Manipulation Attacks in Local Differential Privacy
Albert Cheu, Adam D. Smith, Jonathan R. Ullman
Abstract
Local differential privacy is a widely studied restriction on distributed algorithms that collect aggregates about sensitive user data, and is now deployed in several large systems. We initiate a systematic study of a fundamental limitation of locally differentially private protocols: they are highly vulnerable to adversarial manipulation. While any algorithm can be manipulated by adversaries who lie about their inputs, we show that any noninteractive locally differentially private protocol can be manipulated to a much greater extent—when the privacy level is high, or the domain size is large, a small fraction of users in the protocol can completely obscure the distribution of the honest users’ input. We also construct protocols that are optimally robust to manipulation for a variety of common tasks in local differential privacy. Finally, we give simple experiments validating our theoretical results, and demonstrating that proto-cols that are optimal without manipulation can have dramatically different levels of robustness to manipulation. Our results suggest caution when deploying local differential privacy and reinforce the importance of efficient cryptographic techniques for the distributed emulation of centrally differentially private mechanisms.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 333915ad-1ee1-4eb2-bce1-7976a5a89011Cited by top-tier papers35
- Private Summation in the Multi-Message Shuffle ModelBorja Balle, James Bell, Adrià Gascón, Kobbi NissimCCS 2020 · 52 citations
- Differentially Private Histograms in the Shuffle Model from Fake UsersAlbert Cheu, Maxim ZhilyaevS&P 2022 · 40 citations
- Orchard: Differentially Private Analytics at ScaleEdo Roth, Hengchu Zhang, Andreas Haeberlen, Benjamin C. PierceOSDI 2020 · 40 citations
- On the Privacy-Robustness-Utility Trilemma in Distributed LearningYoussef Allouah, Rachid Guerraoui, Nirupam Gupta, Rafael Pinot et al.ICML 2023 · 33 citations
- On the Risks of Collecting Multidimensional Data Under Local Differential PrivacyHéber Hwang Arcolezi, Sébastien Gambs, Jean-François Couchot, Catuscia PalamidessiVLDB 2023 · 22 citations
Related papers
- Fine-Grained Manipulation Attacks to Local Differential Privacy Protocols for Range QueryXinyu Li, Wenda Chen, Xuebin RenICDE 2026
- An Attack-Agnostic Defense Framework Against Manipulation Attacks Under Local Differential PrivacyPuning Zhao, Zhikun Zhang, Jiawei Dong, Jiafei Wu et al.S&P 2025
- Is Interaction Necessary for Distributed Private Learning?Adam D. Smith, Abhradeep Thakurta, Jalaj UpadhyayS&P 2017 · 159 citations
- Locally Differentially Private Protocols for Frequency EstimationTianhao Wang, Jeremiah Blocki, Ninghui Li, Somesh JhaUSENIX Security 2017 · 629 citations
- Collecting and Analyzing Data Jointly from Multiple Services under Local Differential PrivacyMin Xu, Bolin Ding, Tianhao Wang, Jingren ZhouVLDB 2020 · 22 citations
