Preventing Manipulation Attack in Local Differential Privacy using Verifiable Randomization Mechanism

Preventing Manipulation Attack in Local Differential Privacy using Verifiable Randomization Mechanism
复制标题

DOI:
10.1007/978-3-030-81242-3_3
复制
发表时间:
2021-04
期刊:
ArXiv
影响因子:
--
通讯作者:
Fumiyuki Kato;Yang Cao;Masatoshi Yoshikawa
Fumiyuki Kato;Yang Cao;Masatoshi Yoshikawa
中科院分区:
其他
文献类型:
--
作者:
Fumiyuki Kato;Yang Cao;Masatoshi Yoshikawa

文献摘要

相似文献

本地差分隐私(LDP)作为一种无需可信服务器的正式隐私定义,受到越来越多的关注。在典型的 LDP 协议中,客户端在将数据发送到服务器进行分析之前,使用随机机制在本地扰乱数据。自民党文献中的许多研究都隐含地假设客户诚实地遵守协议;然而,最近的两项研究表明,LDP 通常容易受到恶意客户端的攻击。曹等人。 (USENIX Security ’21) 和 Cheu 等人。 (IEEE S&P ’21) 证明,恶意客户端可以通过向服务器发送虚假数据来有效地扭曲分析(例如频率估计),这被称为针对 LDP 的数据中毒攻击或操纵攻击。在本文中,我们提出了安全高效的可验证 LDP 协议来防止操纵攻击。具体来说,我们利用加密随机响应技术 (CRRT) 作为构建块,将现有的 LDP 机制转换为可验证的版本。这样,服务器可以在不牺牲本地隐私的情况下验证客户端执行约定的随机化机制的完整性。我们提出的方法可以完全保护 LDP 协议免受输出操纵攻击,并以可接受的计算开销显着减轻恶意客户端的意外损害。
Local differential privacy (LDP) has been received increasing attention as a formal privacy definition without a trusted server. In a typical LDP protocol, the clients perturb their data locally with a randomized mechanism before sending it to the server for analysis. Many studies in the literature of LDP implicitly assume that the clients honestly follow the protocol; however, two recent studies show that LDP is generally vulnerable under malicious clients. Cao et al. (USENIX Security ’21) and Cheu et al. (IEEE S&P ’21) demonstrated that the malicious clients could effectively skew the analysis (such as frequency estimation) by sending fake data to the server, which is called data poisoning attack or manipulation attack against LDP. In this paper, we propose secure and efficient verifiable LDP protocols to prevent manipulation attacks. Specifically, we leverage Cryptographic Randomized Response Technique (CRRT) as a building block to convert existing LDP mechanisms into a verifiable version. In this way, the server can verify the completeness of executing an agreed randomization mechanism on the client side without sacrificing local privacy. Our proposed method can completely protect the LDP protocol from output manipulation attacks, and significantly mitigates unexpected damage from malicious clients with acceptable computational overhead.