Elephants Do Not Forget: Differential Privacy with State Continuity for Privacy Budget
Jiankai Jin, Chitchanok Chuengsatiansup, Toby Murray, Benjamin I. P. Rubinstein, Yuval Yarom, Olga Ohrimenko
Abstract
Current implementations of differentially-private (DP) systems either lack support to track the global privacy budget consumed on a dataset, or fail to faithfully maintain the state continuity of this budget. We show that failure to maintain a privacy budget enables an adversary to mount replay, rollback and fork attacks -obtaining answers to many more queries than what a secure system would allow. As a result the attacker can reconstruct secret data that DP aims to protect -even if DP code runs in a Trusted Execution Environment (TEE). We propose ElephantDP, a system that aims to provide the same guarantees as a trusted curator in the global DP model would, albeit set in an untrusted environment. Our system relies on a state continuity module to provide protection for the privacy budget and a TEE to faithfully execute DP code and update the budget. To provide security, our protocol makes several design choices including the content of the persistent state and the order between budget updates and query answers. We prove that ElephantDP provides liveness (i.e., the protocol can restart from a correct state and respond to queries as long as the budget is not exceeded) and DP confidentiality (i.e., an attacker learns about a dataset as much as it would from interacting with a trusted curator). Our implementation and evaluation of the protocol use Intel SGX as a TEE to run the DP code and a network of TEEs to maintain state continuity. Compared to an insecure baseline, we observe 1.1-3.2× overheads and lower relative overheads for complex DP queries. CCS CONCEPTS • Security and privacy → Privacy protections; Security in hardware.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers4
- Samplable Anonymous Aggregation for Private Federated Data AnalysisKunal Talwar, Shan Wang, Audra McMillan, Vitaly Feldman et al.CCS 2024 · 6 citations
- PAPAYA Federated Analytics Stack: Engineering Privacy, Scalability and PracticalityHarish Srinivas, Graham Cormode, Mehrdad Honarkhah, Samuel Lurye et al.NSDI 2025 · 2 citations
- Characterizing Trust Boundary Vulnerabilities in TEE Container Systems: An Empirical StudyWeijie Liu, Hongbo Chen, Shuo Huai, Zhen Xu et al.FSE 2026
- How Researchers De-Identify Data in PracticeWentao Guo, Paige Pepitone, Adam J. Aviv, Michelle L. MazurekUSENIX Security 2025
Builds on12
- Oblivious Multi-Party Machine Learning on Trusted ProcessorsOlga Ohrimenko, Felix Schuster, Cédric Fournet, Aastha Mehta et al.USENIX Security 2016 · 594 citations
- The Discrete Gaussian for Differential PrivacyClément L. Canonne, Gautam Kamath, Thomas SteinkeNeurIPS 2020 · 355 citations
- EnclaveDB: A Secure Database Using SGXChristian Priebe, Kapil Vaswani, Manuel CostaS&P 2018 · 329 citations
- ROTE: Rollback Protection for Trusted ExecutionSinisa Matetic, Mansoor Ahmed, Kari Kostiainen, Aritra Dhar et al.USENIX Security 2017 · 249 citations
- Ariadne: A Minimal Approach to State ContinuityRaoul Strackx, Frank PiessensUSENIX Security 2016 · 107 citations
Related papers
- NARRATOR: Secure and Practical State Continuity for Trusted Execution in the CloudJianyu Niu, Wei Peng, Xiaokuan Zhang, Yinqian ZhangCCS 2022 · 21 citations
- Towards Formal Verification of State Continuity for Enclave ProgramsMohit Kumar Jangid, Guoxing Chen, Yinqian Zhang, Zhiqiang LinUSENIX Security 2021 · 18 citations
- Fully Oblivious Differential Privacy for Frequency Estimation in the Augmented Shuffle Model with Trusted ProcessorsTakao Murakami, Yuichi Sei, Reo EriguchiUSENIX Security 2026
- Enabling Secure and Efficient Data Analytics Pipeline Evolution with Trusted Execution EnvironmentHaotian Gao, Cong Yue, Tien Tuan Anh Dinh, Zhiyong Huang et al.VLDB 2023 · 6 citations
- DDRop: Active Memory Interposer Attacks on Confidential VMs by Dropping DDR5 WritesJesse De Meulemeester, Stefan Gloor, Patrick Jattke, Daniel Moghimi et al.CCS 2026
