HisTorε: Differentially Private and Robust Statistics Collection for Tor
Akshaya Mani, Micah Sherr
摘要
A large volume of existing research attempts to understand who uses Tor and how the network is used (and misused). However, conducting measurements on the live Tor network, if done improperly, can endanger the security and anonymity of the millions of users who depend on the network to enhance their online privacy. Indeed, several existing measurement studies of Tor have been heavily criticized for unsafe research practices. Tor needs privacy-preserving methods of gathering statistics. The recently proposed PrivEx system demonstrates how data can be safely collected on Tor using techniques from differential privacy. However, as we demonstrate in this paper, the integrity of the statistics reported by PrivEx is brittle under realistic deployment conditions. An adversary who operates even a single relay in the volunteer-operated anonymity network can arbitrarily influence the result of PrivEx queries. We argue that a safe and useful data collection mechanism must provide both privacy and integrity protections. This paper presents HisTor , a privacy-preserving statistics collection scheme based on ( , δ)-differential privacy that is robust against adversarial manipulation. We formalize the security guarantees of HisTor and show using historical data from the Tor Project that HisTor provides useful data collection and reporting with low bandwidth and processing overheads. 2 HisTor is pronounced as "history." Permission to freely reproduce all or part of this paper for noncommercial purposes is granted provided that copies bear this notice and the full citation on the first page. Reproduction for commercial purposes is strictly prohibited without the prior written consent of the Internet Society, the first-named author (for reproduction of an entire paper only), and the author's employer if the paper was prepared within the scope of employment.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper7
- Distributed Measurement with Private Set-Union CardinalityEllis Fenske, Akshaya Mani, Aaron Johnson, Micah SherrCCS 2017 · 被引用 27 次
- Privacy-Preserving Dynamic Learning of Tor Network TrafficRob Jansen, Matthew Traudt, Nicholas HopperCCS 2018 · 被引用 26 次
- How to Make Private Distributed Cardinality Estimation Practical, and Get Differential Privacy for FreeChanghui Hu, Jin Li, Zheli Liu, Xiaojie Guo 等USENIX Security 2021 · 被引用 22 次
- Once is Never Enough: Foundations for Sound Statistical Inference in Tor Network ExperimentationRob Jansen, Justin Tracey, Ian GoldbergUSENIX Security 2021 · 被引用 21 次
- Characterizing the Nature and Dynamics of Tor Exit BlockingRachee Singh, Rishab Nithyanand, Sadia Afroz, Paul Pearce 等USENIX Security 2017 · 被引用 6 次
它引用的顶会 Paper1
相关 Paper
- Ghostor: Toward a Secure Data-Sharing System from Decentralized TrustYuncong Hu, Sam Kumar, Raluca Ada PopaNSDI 2020 · 被引用 48 次
- Dissecting Tor Bridges: A Security Evaluation of their Private and Public InfrastructuresSrdjan Matic, Carmela Troncoso, Juan CaballeroNDSS 2017 · 被引用 21 次
- Stormy: Statistics in Tor by Measuring SecurelyRyan Wails, Aaron Johnson, Daniel Starin, Arkady Yerukhimovich 等CCS 2019 · 被引用 2 次
- Click Without Compromise: Online Advertising Measurement via Per User Differential PrivacyYingtai Xiao, Jian Du, Shikun Zhang, Wanrong Zhang 等S&P 2025
- Differentially-private software frequency profiling under linear constraintsHailong Zhang, Yu Hao, Sufian Latif, Raef Bassily 等OOPSLA 2020 · 被引用 1 次
