USENIX Security2021Top-tier venue
Data Poisoning Attacks to Local Differential Privacy Protocols
Xiaoyu Cao, Jinyuan Jia, Neil Zhenqiang Gong
Abstract
Local Differential Privacy (LDP) protocols enable an untrusted data collector to perform privacy-preserving data analytics. In particular, each user locally perturbs his/her data to preserve privacy before sending it to the data collector, who aggregates the perturbed data to obtain statistics of interest. Over the past several years, researchers from multiple communities--such as security, database, and theoretical computer science-- have proposed many LDP protocols. These studies mainly focused on improving the utility of the LDP protocols. However, the security of LDP protocols is largely unexplored. In this work, we aim to bridge this gap. We focus on LDP protocols for frequency estimation and heavy hitter identification, which are two basic data analytics tasks. Specifically, we show that an attacker can inject fake users into an LDP protocol and the fake users send carefully crafted data to the data collector such that the LDP protocol estimates high frequencies for certain items or identifies them as heavy hitters. We call our attacks data poisoning attacks. We theoretically and/or empirically show the effectiveness of our attacks. We also explore two countermeasures against our attacks. Our experimental results show that they can effectively defend against our attacks in some scenarios but have limited effectiveness in others, highlighting the needs for new defenses against our attacks.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext f16b7645-32e4-4170-ab4a-32c7d636f81bCited by top-tier papers31
- Hidden Backdoors in Human-Centric Language ModelsShaofeng Li, Hui Liu, Tian Dong, Benjamin Zi Hao Zhao et al.CCS 2021 · 108 citations
- Differentially Private Histograms in the Shuffle Model from Fake UsersAlbert Cheu, Maxim ZhilyaevS&P 2022 · 40 citations
- Orchard: Differentially Private Analytics at ScaleEdo Roth, Hengchu Zhang, Andreas Haeberlen, Benjamin C. PierceOSDI 2020 · 40 citations
- On the Risks of Collecting Multidimensional Data Under Local Differential PrivacyHéber Hwang Arcolezi, Sébastien Gambs, Jean-François Couchot, Catuscia PalamidessiVLDB 2023 · 22 citations
- LDPRecover: Recovering Frequencies from Poisoning Attacks Against Local Differential PrivacyXinyue Sun, Qingqing Ye, Haibo Hu, Jiawei Duan et al.ICDE 2024 · 21 citations
Builds on17
- Trojaning Attack on Neural NetworksYingqi Liu, Shiqing Ma, Yousra Aafer, Wen-Chuan Lee et al.NDSS 2018 · 1,377 citations
- Manipulating Machine Learning: Poisoning Attacks and Countermeasures for Regression LearningMatthew Jagielski, Alina Oprea, Battista Biggio, Chang Liu et al.S&P 2018 · 867 citations
- Locally Differentially Private Protocols for Frequency EstimationTianhao Wang, Jeremiah Blocki, Ninghui Li, Somesh JhaUSENIX Security 2017 · 629 citations
- Heavy Hitter Estimation over Set-Valued Data with Local Differential PrivacyZhan Qin, Yin Yang, Ting Yu, Issa Khalil et al.CCS 2016 · 344 citations
- Locally Differentially Private Frequent Itemset MiningTianhao Wang, Ninghui Li, Somesh JhaS&P 2018 · 196 citations
Related papers
- Data Poisoning Attacks to Locally Differentially Private Frequent Itemset Mining ProtocolsWei Tong, Haoyu Chen, Jiacheng Niu, Sheng ZhongCCS 2024 · 2 citations
- Poisoning Attacks to Local Differential Privacy Protocols for Key-Value DataYongji Wu, Xiaoyu Cao, Jinyuan Jia, Neil Zhenqiang GongUSENIX Security 2022
- Fine-grained Poisoning Attack to Local Differential Privacy Protocols for Mean and Variance EstimationXiaoguang Li, Ninghui Li, Wenhai Sun, Neil Zhenqiang Gong et al.USENIX Security 2023
- Fine-Grained Manipulation Attacks to Local Differential Privacy Protocols for Range QueryXinyu Li, Wenda Chen, Xuebin RenICDE 2026
- Mitigating Data Poisoning Attacks to Local Differential PrivacyXiaolin Li, Ninghui Li, Boyang Wang, Wenhai SunCCS 2025 · 1 citation
