USENIX Security2026Top-tier venue
High-Accuracy, Poisoning-Resilient Frequency Estimation in the Shuffle Model
Shaoqiang Wu, Jingyu Jia, Yikuan Zhu, Xinhao Li, Changyu Dong, Zheli Liu
Abstract
We study frequency estimation in the shuffle model of differential privacy under poisoning attacks, where corrupted users may deviate from the local randomizer to inject crafted in-domain messages. Existing shuffle-model protocols face a core tension: achieving low estimation error relies on flexible multi-message noise generation, which can amplify poisoning influence once messages are anonymized by shuffling.
To address this tension, we propose a symmetric binomialsum noise distribution (i.e., Bin(n/2, p) + Bin(n/2, 1p)), which preserves high accuracy while limiting the impact of crafted in-domain messages. We realize this distribution via preprocessing-guided noise generation, which routes a balanced collection of mode flags through the shuffler so that each user receives a randomly assigned mode flag that fixes their noise-sampling behavior prior to shuffling. For binary estimation, our protocol requires a single Bernoulli trial per user and at most 2 messages per user (1.5 on average), while bounding the worst-case poisoning influence of a single corrupted user by O(1/n). We extend the protocol to histograms, including large domains via hashing, and provide formal privacy, accuracy, and robustness guarantees. Experiments on real datasets show that our protocols remain resilient under poisoning and reduce MAE by up to nearly 2× over the strongest baseline at comparable per-user communication on small domains, and match it on large domains.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Builds on10
- Manipulation Attacks in Local Differential PrivacyAlbert Cheu, Adam D. Smith, Jonathan R. UllmanS&P 2021 · 122 citations
- Data Poisoning Attacks to Local Differential Privacy ProtocolsXiaoyu Cao, Jinyuan Jia, Neil Zhenqiang GongUSENIX Security 2021 · 100 citations
- Private Summation in the Multi-Message Shuffle ModelBorja Balle, James Bell, Adrià Gascón, Kobbi NissimCCS 2020 · 52 citations
- Differentially Private Aggregation in the Shuffle Model: Almost Central Accuracy in Almost a Single MessageBadih Ghazi, Ravi Kumar, Pasin Manurangsi, Rasmus Pagh et al.ICML 2021 · 45 citations
- Differentially Private Histograms in the Shuffle Model from Fake UsersAlbert Cheu, Maxim ZhilyaevS&P 2022 · 40 citations
Related papers
- Defense against Poisoning Attacks under Shuffle-DPSiyi Wang, Qiyao Luo, Yihua Hu, Lixu Wang et al.SIGMOD 2026 · 1 citation
- Augmented Shuffle Protocols for Accurate and Robust Frequency Estimation Under Differential PrivacyTakao Murakami, Yuichi Sei, Reo EriguchiS&P 2025
- Augmented Shuffle Differential Privacy Protocols for Large-Domain Categorical and Key-Value DataTakao Murakami, Yuichi Sei, Reo EriguchiNDSS 2026 · 1 citation
- Robust Single-Message Shuffle Differential Privacy Protocol for Accurate Distribution EstimationXiaoguang Li, Hanyi Wang, Yaowei Huang, Jungang Yang et al.ICDE 2026
- On the Power of Multiple Anonymous Messages: Frequency Estimation and Selection in the Shuffle Model of Differential PrivacyBadih Ghazi, Noah Golowich, Ravi Kumar, Rasmus Pagh et al.EUROCRYPT 2021 · 34 citations
