TY - JOUR
T1 - Fine-Grained Manipulation Attacks to Local Differential Privacy Protocols for Data Streams
AU - Li, Xinyu
AU - Ren, Xuebin
AU - Yang, Shusen
AU - Shi, Liang
AU - Yu, Chia Mu
AU - Han, Qing
N1 - Publisher Copyright:
© 1989-2012 IEEE.
PY - 2026
Y1 - 2026
N2 - Local Differential Privacy (LDP) enables massive data collection and analysis while protecting end users’ privacy against untrusted aggregators. It has been applied to various data types (e.g., categorical, numerical, and graph data) and application settings (e.g., static and streaming). Recent findings indicate that LDP protocols can be easily disrupted by poisoning or manipulation attacks, where an attacker can leverage injected/corrupted fake users to send crafted data to the aggregator in order to manipulate the final estimate of the aggregator. However, current attacks primarily target static protocols, neglecting the security of LDP protocols in the streaming settings. Our research fills the gap by developing novel fine-grained manipulation attacks to LDP protocols for data streams. By reviewing the attack surfaces in existing algorithms, we introduce a unified attack framework with composable modules, which can manipulate the LDP estimated stream toward a target stream. Our attack framework can adapt to state-of-the-art streaming LDP algorithms with different analytic tasks (e.g., frequency and mean) and LDP models (event-level, user-level, w-event level). We verify our attacks theoretically and validate them through extensive experiments on real-world datasets. Finally, we explore a possible defense mechanism for mitigating our attacks.
AB - Local Differential Privacy (LDP) enables massive data collection and analysis while protecting end users’ privacy against untrusted aggregators. It has been applied to various data types (e.g., categorical, numerical, and graph data) and application settings (e.g., static and streaming). Recent findings indicate that LDP protocols can be easily disrupted by poisoning or manipulation attacks, where an attacker can leverage injected/corrupted fake users to send crafted data to the aggregator in order to manipulate the final estimate of the aggregator. However, current attacks primarily target static protocols, neglecting the security of LDP protocols in the streaming settings. Our research fills the gap by developing novel fine-grained manipulation attacks to LDP protocols for data streams. By reviewing the attack surfaces in existing algorithms, we introduce a unified attack framework with composable modules, which can manipulate the LDP estimated stream toward a target stream. Our attack framework can adapt to state-of-the-art streaming LDP algorithms with different analytic tasks (e.g., frequency and mean) and LDP models (event-level, user-level, w-event level). We verify our attacks theoretically and validate them through extensive experiments on real-world datasets. Finally, we explore a possible defense mechanism for mitigating our attacks.
KW - data streams
KW - fine-grained manipulation
KW - Local differential privacy
KW - poisoning attack
UR - https://www.scopus.com/pages/publications/105028012098
U2 - 10.1109/TKDE.2026.3652139
DO - 10.1109/TKDE.2026.3652139
M3 - 文章
AN - SCOPUS:105028012098
SN - 1041-4347
VL - 38
SP - 1768
EP - 1782
JO - IEEE Transactions on Knowledge and Data Engineering
JF - IEEE Transactions on Knowledge and Data Engineering
IS - 3
ER -