Are We There Yet? Timing and Floating-Point Attacks on Differential Privacy Systems
Jiankai Jin, Eleanor McMurtry, Benjamin I. P. Rubinstein, Olga Ohrimenko
摘要
Differential privacy is a de facto privacy framework that has seen adoption in practice via a number of mature software platforms. Implementation of differentially private (DP) mechanisms has to be done carefully to ensure end-to-end security guarantees. In this paper we study two implementation flaws in the noise generation commonly used in DP systems. First we examine the Gaussian mechanism’s susceptibility to a floating-point representation attack. The premise of this first vulnerability is similar to the one carried out by Mironov in 2011 against the Laplace mechanism. Our experiments show the attack’s success against DP algorithms, including deep learning models trained using differentially-private stochastic gradient descent. In the second part of the paper we study discrete counterparts of the Laplace and Gaussian mechanisms that were previously proposed to alleviate the shortcomings of floating-point representation of real numbers. We show that such implementations unfortunately suffer from another side channel: a novel timing attack. An observer that can measure the time to draw (discrete) Laplace or Gaussian noise can predict the noise magnitude, which can then be used to recover sensitive attributes. This attack invalidates differential privacy guarantees of systems implementing such mechanisms. We demonstrate that several commonly used, state-of-the-art implementations of differential privacy are susceptible to these attacks. We report success rates up to 92.56% for floating point attacks on DP-SGD, and up to 99.65% for end-to-end timing attacks on private sum protected with discrete Laplace. Finally, we evaluate and suggest partial mitigations.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper16
- "Get in Researchers; We're Measuring Reproducibility": A Reproducibility Study of Machine Learning Papers in Tier 1 Security ConferencesDaniel Olszewski, Allison Lu, Carson Stillman, Kevin Warren 等CCS 2023 · 被引用 19 次
- Widespread Underestimation of Sensitivity in Differentially Private Libraries and How to Fix ItSílvia Casacuberta, Michael Shoemate, Salil P. Vadhan, Connor WagamanCCS 2022 · 被引用 12 次
- Machine Learning needs Better Randomness Standards: Randomised Smoothing and PRNG-based attacksPranav Dahiya, Ilia Shumailov, Ross AndersonUSENIX Security 2024 · 被引用 11 次
- Group and Attack: Auditing Differential PrivacyJohan Lokna, Anouk Paradis, Dimitar I. Dimitrov, Martin T. VechevCCS 2023 · 被引用 10 次
- Online Local Differential Private Quantile Inference via Self-normalizationYi Liu, Qirui Hu, Lei Ding, Linglong KongICML 2023 · 被引用 7 次
它引用的顶会 Paper10
- Deep Learning with Differential PrivacyMartín Abadi, Andy Chu, Ian J. Goodfellow, H. Brendan McMahan 等CCS 2016 · 被引用 7,620 次
- The Discrete Gaussian for Differential PrivacyClément L. Canonne, Gautam Kamath, Thomas SteinkeNeurIPS 2020 · 被引用 355 次
- Differentially Private Model Publishing for Deep LearningLei Yu, Ling Liu, Calton Pu, Mehmet Emre Gursoy 等S&P 2019 · 被引用 294 次
- The Distributed Discrete Gaussian Mechanism for Federated Learning with Secure AggregationPeter Kairouz, Ziyu Liu, Thomas SteinkeICML 2021 · 被引用 291 次
- Detecting Violations of Differential PrivacyZeyu Ding, Yuxin Wang, Guanhong Wang, Danfeng Zhang 等CCS 2018 · 被引用 156 次
相关 Paper
- Timing Attacks on Differential Privacy are PracticalZachary Ratliff, Nicolás Berrios, James MickensCCS 2025
- A Framework for Differential Privacy Against Timing AttacksZachary Ratliff, Salil P. VadhanCCS 2024 · 被引用 3 次
- Auditing Differentially Private Machine Learning: How Private is Private SGD?Matthew Jagielski, Jonathan R. Ullman, Alina OpreaNeurIPS 2020 · 被引用 354 次
- GPM: The Gaussian Pancake Mechanism for Planting Undetectable Backdoors in Differential PrivacyHaochen Sun, Xi HeSIGMOD 2026
- Implementing the Exponential Mechanism with Base-2 Differential PrivacyChristina IlventoCCS 2020 · 被引用 2 次
