Auditing Apple's DifferentialPrivacy.framework: Implementation Bugs, Misconfigurations, and Practical Risks
Rishav Chourasia, Ergute Bao, Uzair Javaid, Xiaokui Xiao
Abstract
Since 2016, Apple claims that the device analytics it collects to improve user experience are protected by differential privacy (DP). Running on over 2.35 billion Apple devices today, 11Source: MacRumors report on Apple's worldwide active device count. their DP framework gathers a variety of sensitive data ranging from contents of photos to COVID-19 vaccination status. However, despite strong community interest, Apple has not open-sourced its privatization algorithms, impeding independent researchers from verifying its privacy claims and testing for privacy violations. We perform a deep audit of Apple's client-side DP framework on macOS Sonoma 14.2 and Sequoia 15.6 by reverse engineering its native binaries and building runtime interfaces to execute Apple's deployed mechanisms. Our audit covers nearly all deployed algorithms, including Count Median Sketch (CMS) and Hadamard-CMS from Apple's white paper [1], and the Prio protocol for secure aggregation (SecAgg), which Apple uses for learning iconic scenes [2]. We report multiple issues. Every algorithm in Apple's framework that relies on floating-point noise fails to meet its advertised DP and zero-knowledge (ZK) proof guarantees. These violations happen because the DP framework uses insecure noise generators that are known to have floating-point vulnerabilities since 2012. We also discover that the SecAgg protocols in Apple's DP framework are configured with local DP disabled, uploading data without any local DP protection. Our audit provides evidence of DP violations in 5 out of 9 audited mechanisms, impacting 87 % of data collection in macOS Sonoma and 68 % in Sequoia. These vulnerabilities are exploitable by any party with access to pre-aggregation logs. We found instances on the open internet of leaked iPhone logs that can be decoded to recover private information, such as domains visited in Safari and emojis typed on the iPhone keyboard. We responsibly disclosed these vulnerabilities to Apple; the concerned mechanisms are now deprecated.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext b34bd6d5-cfcd-4958-baa0-338625402c3eBuilds on15
- The Discrete Gaussian for Differential PrivacyClément L. Canonne, Gautam Kamath, Thomas SteinkeNeurIPS 2020 · 355 citations
- Privacy Auditing with One (1) Training RunThomas Steinke, Milad Nasr, Matthew JagielskiNeurIPS 2023 · 178 citations
- Detecting Violations of Differential PrivacyZeyu Ding, Yuxin Wang, Guanhong Wang, Danfeng Zhang et al.CCS 2018 · 156 citations
- Are We There Yet? Timing and Floating-Point Attacks on Differential Privacy SystemsJiankai Jin, Eleanor McMurtry, Benjamin I. P. Rubinstein, Olga OhrimenkoS&P 2022 · 57 citations
- DP-Sniper: Black-Box Discovery of Differential Privacy Violations using ClassifiersBenjamin Bichsel, Samuel Steffen, Ilija Bogunovic, Martin T. VechevS&P 2021 · 53 citations
Related papers
- Kobold: Evaluating Decentralized Access Control for Remote NSXPC Methods on iOSLuke Deshotels, Costin Carabas, Jordan Beichler, Razvan Deaconescu et al.S&P 2020 · 10 citations
- Pool Inference Attacks on Local Differential Privacy: Quantifying the Privacy Guarantees of Apple's Count Mean Sketch in PracticeAndrea Gadotti, Florimond Houssiau, Meenatchi Sundaram Muthu Selva Annamalai, Yves-Alexandre de MontjoyeUSENIX Security 2022
- Disrupting Continuity of Apple's Wireless Ecosystem Security: New Tracking, DoS, and MitM Attacks on iOS and macOS Through Bluetooth Low Energy, AWDL, and Wi-FiMilan Stute, Alexander Heinrich, Jannik Lorenz, Matthias HollickUSENIX Security 2021 · 31 citations
- Exploring Privacy Leakage and Data Disclosure Violations in the MacOS Application EcosystemJyotirmay Chauhan, Kostas Solomos, Mir Masood Ali, Jason PolakisCCS 2026
- Timing Attacks on Differential Privacy are PracticalZachary Ratliff, Nicolás Berrios, James MickensCCS 2025
