Mitigating Data Poisoning Attacks to Local Differential Privacy

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Li, Xiaolin, Li, Ninghui, Wang, Boyang, Sun, Wenhai
Format: Preprint
Published: 2025
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866908409160269824
author Li, Xiaolin
Li, Ninghui
Wang, Boyang
Sun, Wenhai
author_facet Li, Xiaolin
Li, Ninghui
Wang, Boyang
Sun, Wenhai
contents The distributed nature of local differential privacy (LDP) invites data poisoning attacks and poses unforeseen threats to the underlying LDP-supported applications. In this paper, we propose a comprehensive mitigation framework for popular frequency estimation, which contains a suite of novel defenses, including malicious user detection, attack pattern recognition, and damaged utility recovery. In addition to existing attacks, we explore new adaptive adversarial activities for our mitigation design. For detection, we present a new method to precisely identify bogus reports and thus LDP aggregation can be performed over the ``clean'' data. When the attack behavior becomes stealthy and direct filtering out malicious users is difficult, we further propose a detection that can effectively recognize hidden adversarial patterns, thus facilitating the decision-making of service providers. These detection methods require no additional data and attack information and incur minimal computational cost. Our experiment demonstrates their excellent performance and substantial improvement over previous work in various settings. In addition, we conduct an empirical analysis of LDP post-processing for corrupted data recovery and propose a new post-processing method, through which we reveal new insights into protocol recommendations in practice and key design principles for future research.
format Preprint
id arxiv_https___arxiv_org_abs_2506_02156
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle Mitigating Data Poisoning Attacks to Local Differential Privacy
Li, Xiaolin
Li, Ninghui
Wang, Boyang
Sun, Wenhai
Cryptography and Security
The distributed nature of local differential privacy (LDP) invites data poisoning attacks and poses unforeseen threats to the underlying LDP-supported applications. In this paper, we propose a comprehensive mitigation framework for popular frequency estimation, which contains a suite of novel defenses, including malicious user detection, attack pattern recognition, and damaged utility recovery. In addition to existing attacks, we explore new adaptive adversarial activities for our mitigation design. For detection, we present a new method to precisely identify bogus reports and thus LDP aggregation can be performed over the ``clean'' data. When the attack behavior becomes stealthy and direct filtering out malicious users is difficult, we further propose a detection that can effectively recognize hidden adversarial patterns, thus facilitating the decision-making of service providers. These detection methods require no additional data and attack information and incur minimal computational cost. Our experiment demonstrates their excellent performance and substantial improvement over previous work in various settings. In addition, we conduct an empirical analysis of LDP post-processing for corrupted data recovery and propose a new post-processing method, through which we reveal new insights into protocol recommendations in practice and key design principles for future research.
title Mitigating Data Poisoning Attacks to Local Differential Privacy
topic Cryptography and Security
url https://arxiv.org/abs/2506.02156