, <string-name><surname>Sali</surname> <given-names>A</given-names></string-name>, <string-name><surname>Marjani</surname> <given-names>M</given-names></string-name>, <string-name><surname>Gordan</surname> <given-names>M</given-names></string-name>, <string-name><surname>Hashim</surname> <given-names>SJ</given-names></string-name>, <string-name><surname>Rokhani</surname> <given-names>FZ</given-names></string-name></person-group>. <article-title>IoT and big data applications in smart cities: recent advances, challenges, and critical issues</article-title>. <source>IEEE Access</source>. <year>2021</year>;<volume>9</volume>:<fpage>55465</fpage>&#x2013;<lpage>84</lpage>. doi:<pub-id pub-id-type="doi">10.1109/access.2021.3070905</pub-id>.</mixed-citation></ref>
<ref id="ref-20"><label>[20]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Lee</surname> <given-names>MW</given-names></string-name>, <string-name><surname>Khan</surname> <given-names>AM</given-names></string-name>, <string-name><surname>Kim</surname> <given-names>TS</given-names></string-name></person-group>. <article-title>A single tri-axial accelerometer-based real-time personal life log system capable of human activity recognition and exercise information generation</article-title>. <source>Personal Ubiquitous Comput</source>. <year>2011</year>;<volume>15</volume>(<issue>8</issue>):<fpage>887</fpage>&#x2013;<lpage>98</lpage>. doi:<pub-id pub-id-type="doi">10.1007/s00779-011-0403-3</pub-id>.</mixed-citation></ref>
<ref id="ref-21"><label>[21]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Xu</surname> <given-names>H</given-names></string-name>, <string-name><surname>Pan</surname> <given-names>Y</given-names></string-name>, <string-name><surname>Li</surname> <given-names>J</given-names></string-name>, <string-name><surname>Nie</surname> <given-names>L</given-names></string-name>, <string-name><surname>Xu</surname> <given-names>X</given-names></string-name></person-group>. <article-title>Activity recognition method for home-based elderly care service based on random forest and activity similarity</article-title>. <source>IEEE Access</source>. <year>2019</year>;<volume>7</volume>:<fpage>16217</fpage>&#x2013;<lpage>25</lpage>. doi:<pub-id pub-id-type="doi">10.1109/access.2019.2894184</pub-id>.</mixed-citation></ref>
<ref id="ref-22"><label>[22]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Inoue</surname> <given-names>S</given-names></string-name>, <string-name><surname>Ueda</surname> <given-names>N</given-names></string-name>, <string-name><surname>Nohara</surname> <given-names>Y</given-names></string-name>, <string-name><surname>Nakashima</surname> <given-names>N</given-names></string-name></person-group>. <article-title>Recognizing and understanding nursing activities for a whole day with a big dataset</article-title>. <source>J Inf Process</source>. <year>2016</year>;<volume>24</volume>(<issue>6</issue>):<fpage>853</fpage>&#x2013;<lpage>66</lpage>. doi:<pub-id pub-id-type="doi">10.2197/ipsjjip.24.853</pub-id>.</mixed-citation></ref>
<ref id="ref-23"><label>[23]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Kwapisz</surname> <given-names>JR</given-names></string-name>, <string-name><surname>Weiss</surname> <given-names>GM</given-names></string-name>, <string-name><surname>Moore</surname> <given-names>S</given-names></string-name></person-group>. <article-title>Activity recognition using cell phone accelerometers</article-title>. <source>SIGKDD Explor</source>. <year>2011</year>;<volume>12</volume>(<issue>2</issue>):<fpage>74</fpage>&#x2013;<lpage>82</lpage>. doi:<pub-id pub-id-type="doi">10.1145/1964897.1964918</pub-id>.</mixed-citation></ref>
<ref id="ref-24"><label>[24]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Shoaib</surname> <given-names>M</given-names></string-name>, <string-name><surname>Bosch</surname> <given-names>S</given-names></string-name>, <string-name><surname>Incel</surname> <given-names>&#x00D6;D</given-names></string-name>, <string-name><surname>Scholten</surname> <given-names>H</given-names></string-name>, <string-name><surname>Havinga</surname> <given-names>PJM</given-names></string-name></person-group>. <article-title>Complex human activity recognition using smartphone and wrist-worn motion sensors</article-title>. <source>Sensors</source>. <year>2016</year>;<volume>16</volume>(<issue>4</issue>):<fpage>426</fpage>. doi:<pub-id pub-id-type="doi">10.3390/s16040426</pub-id>; <pub-id pub-id-type="pmid">27023543</pub-id></mixed-citation></ref>
<ref id="ref-25"><label>[25]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Voicu</surname> <given-names>RA</given-names></string-name>, <string-name><surname>Dobre</surname> <given-names>C</given-names></string-name>, <string-name><surname>Bajenaru</surname> <given-names>L</given-names></string-name>, <string-name><surname>Ciobanu</surname> <given-names>RI</given-names></string-name></person-group>. <article-title>Human physical activity recognition using smartphone sensors</article-title>. <source>Sensors</source>. <year>2019</year>;<volume>19</volume>(<issue>3</issue>):<fpage>458</fpage>. doi:<pub-id pub-id-type="doi">10.3390/s19030458</pub-id>; <pub-id pub-id-type="pmid">30678039</pub-id></mixed-citation></ref>
<ref id="ref-26"><label>[26]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Han</surname> <given-names>F</given-names></string-name>, <string-name><surname>Yang</surname> <given-names>P</given-names></string-name>, <string-name><surname>Du</surname> <given-names>H</given-names></string-name>, <string-name><surname>Li</surname> <given-names>XY</given-names></string-name></person-group>. <article-title><italic>Accuth</italic><sup><italic>&#x002B;</italic></sup><italic>&#x002B;</italic>: accelerometer-based anti-spoofing voice authentication on wrist-worn wearables</article-title>. <source>IEEE Trans Mob Comput</source>. <year>2024</year>;<volume>23</volume>(<issue>5</issue>):<fpage>5571</fpage>&#x2013;<lpage>88</lpage>. doi:<pub-id pub-id-type="doi">10.1109/tmc.2023.3314837</pub-id>.</mixed-citation></ref>
<ref id="ref-27"><label>[27]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Li</surname> <given-names>F</given-names></string-name>, <string-name><surname>Shirahama</surname> <given-names>K</given-names></string-name>, <string-name><surname>Nisar</surname> <given-names>MA</given-names></string-name>, <string-name><surname>K&#x00F6;ping</surname> <given-names>L</given-names></string-name>, <string-name><surname>Grzegorzek</surname> <given-names>M</given-names></string-name></person-group>. <article-title>Comparison of feature learning methods for human activity recognition using wearable sensors</article-title>. <source>Sensors</source>. <year>2018</year>;<volume>18</volume>(<issue>2</issue>):<fpage>679</fpage>. doi:<pub-id pub-id-type="doi">10.3390/s18020679</pub-id>; <pub-id pub-id-type="pmid">29495310</pub-id></mixed-citation></ref>
<ref id="ref-28"><label>[28]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><surname>Mehmood</surname> <given-names>K</given-names></string-name>, <string-name><surname>Imran</surname> <given-names>HA</given-names></string-name>, <string-name><surname>Latif</surname> <given-names>U</given-names></string-name></person-group>. <article-title>HARDenseNet: A 1D densenet inspired convolutional neural network for human activity recognition with inertial sensors</article-title>. In: <conf-name>2020 IEEE 23rd International Multitopic Conference (INMIC)</conf-name>; <year>2020 Nov 5&#x2013;7</year>; <publisher-loc>Bahawalpur, Pakistan</publisher-loc>. p. <fpage>1</fpage>&#x2013;<lpage>6</lpage>.</mixed-citation></ref>
<ref id="ref-29"><label>[29]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Ronald</surname> <given-names>M</given-names></string-name>, <string-name><surname>Poulose</surname> <given-names>A</given-names></string-name>, <string-name><surname>Han</surname> <given-names>DS</given-names></string-name></person-group>. <article-title>iSPLInception: an inception-resnet deep learning architecture for human activity recognition</article-title>. <source>IEEE Access</source>. <year>2021</year>;<volume>9</volume>:<fpage>68985</fpage>&#x2013;<lpage>9001</lpage>. doi:<pub-id pub-id-type="doi">10.1109/access.2021.3078184</pub-id>.</mixed-citation></ref>
<ref id="ref-30"><label>[30]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Al-qaness</surname> <given-names>MAA</given-names></string-name>, <string-name><surname>Dahou</surname> <given-names>A</given-names></string-name>, <string-name><surname>Abd Elaziz</surname> <given-names>M</given-names></string-name>, <string-name><surname>Helmi</surname> <given-names>AM</given-names></string-name></person-group>. <article-title>Human activity recognition and fall detection using convolutional neural network and transformer-based architecture</article-title>. <source>Biomed Signal Process Control</source>. <year>2024</year>;<volume>95</volume>(<issue>3</issue>):<fpage>106412</fpage>. doi:<pub-id pub-id-type="doi">10.1016/j.bspc.2024.106412</pub-id>.</mixed-citation></ref>
<ref id="ref-31"><label>[31]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Hussain</surname> <given-names>A</given-names></string-name>, <string-name><surname>Khan</surname> <given-names>SU</given-names></string-name>, <string-name><surname>Khan</surname> <given-names>N</given-names></string-name>, <string-name><surname>Bhatt</surname> <given-names>MW</given-names></string-name>, <string-name><surname>Farouk</surname> <given-names>A</given-names></string-name>, <string-name><surname>Bhola</surname> <given-names>J</given-names></string-name>, <etal>et al</etal></person-group>. <article-title>A hybrid transformer framework for efficient activity recognition using consumer electronics</article-title>. <source>IEEE Trans Consum Electron</source>. <year>2024</year>;<volume>70</volume>(<issue>4</issue>):<fpage>6800</fpage>&#x2013;<lpage>7</lpage>. doi:<pub-id pub-id-type="doi">10.1109/tce.2024.3373824</pub-id>.</mixed-citation></ref>
<ref id="ref-32"><label>[32]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Pareek</surname> <given-names>G</given-names></string-name>, <string-name><surname>Nigam</surname> <given-names>S</given-names></string-name>, <string-name><surname>Singh</surname> <given-names>R</given-names></string-name></person-group>. <article-title>Modeling transformer architecture with attention layer for human activity recognition</article-title>. <source>Neural Comput Appl</source>. <year>2024</year>;<volume>36</volume>(<issue>10</issue>):<fpage>5515</fpage>&#x2013;<lpage>28</lpage>. doi:<pub-id pub-id-type="doi">10.1007/s00521-023-09362-7</pub-id>.</mixed-citation></ref>
<ref id="ref-33"><label>[33]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Neves</surname> <given-names>F</given-names></string-name>, <string-name><surname>Souza</surname> <given-names>R</given-names></string-name>, <string-name><surname>Sousa</surname> <given-names>J</given-names></string-name>, <string-name><surname>Bonfim</surname> <given-names>M</given-names></string-name>, <string-name><surname>Garcia</surname> <given-names>V</given-names></string-name></person-group>. <article-title>Data privacy in the Internet of Things based on anonymization: a review</article-title>. <source>J Comput Secur</source>. <year>2023</year>;<volume>31</volume>(<issue>3</issue>):<fpage>261</fpage>&#x2013;<lpage>91</lpage>. doi:<pub-id pub-id-type="doi">10.3233/JCS-210089</pub-id>.</mixed-citation></ref>
<ref id="ref-34"><label>[34]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Yang</surname> <given-names>Y</given-names></string-name>, <string-name><surname>Hu</surname> <given-names>P</given-names></string-name>, <string-name><surname>Shen</surname> <given-names>J</given-names></string-name>, <string-name><surname>Cheng</surname> <given-names>H</given-names></string-name>, <string-name><surname>An</surname> <given-names>Z</given-names></string-name>, <string-name><surname>Liu</surname> <given-names>X</given-names></string-name></person-group>. <article-title>Privacy-preserving human activity sensing: a survey</article-title>. <source>High-Confid Comput</source>. <year>2024</year>;<volume>4</volume>(<issue>1</issue>):<fpage>100204</fpage>. doi:<pub-id pub-id-type="doi">10.1016/j.hcc.2024.100204</pub-id>.</mixed-citation></ref>
<ref id="ref-35"><label>[35]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><surname>Debs</surname> <given-names>N</given-names></string-name>, <string-name><surname>Jourdan</surname> <given-names>T</given-names></string-name>, <string-name><surname>Moukadem</surname> <given-names>A</given-names></string-name>, <string-name><surname>Boutet</surname> <given-names>A</given-names></string-name>, <string-name><surname>Frindel</surname> <given-names>C</given-names></string-name></person-group>. <article-title>Motion sensor data anonymization by time-frequency filtering</article-title>. In: <conf-name>2020 28th European Signal Processing Conference (EUSIPCO)</conf-name>; <year>2021 Jan 18&#x2013;21</year>; <publisher-loc>Amsterdam, Netherlands</publisher-loc>. p. <fpage>1707</fpage>&#x2013;<lpage>11</lpage>.</mixed-citation></ref>
<ref id="ref-36"><label>[36]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Rahman</surname> <given-names>M</given-names></string-name>, <string-name><surname>Paul</surname> <given-names>MK</given-names></string-name>, <string-name><surname>Sattar</surname> <given-names>AHMS</given-names></string-name></person-group>. <article-title>Efficient perturbation techniques for preserving privacy of multivariate sensitive data</article-title>. <source>Array</source>. <year>2023</year>;<volume>20</volume>(<issue>4</issue>):<fpage>100324</fpage>. doi:<pub-id pub-id-type="doi">10.1016/j.array.2023.100324</pub-id>.</mixed-citation></ref>
<ref id="ref-37"><label>[37]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Shou</surname> <given-names>L</given-names></string-name>, <string-name><surname>Shang</surname> <given-names>X</given-names></string-name>, <string-name><surname>Chen</surname> <given-names>K</given-names></string-name>, <string-name><surname>Chen</surname> <given-names>G</given-names></string-name>, <string-name><surname>Zhang</surname> <given-names>C</given-names></string-name></person-group>. <article-title>Supporting pattern-preserving anonymization for time-series data</article-title>. <source>IEEE Trans Knowl Data Eng</source>. <year>2013</year>;<volume>25</volume>(<issue>4</issue>):<fpage>877</fpage>&#x2013;<lpage>92</lpage>. doi:<pub-id pub-id-type="doi">10.1109/tkde.2011.249</pub-id>.</mixed-citation></ref>
<ref id="ref-38"><label>[38]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><surname>Samarati</surname> <given-names>P</given-names></string-name>, <string-name><surname>Sweeney</surname> <given-names>L</given-names></string-name></person-group>. <article-title>Protecting privacy when disclosing information: k-anonymity and its enforcement through generalization and suppression</article-title>. In: <conf-name>Proceedings of the 1998 IEEE Symposium on Research in Security and Privacy (S&#x0026;P)</conf-name>. <year>1998 May 3&#x2013;6</year>; <publisher-loc>Oakland, CA, USA</publisher-loc>.</mixed-citation></ref>
<ref id="ref-39"><label>[39]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Liu</surname> <given-names>F</given-names></string-name>, <string-name><surname>Li</surname> <given-names>T</given-names></string-name></person-group>. <article-title>A clustering K-anonymity privacy-preserving method for wearable IoT devices</article-title>. <source>Secur Commun Netw</source>. <year>2018</year>;<volume>2018</volume>(<issue>1</issue>):<fpage>4945152</fpage>.</mixed-citation></ref>
<ref id="ref-40"><label>[40]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Liu</surname> <given-names>K</given-names></string-name>, <string-name><surname>Kargupta</surname> <given-names>H</given-names></string-name>, <string-name><surname>Ryan</surname> <given-names>J</given-names></string-name></person-group>. <article-title>Random projection-based multiplicative data perturbation for privacy preserving distributed data mining</article-title>. <source>IEEE Trans Knowl Data Eng</source>. <year>2006</year>;<volume>18</volume>(<issue>1</issue>):<fpage>92</fpage>&#x2013;<lpage>106</lpage>. doi:<pub-id pub-id-type="doi">10.1109/tkde.2006.14</pub-id>.</mixed-citation></ref>
<ref id="ref-41"><label>[41]</label><mixed-citation publication-type="book"><person-group person-group-type="author"><string-name><surname>Goodfellow</surname> <given-names>IJ</given-names></string-name>, <string-name><surname>Pouget-Abadie</surname> <given-names>J</given-names></string-name>, <string-name><surname>Mirza</surname> <given-names>M</given-names></string-name>, <string-name><surname>Xu</surname> <given-names>B</given-names></string-name>, <string-name><surname>Warde-Farley</surname> <given-names>D</given-names></string-name>, <string-name><surname>Ozair</surname> <given-names>S</given-names></string-name> <etal>et al</etal></person-group>. <chapter-title>Generative adversarial nets</chapter-title>. In: <source>Advances in neural information processing systems</source>. <publisher-loc>Red Hook, NY, USA</publisher-loc>: <publisher-name>Curran Associates, Inc.</publisher-name>; <year>2014</year>. Vol. <volume>27</volume>. doi:<pub-id pub-id-type="doi">10.1145/3422622</pub-id>.</mixed-citation></ref>
<ref id="ref-42"><label>[42]</label><mixed-citation publication-type="book"><person-group person-group-type="author"><string-name><surname>Hallyburton</surname> <given-names>T</given-names></string-name>, <string-name><surname>Nair</surname> <given-names>NR</given-names></string-name>, <string-name><surname>Moya Rueda</surname> <given-names>F</given-names></string-name>, <string-name><surname>Grzeszick</surname> <given-names>R</given-names></string-name>, <string-name><surname>Fink</surname> <given-names>GA</given-names></string-name></person-group>. <chapter-title>Anonymisation for time-series human activity data</chapter-title>. In: <source>Pattern recognition</source>. <publisher-loc>Cham, Switzerland</publisher-loc>: <publisher-name>Springer Nature</publisher-name>; <year>2025</year>. p. <fpage>17</fpage>&#x2013;<lpage>32</lpage>. doi:<pub-id pub-id-type="doi">10.1007/978-3-031-78354-8_2</pub-id>.</mixed-citation></ref>
<ref id="ref-43"><label>[43]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Aleroud</surname> <given-names>A</given-names></string-name>, <string-name><surname>Shariah</surname> <given-names>M</given-names></string-name>, <string-name><surname>Malkawi</surname> <given-names>R</given-names></string-name>, <string-name><surname>Khamaiseh</surname> <given-names>SY</given-names></string-name>, <string-name><surname>Al-Alaj</surname> <given-names>A</given-names></string-name></person-group>. <article-title>A privacy-enhanced human activity recognition using GAN &#x0026; entropy ranking of microaggregated data</article-title>. <source>Cluster Comput</source>. <year>2024</year>;<volume>27</volume>(<issue>2</issue>):<fpage>2117</fpage>&#x2013;<lpage>32</lpage>.</mixed-citation></ref>
<ref id="ref-44"><label>[44]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><surname>Iwasawa</surname> <given-names>Y</given-names></string-name>, <string-name><surname>Nakayama</surname> <given-names>K</given-names></string-name>, <string-name><surname>Yairi</surname> <given-names>I</given-names></string-name>, <string-name><surname>Matsuo</surname> <given-names>Y</given-names></string-name></person-group>. <article-title>Privacy issues regarding the application of DNNs to activity-recognition using wearables and its countermeasures by use of adversarial training</article-title>. In: <conf-name>Proceedings of the Twenty-Sixth International Joint Conference on Artificial Intelligence</conf-name>, <comment>IJCAI-17</comment>; <year>2017 Aug 19&#x2013;25</year>; <publisher-loc>Melbourne, VIC, Australia</publisher-loc>. p. <comment>1930&#x2013;6</comment>. doi:<pub-id pub-id-type="doi">10.24963/ijcai.2017/268</pub-id>.</mixed-citation></ref>
<ref id="ref-45"><label>[45]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><surname>Boutet</surname> <given-names>A</given-names></string-name>, <string-name><surname>Frindel</surname> <given-names>C</given-names></string-name>, <string-name><surname>Gambs</surname> <given-names>S</given-names></string-name>, <string-name><surname>Jourdan</surname> <given-names>T</given-names></string-name>, <string-name><surname>Ngueveu</surname> <given-names>RC</given-names></string-name></person-group>. <article-title>DySan: dynamically sanitizing motion sensor data against sensitive inferences through adversarial networks</article-title>. In: <conf-name>Proceedings of the 2021 ACM Asia Conference on Computer and Communications Security. ASIA CCS &#x2019;21</conf-name>. <year>2021 Jun 7&#x2013;11</year>; <publisher-loc>Hong Kong, China</publisher-loc>. p. <fpage>672</fpage>&#x2013;<lpage>86</lpage>. doi:<pub-id pub-id-type="doi">10.1145/3433210.3453095</pub-id>.</mixed-citation></ref>
<ref id="ref-46"><label>[46]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><surname>Wang</surname> <given-names>G</given-names></string-name>, <string-name><surname>Guo</surname> <given-names>H</given-names></string-name>, <string-name><surname>Wang</surname> <given-names>Y</given-names></string-name>, <string-name><surname>Chen</surname> <given-names>B</given-names></string-name>, <string-name><surname>Zhou</surname> <given-names>C</given-names></string-name>, <string-name><surname>Yan</surname> <given-names>Q</given-names></string-name></person-group>. <article-title>Protecting activity sensing data privacy using hierarchical information dissociation</article-title>. In: <conf-name>2024 IEEE Conference on Communications and Network Security (CNS)</conf-name>; <year>2024 Sep 30&#x2013;Oct 3</year>; <publisher-loc>Taipei, Taiwan</publisher-loc>. p. <fpage>1</fpage>&#x2013;<lpage>9</lpage>.</mixed-citation></ref>
<ref id="ref-47"><label>[47]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><surname>Ahmad</surname> <given-names>S</given-names></string-name>, <string-name><surname>Morerio</surname> <given-names>P</given-names></string-name>, <string-name><surname>Del Bue</surname> <given-names>A</given-names></string-name></person-group>. <article-title>Person re-identification without identification via event anonymization</article-title>. In: <conf-name>Proceedings of the IEEE/CVF International Conference on Computer Vision (ICCV)</conf-name>; <year>2023 Oct 1&#x2013;6</year>; <publisher-loc>Paris, France</publisher-loc>. p. <fpage>11132</fpage>&#x2013;<lpage>41</lpage>.</mixed-citation></ref>
<ref id="ref-48"><label>[48]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Zhang</surname> <given-names>D</given-names></string-name>, <string-name><surname>Yao</surname> <given-names>L</given-names></string-name>, <string-name><surname>Chen</surname> <given-names>K</given-names></string-name>, <string-name><surname>Yang</surname> <given-names>Z</given-names></string-name>, <string-name><surname>Gao</surname> <given-names>X</given-names></string-name>, <string-name><surname>Liu</surname> <given-names>Y</given-names></string-name></person-group>. <article-title>Preventing sensitive information leakage from mobile sensor signals via integrative transformation</article-title>. <source>IEEE Trans Mob Comput</source>. <year>2022</year>;<volume>21</volume>(<issue>12</issue>):<fpage>4517</fpage>&#x2013;<lpage>28</lpage>. doi:<pub-id pub-id-type="doi">10.1109/tmc.2021.3078086</pub-id>.</mixed-citation></ref>
<ref id="ref-49"><label>[49]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><surname>Kurakin</surname> <given-names>A</given-names></string-name>, <string-name><surname>Goodfellow</surname> <given-names>IJ</given-names></string-name>, <string-name><surname>Bengio</surname> <given-names>S</given-names></string-name></person-group>. <article-title>Adversarial machine learning at scale</article-title>. In: <conf-name>International Conference on Learning Representations</conf-name>; <year>2017 Apr 24&#x2013;26</year>; <publisher-loc>Toulon, France</publisher-loc>.</mixed-citation></ref>
<ref id="ref-50"><label>[50]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><surname>Xie</surname> <given-names>C</given-names></string-name>, <string-name><surname>Zhang</surname> <given-names>Z</given-names></string-name>, <string-name><surname>Zhou</surname> <given-names>Y</given-names></string-name>, <string-name><surname>Bai</surname> <given-names>S</given-names></string-name>, <string-name><surname>Wang</surname> <given-names>J</given-names></string-name>, <string-name><surname>Ren</surname> <given-names>Z</given-names></string-name>, <etal>et al</etal></person-group>. <article-title>Improving transferability of adversarial examples with input diversity</article-title>. In: <conf-name>2019 IEEE/CVF Conference on Computer Vision and Pattern Recognition (CVPR)</conf-name>; <year>2019 Jun 15&#x2013;20</year>; <publisher-loc>Long Beach, CA, USA</publisher-loc>. p. <fpage>2725</fpage>&#x2013;<lpage>34</lpage>.</mixed-citation></ref>
<ref id="ref-51"><label>[51]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><surname>Dong</surname> <given-names>Y</given-names></string-name>, <string-name><surname>Pang</surname> <given-names>T</given-names></string-name>, <string-name><surname>Su</surname> <given-names>H</given-names></string-name>, <string-name><surname>Zhu</surname> <given-names>J</given-names></string-name></person-group>. <article-title>Evading defenses to transferable adversarial examples by translation-invariant attacks</article-title>. In: <conf-name>2019 IEEE/CVF Conference on Computer Vision and Pattern Recognition (CVPR)</conf-name>; <year>2019 Jun 15&#x2013;20</year>; <publisher-loc>Long Beach, CA, USA</publisher-loc>. p. <fpage>4307</fpage>&#x2013;<lpage>16</lpage>.</mixed-citation></ref>
<ref id="ref-52"><label>[52]</label><mixed-citation publication-type="other"><person-group person-group-type="author"><string-name><surname>Goodfellow</surname> <given-names>IJ</given-names></string-name>, <string-name><surname>Shlens</surname> <given-names>J</given-names></string-name>, <string-name><surname>Szegedy</surname> <given-names>C</given-names></string-name></person-group>. <article-title>Explaining and harnessing adversarial examples</article-title>. <comment>arXiv:1412.6572. 2015</comment>.</mixed-citation></ref>
<ref id="ref-53"><label>[53]</label><mixed-citation publication-type="other"><person-group person-group-type="author"><string-name><surname>Chung</surname> <given-names>MK</given-names></string-name></person-group>. <article-title>Gaussian kernel smoothing</article-title>. <year>arXiv:2007.09539. 2021</year>.</mixed-citation></ref>
<ref id="ref-54"><label>[54]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><surname>Simonyan</surname> <given-names>K</given-names></string-name>, <string-name><surname>Zisserman</surname> <given-names>A</given-names></string-name></person-group>. <article-title>Very deep convolutional networks for large-scale image recognition</article-title>. In: <conf-name>Proceedings of the 3rd International Conference on Learning Representations (ICLR 2015)</conf-name>; <year>2015 May 7&#x2013;9</year>; <publisher-loc>San Diego, CA, USA</publisher-loc>. p. <fpage>1</fpage>&#x2013;<lpage>14</lpage>.</mixed-citation></ref>
<ref id="ref-55"><label>[55]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><surname>He</surname> <given-names>K</given-names></string-name>, <string-name><surname>Zhang</surname> <given-names>X</given-names></string-name>, <string-name><surname>Ren</surname> <given-names>S</given-names></string-name>, <string-name><surname>Sun</surname> <given-names>J</given-names></string-name></person-group>. <article-title>Deep residual learning for image recognition</article-title>. In: <conf-name>Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition (CVPR)</conf-name>; <year>2016</year>; <publisher-loc>Las Vegas, NV, USA</publisher-loc>. p. <fpage>770</fpage>&#x2013;<lpage>8</lpage>.</mixed-citation></ref>
<ref id="ref-56"><label>[56]</label><mixed-citation publication-type="book"><person-group person-group-type="author"><string-name><surname>Zheng</surname> <given-names>S</given-names></string-name>, <string-name><surname>Shi</surname> <given-names>P</given-names></string-name>, <string-name><surname>Xu</surname> <given-names>H</given-names></string-name>, <string-name><surname>Zhang</surname> <given-names>C</given-names></string-name></person-group>. <source>Launching the new profile on facebook: understanding the triggers and outcomes of users&#x2019; privacy concerns</source>. <comment>In: Trust and trustworthy computing;</comment> <publisher-loc>Berlin/Heidelberg, Germany</publisher-loc>: <conf-name>Springer</conf-name>; <year>2012</year>. p. <fpage>325</fpage>&#x2013;<lpage>39</lpage>.</mixed-citation></ref>
<ref id="ref-57"><label>[57]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><surname>Narain</surname> <given-names>S</given-names></string-name>, <string-name><surname>Vo-Huu</surname> <given-names>TD</given-names></string-name>, <string-name><surname>Block</surname> <given-names>K</given-names></string-name>, <string-name><surname>Noubir</surname> <given-names>G</given-names></string-name></person-group>. <article-title>Inferring user routes and locations using zero-permission mobile sensors</article-title>. In: <conf-name>2016 IEEE Symposium on Security and Privacy (SP)</conf-name>; <year>2016 May 22&#x2013;26</year>; <publisher-loc>San Jose, CA, USA</publisher-loc>. p. <fpage>397</fpage>&#x2013;<lpage>413</lpage>.</mixed-citation></ref>
</ref-list>
</back></article>