Cities are rapidly deploying sensing infrastructure -- cameras, environmental sensors, and connected kiosks -- that continuously observe public spaces, yet they lack a system architecture governing how applications access, aggregate, and retain this data, creating privacy risks and preventing consistent policy enforcement. We present CityOS, an operating system for urban sensing that mediates application access to sensor data through a three-tier API inspired by structured, privacy-conscious web interfaces. The tiers expand the spatial scope of data access while imposing progressively stronger privacy constraints: On-Scene supports real-time sensing with raw data confined to the local context; Single-Locality Aggregation enables differentially private longitudinal statistics at a fixed location; and Cross-Locality Aggregation supports citywide analytics via aggregation across locations, with user devices enforcing per-user privacy budgets. CityOS runs as an edge runtime that executes untrusted applications in ephemeral containers, enforcing these policies and providing transparency via broadcasts of differential privacy loss. We implement CityOS and applications across all tiers -- including pedestrian safety alerts, real-time and forecast parking availability, traffic dashboards, and subway trajectory measurement -- and show that it supports practical streetscape applications while enforcing strong privacy.
翻译:城市正在快速部署感知基础设施——摄像头、环境传感器和互联信息亭——这些设施持续观测公共空间,但缺乏规范应用程序如何访问、聚合和保留这些数据的系统架构,从而造成隐私风险并阻碍策略的一致性执行。我们提出CityOS,一种用于城市感知的操作系统,通过受结构化、注重隐私的Web界面启发的三层API来中介应用程序对传感器数据的访问。各层扩展了数据访问的空间范围,同时施加逐渐增强的隐私约束:现场层支持原始数据局限于本地上下文的实时感知;单地点聚合层在固定位置实现差分隐私的纵向统计;跨地点聚合层通过跨位置聚合支持全市范围的分析,并由用户设备强制执行每位用户的隐私预算。CityOS作为边缘运行时运行,在临时容器中执行不可信应用程序,强制实施这些策略,并通过广播差分隐私损失实现透明性。我们实现了CityOS及涵盖所有层的应用程序——包括行人安全告警、实时与预测停车位可用性、交通仪表盘以及地铁轨迹测量——并表明它在强制执行强隐私的同时,支持实用的街景应用。