Experimental study demonstrates stealthy data poisoning attacks in local differential privacy protocols, highlighting critical vulnerabilities in privacy-preserving data aggregation systems.
Local Differential Privacy (LDP) enables users to perturb data locally from the untrusted data collectors. Recent studies validate the vulnerability of LDP to data poisoning attacks where an attacker injects the deliberately crafted data into the LDP protocols to manipulate the results of data analytic tasks. In this work, we advance the knowledge by proposing the disguised data poisoning attack against the three state-of-the-art LDP protocols, i.e., Optimized Unary Encoding, Prefix Extending Method and Piecewise Mechanism, that manipulates the results of three popular data analytic tasks, Frequency Estimation, Heavy Hitter Identification and Mean-Variance Estimation, and moreover can disguise the attack behavior by deeply considering the inherent properties of LDP protocols. The main idea is to bundle the target item with the neighboring items, and leverage the enhancement of the target item to drive sophisticated changes within its neighboring items to maximize the attack gain and disguise the attack behavior. Both the theoretical analysis and the experimental results validate the superior performance of our attack compared to the five existing attacks on five datasets. Furthermore, we explore an defense to mitigate the proposed attack, using the Discrete Cosine Transform, \(α\) sampling and clustering in frequency domain. The extensive results validate the effectiveness of the proposed defense on five datasets in some scenarios, compared to two latest existing defenses. But, in other cases, the proposed defense is not very effective, and thus new defenses in the further are needed.
No takes yet. Share an insight, caveat, or question.
Zhao et al. (2026) studied this question.
Synapse has enriched 5 closely related papers on similar clinical questions. Consider them for comparative context: