Towards Robust Fingerprinting of Relational Databases by Mitigating Correlation Attacks

Towards Robust Fingerprinting of Relational Databases by Mitigating Correlation Attacks
复制标题

DOI:
10.1109/tdsc.2022.3191117
复制
发表时间:
2023-07
影响因子:
7.3
通讯作者:
Tianxi Ji;Erman Ayday;Emre Yilmaz;Pan Li
Tianxi Ji;Erman Ayday;Emre Yilmaz;Pan Li
中科院分区:
计算机科学2区
文献类型:
--
作者:
Tianxi Ji;Erman Ayday;Emre Yilmaz;Pan Li

文献摘要

相似文献

数据库指纹被广泛采用,以防止未经授权的数据共享和识别数据泄漏的来源。虽然现有的计划对常见的攻击是强大的,他们的鲁棒性显着下降,如果攻击者利用数据库条目之间的内在相关性。在本文中,我们证明了现有的方案的脆弱性,通过识别不同的相关性攻击:列相关性攻击,行相关性攻击,以及它们的集成。我们通过开发缓解技术来提供针对这些攻击的强大指纹识别,这些技术可以作为任何现成的数据库指纹识别方案的后处理步骤,并保留数据库的实用性。我们使用真实数据库研究相关攻击的影响和缓解技术的性能。我们的研究结果表明:(i)针对现有指纹识别方案的相关攻击的成功率很高(例如,集成相关攻击可以通过仅修改指纹数据库中的14.2%的条目而使64.8%的指纹位失真),以及(i i)减轻技术的高鲁棒性(例如,在减轻之后,综合相关攻击仅能使3%的指纹比特失真)。此外,缓解技术有效地缓解相关性攻击,即使(i)攻击者可以访问从原始数据库直接计算的相关性模型,而数据库所有者使用不准确的相关性模型,(ii)或攻击者利用比数据库所有者更高阶的相关性。
Database fingerprinting is widely adopted to prevent unauthorized data sharing and identify the source of data leakages. Although existing schemes are robust against common attacks, their robustness degrades significantly if attackers utilize inherent correlations among database entries. In this paper, we demonstrate the vulnerability of existing schemes by identifying different correlation attacks: column-wise correlation attack, row-wise correlation attack, and their integration. We provide robust fingerprinting against these attacks by developing mitigation techniques, which can work as post-processing steps for any off-the-shelf database fingerprinting schemes and preserve the utility of databases. We investigate the impact of correlation attacks and the performance of mitigation techniques using a real-world database. Our results show (i) high success rates of correlation attacks against existing fingerprinting schemes (e.g., integrated correlation attack can distort 64.8% fingerprint bits by just modifying 14.2% entries in a fingerprinted database), and (ii) high robustness of mitigation techniques (e.g., after mitigation, integrated correlation attack can only distort 3% fingerprint bits). Additionally, the mitigation techniques effectively alleviate correlation attacks even if (i) attackers have access to correlation models directly computed from the original database, while the database owner uses inaccurate correlation models, (ii) or attackers utilize higher order of correlations than the database owner.