REVIEW 3 cited by
Robustness of Locally Differentially Private Graph Analysis Against Poisoning
Not yet reviewed by Pith; the record is open.
This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.
SPECIMEN: schema-true, not a live event
T0 review · schema-true
One-sentence machine reading of the paper's core claim.
pith:XXXXXXXX · record.json · timestamp
Signed reviews
read the original abstract
Locally differentially private (LDP) graph analysis allows private analysis on a graph that is distributed across multiple users. However, such computations are vulnerable to data poisoning attacks where an adversary can skew the results by submitting malformed data. In this paper, we formally study the impact of poisoning attacks for graph degree estimation protocols under LDP. We make two key technical contributions. First, we observe LDP makes a protocol more vulnerable to poisoning -- the impact of poisoning is worse when the adversary can directly poison their (noisy) responses, rather than their input data. Second, we observe that graph data is naturally redundant -- every edge is shared between two users. Leveraging this data redundancy, we design robust degree estimation protocols under LDP that can significantly reduce the impact of data poisoning and compute degree estimates with high accuracy. We evaluate our proposed robust degree estimation protocols under poisoning attacks on real-world datasets to demonstrate their efficacy in practice.
Forward citations
Cited by 3 Pith papers
-
On Evaluating the Poisoning Robustness of Federated Learning under Local Differential Privacy
Malicious clients can craft LDP-compliant updates that collapse the global model in federated learning, even when the server uses Multi-Krum or trimmed mean aggregation.
-
Don't Hash Me Like That: Exposing and Mitigating Hash-Induced Unfairness in Local Differential Privacy
Hash selection in LDP creates measurable disparities in inference and poisoning vulnerability, and an entropy-filtered OLH variant reduces those disparities, though with added runtime.
-
PoisonCatcher: Revealing and Identifying LDP Poisoning Attacks in IIoT
PoisonCatcher is an aggregator-side LDP poisoning defense that reports F2 scores above 90.7% in identifying poisoned data, but on a weather benchmark and with flawed theoretical support.
Discussion (0). Continue with ORCID to comment.