On the Robustness of LDP Protocols for Numerical Attributes under Data Poisoning Attacks
Xiaoguang Li, Zitao Li, Ninghui Li, Wenhai Sun
Abstract
Recent studies reveal that local differential privacy (LDP) protocols are vulnerable to data poisoning attacks where an attacker can manipulate the final estimate on the server by leveraging the characteristics of LDP and sending carefully crafted data from a small fraction of controlled local clients. This vulnerability raises concerns regarding the robustness and reliability of LDP in hostile environments. In this paper, we conduct a systematic investigation of the robustness of state-of-the-art LDP protocols for numerical attributes, i.e., categorical frequency oracles (CFOs) with binning and consistency, and distribution reconstruction. We evaluate protocol robustness through an attack-driven approach and propose new metrics for cross-protocol attack gain measurement. The results indicate that Square Wave and CFO-based protocols in the Server setting are more robust against the attack compared to the CFO-based protocols in the User setting. Our evaluation also unfolds new relationships between LDP security and its inherent design choices. We found that the hash domain size in local-hashing-based LDP has a profound impact on protocol robustness beyond the well-known effect on utility. Further, we propose a zero-shot attack detection by leveraging the rich reconstructed distribution information. The experiment show that our detection significantly improves the existing methods and effectively identifies data manipulation in challenging scenarios.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 454bb823-66e4-43cc-b674-09d64e0dfbc1Cited by top-tier papers5
- Mitigating Data Poisoning Attacks to Local Differential PrivacyXiaolin Li, Ninghui Li, Boyang Wang, Wenhai SunCCS 2025 · 1 citation
- Poisoning Attacks to Local Differential Privacy for Ranking EstimationPei Zhan, Peng Tang, Yangzhuo Li, Puwen Wei et al.CCS 2025
- Robust Estimation of Sparse Numerical Vectors under Local Differential PrivacyPuning Zhao, Zhikun Zhang, Shaowei Wang, Sheng Yue et al.CCS 2026
- Revisiting EM-based Estimation for Locally Differentially Private ProtocolsYutong Ye, Tianhao Wang, Min Zhang, Dengguo FengNDSS 2025
- Robust Single-Message Shuffle Differential Privacy Protocol for Accurate Distribution EstimationXiaoguang Li, Hanyi Wang, Yaowei Huang, Jungang Yang et al.ICDE 2026
Builds on12
- Locally Differentially Private Protocols for Frequency EstimationTianhao Wang, Jeremiah Blocki, Ninghui Li, Somesh JhaUSENIX Security 2017 · 629 citations
- Generating Synthetic Decentralized Social Graphs with Local Differential PrivacyZhan Qin, Ting Yu, Yin Yang, Issa Khalil et al.CCS 2017 · 266 citations
- Locally Differentially Private Analysis of Graph StatisticsJacob Imola, Takao Murakami, Kamalika ChaudhuriUSENIX Security 2021 · 139 citations
- Manipulation Attacks in Local Differential PrivacyAlbert Cheu, Adam D. Smith, Jonathan R. UllmanS&P 2021 · 122 citations
- Estimating Numerical Distributions under Local Differential PrivacyZitao Li, Tianhao Wang, Milan Lopuhaä-Zwakenberg, Ninghui Li et al.SIGMOD 2020 · 115 citations
Related papers
- Fine-grained Poisoning Attack to Local Differential Privacy Protocols for Mean and Variance EstimationXiaoguang Li, Ninghui Li, Wenhai Sun, Neil Zhenqiang Gong et al.USENIX Security 2023
- Poisoning Attacks to Local Differential Privacy Protocols for Key-Value DataYongji Wu, Xiaoyu Cao, Jinyuan Jia, Neil Zhenqiang GongUSENIX Security 2022
- Revisiting Locally Differentially Private Protocols: Towards Better Trade-Offs in Privacy, Utility, and Attack ResistanceHéber Hwang Arcolezi, Sébastien GambsICDE 2026
- Fine-Grained Manipulation Attacks to Local Differential Privacy Protocols for Range QueryXinyu Li, Wenda Chen, Xuebin RenICDE 2026
- LDPRecover: Recovering Frequencies from Poisoning Attacks Against Local Differential PrivacyXinyue Sun, Qingqing Ye, Haibo Hu, Jiawei Duan et al.ICDE 2024 · 21 citations
