
- Home
高级 检索
Chinese
English



1.中国科学院信息工程研究所,北京 100085
2.中国科学院大学网络空间安全学院,北京 100049
3.网络空间安全防御全国重点实验室,北京 100085
4.西安电子科技大学网络与信息安全学院,陕西 西安 710126
Received:03 June 2026,
Revised:2026-07-06,
Accepted:06 July 2026,
Published:25 August 2026
移动端阅览
田月池,彭锦钰,李效光等.数据流场景下内存受限本地差分隐私协议鲁棒性评估与增强[J].通信学报,2026,47(08):60-77.
Tian Yuechi,Peng Jinyu,Li Xiaoguang,et al.Evaluating and enhancing the robustness of memory-bounded LDP protocols for streaming data[J].Journal on Communications,2026,47(08):60-77.
田月池,彭锦钰,李效光等.数据流场景下内存受限本地差分隐私协议鲁棒性评估与增强[J].通信学报,2026,47(08):60-77. DOI: 10.11959/j.issn.1000-436x.TXXB260318.
Tian Yuechi,Peng Jinyu,Li Xiaoguang,et al.Evaluating and enhancing the robustness of memory-bounded LDP protocols for streaming data[J].Journal on Communications,2026,47(08):60-77. DOI: 10.11959/j.issn.1000-436x.TXXB260318.
本地差分隐私(LDP)因其本地扰动的特性易受数据投毒攻击,现有研究多聚焦于静态数据协议,对内存受限场景下采用域压缩技术的流式数据采集分析协议鲁棒性研究不足。针对BGR、DSR、BDR、CNR这4种主流LDP流式高频项识别协议展开研究。首先,提出一种攻击驱动的鲁棒性评估框架,设计基于最大化频率提升的数据投毒攻击,通过分析协议对该攻击的抵抗性来评估协议的鲁棒性。其次,将攻击成功率(ASR)作为评估指标,在3个现实数据集上评估发现DSR协议鲁棒性最高;同时,发现存储空间大小依然对协议鲁棒性有显著影响。最后,提出一种基于分布一致性的攻击检测方案,不依赖具体协议设计,通过数据频率重建技术解决受限内存下全域频率缺失的问题。实验表明,该方案在低隐私预算或高投毒比例下检测效果显著。
Local differential privacy (LDP) is vulnerable to data poisoning attacks
yet the robustness of memory-bounded streaming data protocols with domain compression remains understudies. Four mainstream LDP streaming frequent item identification protocols (BGR
DSR
BDR
and CNR) were investigated. Firstly
an attack-driven evaluation framework was proposed
and a data poisoning attack maximizing frequency gain was designed. Secondly
using attack success rate (ASR) as the evaluation metric
experiments on three datasets showed that DSR was the most robust protocol
and storage size significantly impacts robustness. Finally
a protocol-agnostic attack detection scheme based on distribution consistency was proposed
utilizing data frequency reconstruction to address missing global frequencies. Experimental results demonstrate that the proposed scheme achieves significant detection performance under low privacy budgets or high poisoning ratios.
Erlingsson Ú , Pihur V , Korolova A . RAPPOR: randomized aggregatable privacy-preserving ordinal response [C ] // Proceedings of the 2014 ACM SIGSAC Conference on Computer and Communications Security . New York : ACM Press , 2014 : 1054 - 1067 .
Apple Differential Privacy Team . Learning with privacy at scale [R ] . (2017-12-06) [2026-06-03 ] .
Ding B L , Kulkarni J , Yekhanin S . Collecting telemetry data privately [C ] // Proceedings of the 31st International Conference on Neural Information Processing Systems . New York : ACM Press , 2017 : 3574 - 3583 .
Cheu A , Smith A , Ullman J . Manipulation attacks in local differential privacy [C ] // Proceedings of the 2021 IEEE Symposium on Security and Privacy (SP) . Piscataway : IEEE Press , 2021 : 883 - 900 .
Cao X , Jia J , Gong N Z . Data poisoning attacks to local differential privacy protocols [C ] // Proceedings of the 30th USENIX Conference on Security Symposium . Berkeley : USENIX Association , 2021 : 947 – 964 .
Li X G , Li N H , Sun W H , et al . Fine-grained poisoning attack to local differential privacy protocols for mean and variance estimation [C ] // Proceedings of the 32nd USENIX Conference on Security Symposium . New York : ACM Press , 2023 : 1739 - 1756 .
Li X G , Li Z T , Li N H , et al . On the robustness of LDP protocols for numerical attributes under data poisoning attacks [C ] // Proceedings 2025 Network and Distributed System Security Symposium . Piscataway : IEEE Press , 2025 : 1 - 15 .
Wu Y , Cao X , Jia J , et al . Poisoning attacks to local differential privacy protocols for key-value data [C ] // Proceedings of the 31st USENIX Conference on Security Symposium . Berkeley : USENIX Association , 2022 : 535 - 552 .
Li X C , Liu W R , Lou J , et al . Local differentially private heavy hitter detection in data streams with bounded memory [J ] . Proceedings of the ACM on Management of Data , 2024 , 2 ( 1 ): 1 - 27 .
Li W H . Pandora: an efficient and rapid solution for persistence-based tasks in high-speed data streams [J ] . Proceedings of the ACM on Management of Data , 2025 , 3 ( 1 ): 1 - 26 .
Bao E , Yang Y , Xiao X K , et al . CGM: an enhanced mechanism for streaming data collection with local differential privacy [J ] . Proceedings of the VLDB Endowment , 2021 , 14 ( 11 ): 2258 - 2270 .
Joseph M , Roth A , Ullman J , et al . Local differential privacy for evolving data [C ] // Proceedings of the 32nd International Conference on Neural Information Processing Systems . New York : ACM Press , 2018 : 2381 - 2390 .
Ren X B , Shi L , Yu W R , et al . LDP-IDS: local differential privacy for infinite data streams [C ] // Proceedings of the 2022 International Conference on Management of Data . New York : ACM Press , 2022 : 1064 - 1077 .
Wang T H , Chen J Q , Zhang Z K , et al . Continuous release of data streams under both centralized and local differential privacy [C ] // Proceedings of the 2021 ACM SIGSAC Conference on Computer and Communications Security . New York : ACM Press , 2021 : 1237 - 1253 .
Sánchez-Macián A , Martínez J , Reviriego P , et al . On the privacy of the count-min sketch: extracting the top-K elements [J ] . IEEE Transactions on Emerging Topics in Computing , 2024 , 12 ( 4 ): 1056 - 1065 .
Wang X J , Mo L , Guo L K , et al . Online streaming sampling publication method over sliding windows with differential privacy [J ] . IEEE Transactions on Dependable and Secure Computing , 2025 , 22 ( 6 ): 6896 - 6912 .
Li J Z , Li Z K , Xu Y F , et al . WavingSketch: an unbiased and generic sketch for finding top-k items in data streams [C ] // Proceedings of the 26th ACM SIGKDD International Conference on Knowledge Discovery & Data Mining . New York : ACM Press , 2020 : 1574 - 1584 .
Yang T , Jiang J , Liu P , et al . Elastic sketch: adaptive and fast network-wide measurements [C ] // Proceedings of the 2018 Conference of the ACM Special Interest Group on Data Communication . New York : ACM Press , 2018 : 561 - 575 .
Metwally A , Agrawal D , Abbadi A E . Efficient computation of frequent and top-k elements in data streams [M ] . Berlin : Springer , 2004 .
Li X Y , Ren X B , Yang S S , et al . Fine-grained manipulation attacks to local differential privacy protocols for data streams [J ] . IEEE Transactions on Knowledge and Data Engineering , 2026 , 38 ( 3 ): 1768 - 1782 .
Duchi J C , Jordan M I , Wainwright M J . Local privacy and statistical minimax rates [C ] // Proceedings of the 2013 IEEE 54th Annual Symposium on Foundations of Computer Science . Piscataway : IEEE Press , 2013 : 429 - 438 .
Dwork C , Naor M , Pitassi T , et al . Differential privacy under continual observation [C ] // Proceedings of the Forty-Second ACM Symposium on Theory of Computing . New York : ACM Press , 2010 : 715 - 724 .
Wang T H , Blocki J , Li N H , et al . Locally differentially private protocols for frequency estimation [C ] // Proceedings of the 26th USENIX Conference on Security Symposium . New York : ACM Press , 2017 : 729 - 745 .
Feng W Q , Gao J Q , Chen X Q , et al . F3: fast and flexible network telemetry with an FPGA coprocessor [J ] . Proceedings of the ACM on Networking , 2024 , 2 ( 4 ): 1 - 22 .
Liang J C , Du Y , Huang H , et al . Memory-efficient and hardware-friendly sketches for hierarchical heavy hitter detection [J ] . IEEE Transactions on Network and Service Management , 2026 , 23 : 582 - 593 .
Jarlow V , Stylianopoulos C , Papatriantafilou M . QPOPSS: query and parallelism optimized space-saving for finding frequent stream elements [J ] . Journal of Parallel and Distributed Computing , 2025 , 204 : 105134 .
Ma T Y , Gao G J , Huang H , et al . Scout sketch: finding promising items in data streams [C ] // Proceedings of the IEEE INFOCOM 2024 - IEEE Conference on Computer Communications . Piscataway : IEEE Press , 2024 : 1561 - 1570 .
Yang T , Gong J Z , Zhang H W , et al . HeavyGuardian: separate and guard hot items in data streams [C ] // Proceedings of the 24th ACM SIGKDD International Conference on Knowledge Discovery & Data Mining . New York : ACM Press , 2018 : 2584 - 2593 .
Massey F J J . The Kolmogorov-Smirnov test for goodness of fit [J ] . Journal of the American Statistical Association , 1951 , 46 ( 253 ): 68 - 78 .
Wasserman L . All of statistics: a concise course in statistical inference [M ] . New York : Springer New York , 2004 .
0
Views
28
下载量
0
CSCD
Publicity Resources
Related Articles
Related Author
Related Institution
京公网安备11010602201714号