An Attack-Agnostic Defense Framework Against Manipulation Attacks under Local Differential Privacy

IEEE S&P 2025

Puning Zhao1 Zhikun Zhang2 Jiawei Dong2 Jiafei Wu3 Shaowei Wang4 Zhe Liu3 Yunjun Gao2

1. Shenzhen Campus of Sun Yat-sen University 2. Zhejiang University 3. Zhejiang Lab 4. Guangzhou University

Abstract


Protection of local differential privacy (LDP) protocols against manipulation attacks is an important and challenging problem. We design an attack-agnostic framework that does not rely on prior knowledge of attackers. An early work [1] restricts attacker capability by converting each sample into a binary signal. However, this compression causes severe information loss and unnecessary utility degradation, especially when epsilon > 1. In this paper, we propose a general estimation framework, RobustLDP, for robust estimation under LDP. The key idea is to send carefully crafted predefined information to all users and then aggregate their feedback at the server. We strike a better tradeoff between preserving information and restricting attacker capability. We instantiate RobustLDP for frequency estimation and mean estimation in l1 and l2 support, which serve as building blocks for more advanced tasks. We also establish theoretical guarantees for all possible attacks. Results show that our method significantly outperforms the existing one for epsilon > 1. Extensive experiments on multiple real-world datasets validate the effectiveness of our method.

Resources


Citation

 @inproceedings{ZZDWWLG25,
    author = {Puning Zhao and Zhikun Zhang and Jiawei Dong and Jiafei Wu and Shaowei Wang and Zhe Liu and Yunjun Gao},
    title = {{An Attack-Agnostic Defense Framework Against Manipulation Attacks under Local Differential Privacy}},
    booktitle = {{S&P}},
    publisher = {IEEE},
    year = {2025},
}