QueryCheetah: Fast Automated Discovery of Attribute Inference Attacks Against Query-Based Systems

Fuente: arXiv
Gespeichert in:
Bibliographische Detailangaben
Hauptverfasser: Stevanoski, Bozhidar, Cretu, Ana-Maria, de Montjoye, Yves-Alexandre
Format: Preprint
Veröffentlicht: 2024
Schlagworte:
Online-Zugang:
Tags: Tag hinzufügen
Keine Tags, Fügen Sie den ersten Tag hinzu!
_version_ 1866912013566869504
author Stevanoski, Bozhidar
Cretu, Ana-Maria
de Montjoye, Yves-Alexandre
author_facet Stevanoski, Bozhidar
Cretu, Ana-Maria
de Montjoye, Yves-Alexandre
contents Query-based systems (QBSs) are one of the key approaches for sharing data. QBSs allow analysts to request aggregate information from a private protected dataset. Attacks are a crucial part of ensuring QBSs are truly privacy-preserving. The development and testing of attacks is however very labor-intensive and unable to cope with the increasing complexity of systems. Automated approaches have been shown to be promising but are currently extremely computationally intensive, limiting their applicability in practice. We here propose QueryCheetah, a fast and effective method for automated discovery of privacy attacks against QBSs. We instantiate QueryCheetah on attribute inference attacks and show it to discover stronger attacks than previous methods while being 18 times faster than the state-of-the-art automated approach. We then show how QueryCheetah allows system developers to thoroughly evaluate the privacy risk, including for various attacker strengths and target individuals. We finally show how QueryCheetah can be used out-of-the-box to find attacks in larger syntaxes and workarounds around ad-hoc defenses.
format Preprint
id arxiv_https___arxiv_org_abs_2409_01992
institution arXiv
publishDate 2024
record_format arxiv
spellingShingle QueryCheetah: Fast Automated Discovery of Attribute Inference Attacks Against Query-Based Systems
Stevanoski, Bozhidar
Cretu, Ana-Maria
de Montjoye, Yves-Alexandre
Cryptography and Security
Artificial Intelligence
Query-based systems (QBSs) are one of the key approaches for sharing data. QBSs allow analysts to request aggregate information from a private protected dataset. Attacks are a crucial part of ensuring QBSs are truly privacy-preserving. The development and testing of attacks is however very labor-intensive and unable to cope with the increasing complexity of systems. Automated approaches have been shown to be promising but are currently extremely computationally intensive, limiting their applicability in practice. We here propose QueryCheetah, a fast and effective method for automated discovery of privacy attacks against QBSs. We instantiate QueryCheetah on attribute inference attacks and show it to discover stronger attacks than previous methods while being 18 times faster than the state-of-the-art automated approach. We then show how QueryCheetah allows system developers to thoroughly evaluate the privacy risk, including for various attacker strengths and target individuals. We finally show how QueryCheetah can be used out-of-the-box to find attacks in larger syntaxes and workarounds around ad-hoc defenses.
title QueryCheetah: Fast Automated Discovery of Attribute Inference Attacks Against Query-Based Systems
topic Cryptography and Security
Artificial Intelligence
url https://arxiv.org/abs/2409.01992