Side-Channel Attacks on Query-Based Data Anonymization
Franziska Boenisch, Reinhard Munz, Marcel Tiepelt, Simon Hanisch, Christiane Kuhn, Paul Francis
Abstract
A longstanding problem in computer privacy is that of data anonymization. One common approach is to present a query interface to analysts, and anonymize on a query-by-query basis. In practice, this approach often uses a standard database back end, and presents the query semantics of the database to the analyst. This paper presents a class of novel side-channel attacks that work against any query-based anonymization system that uses a standard database back end. The attacks exploit the implicit conditional logic of database runtime optimizations. They manipulate this logic to trigger timing and exception-throwing side-channels based on the contents of the data. We demonstrate the attacks on the implementation of the CHORUS Differential Privacy system released by Uber as an open source project. We obtain perfect reconstruction of millions of data values even with a Differential Privacy budget smaller than epsilon = 1.0 and no prior knowledge. The paper also presents the design of a general defense to the runtime-optimization attacks, and a concrete implementation of the defense in the latest version of Diffix. The defense works without modifications to the back end database, and operates by modifying SQL to eliminate the runtime optimization or disable the side-channels. In addition, two other attacks that exploit specific flaws in Diffix and CHORUS are reported. These have been fixed in the respective implementations.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers3
- From Principle to Practice: Vertical Data Minimization for Machine LearningRobin Staab, Nikola Jovanovic, Mislav Balunovic, Martin T. VechevS&P 2024 · 10 citations
- QueryCheetah: Fast Automated Discovery of Attribute Inference Attacks Against Query-Based SystemsBozhidar Stevanoski, Ana-Maria Cretu, Yves-Alexandre de MontjoyeCCS 2024
- Plaintext Recovery Against Post-Filtering Access ControlZachary Espiritu, David CashUSENIX Security 2026
Builds on1
Related papers
- Privacy Side Channels in Machine Learning SystemsEdoardo Debenedetti, Giorgio Severi, Milad Nasr, Christopher A. Choquette-Choo et al.USENIX Security 2024 · 52 citations
- Timing Attacks on Differential Privacy are PracticalZachary Ratliff, Nicolás Berrios, James MickensCCS 2025
- Database Reconstruction from Noisy Volumes: A Cache Side-Channel Attack on SQLiteAria Shahverdi, Mahammad Shirinov, Dana Dachman-SoledUSENIX Security 2021 · 20 citations
- A Framework for Differential Privacy Against Timing AttacksZachary Ratliff, Salil P. VadhanCCS 2024 · 3 citations
- Exposing Privacy Risks in Anonymizing Clinical Data: Combinatorial Refinement Attacks on k-Anonymity Without Auxiliary InformationSomiya Chhillar, Mary K. Righi, Rebecca E. Sutter, Evgenios M. KornaropoulosCCS 2025
