USENIX Security2023Top-tier venue
Fine-grained Poisoning Attack to Local Differential Privacy Protocols for Mean and Variance Estimation
Xiaoguang Li, Ninghui Li, Wenhai Sun, Neil Zhenqiang Gong, Hui Li
Abstract
Although local differential privacy (LDP) protects individual users' data from inference by an untrusted data curator, recent studies show that an attacker can launch a data poisoning attack from the user side to inject carefully-crafted bogus data into the LDP protocols in order to maximally skew the final estimate by the data curator. In this work, we further advance this knowledge by proposing a new fine-grained attack, which allows the attacker to fine-tune and simultaneously manipulate mean and variance estimations that are popular analytical tasks for many real-world applications. To accomplish this goal, the attack leverages the characteristics of LDP to inject fake data into the output domain of the local LDP instance. We call our attack the output poisoning attack (OPA). We observe a security-privacy consistency where a small privacy loss enhances the security of LDP, which contradicts the known security-privacy trade-off from prior work. We further study the consistency and reveal a more holistic view of the threat landscape of data poisoning attacks on LDP. We comprehensively evaluate our attack against a baseline attack that intuitively provides false input to LDP. The experimental results show that OPA outperforms the baseline on three real-world datasets. We also propose a novel defense method that can recover the result accuracy from polluted data collection and offer insight into the secure LDP design.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 8176d170-1749-49cc-aceb-dd336b8d8f0aCited by top-tier papers15
- LDPRecover: Recovering Frequencies from Poisoning Attacks Against Local Differential PrivacyXinyue Sun, Qingqing Ye, Haibo Hu, Jiawei Duan et al.ICDE 2024 · 21 citations
- Differential Aggregation against General Colluding AttackersRong Du, Qingqing Ye, Yue Fu, Haibo Hu et al.ICDE 2023 · 11 citations
- Practical and Accurate Local Edge Differentially Private Graph AlgorithmsPranay Mundra, Charalampos Papamanthou, Julian Shun, Quanquan C. LiuVLDB 2025 · 3 citations
- Interactive Trimming Against Evasive Online Data Manipulation Attacks: A Game-Theoretic ApproachYue Fu, Qingqing Ye, Rong Du, Haibo HuICDE 2024 · 3 citations
- Data Poisoning Attacks to Locally Differentially Private Frequent Itemset Mining ProtocolsWei Tong, Haoyu Chen, Jiacheng Niu, Sheng ZhongCCS 2024 · 2 citations
Builds on17
- Foreshadow: Extracting the Keys to the Intel SGX Kingdom with Transient Out-of-Order ExecutionJo Van Bulck, Marina Minkin, Ofir Weisse, Daniel Genkin et al.USENIX Security 2018 · 1,175 citations
- Town Crier: An Authenticated Data Feed for Smart ContractsFan Zhang, Ethan Cecchetti, Kyle Croman, Ari Juels et al.CCS 2016 · 668 citations
- Locally Differentially Private Protocols for Frequency EstimationTianhao Wang, Jeremiah Blocki, Ninghui Li, Somesh JhaUSENIX Security 2017 · 629 citations
- Keystone: an open framework for architecting trusted execution environmentsDayeol Lee, David Kohlbrenner, Shweta Shinde, Krste Asanovic et al.EuroSys 2020 · 381 citations
- Plundervolt: Software-based Fault Injection Attacks against Intel SGXKit Murdock, David F. Oswald, Flavio D. Garcia, Jo Van Bulck et al.S&P 2020 · 369 citations
Related papers
- Data Poisoning Attacks to Local Differential Privacy ProtocolsXiaoyu Cao, Jinyuan Jia, Neil Zhenqiang GongUSENIX Security 2021 · 100 citations
- Poisoning Attacks to Local Differential Privacy Protocols for Key-Value DataYongji Wu, Xiaoyu Cao, Jinyuan Jia, Neil Zhenqiang GongUSENIX Security 2022
- Fine-Grained Manipulation Attacks to Local Differential Privacy Protocols for Range QueryXinyu Li, Wenda Chen, Xuebin RenICDE 2026
- Revisiting Locally Differentially Private Protocols: Towards Better Trade-Offs in Privacy, Utility, and Attack ResistanceHéber Hwang Arcolezi, Sébastien GambsICDE 2026
- On the Robustness of LDP Protocols for Numerical Attributes under Data Poisoning AttacksXiaoguang Li, Zitao Li, Ninghui Li, Wenhai SunNDSS 2025
