Unexpected Information Leakage of Differential Privacy Due to the Linear Property of Queries

被引:5
|
作者
Huang, Wen [1 ]
Zhou, Shijie [1 ]
Liao, Yongjian [1 ]
机构
[1] Univ Elect Sci & Technol China, Sch Informat & Software Engn, Chengdu 610054, Peoples R China
关键词
Privacy; Differential privacy; Sensitivity; Correlation; Testing; National Institutes of Health; Switches; Laplace mechanism; membership inference attacks; differential privacy; linear property;
D O I
10.1109/TIFS.2021.3075843
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
Differential privacy is a widely accepted concept of privacy preservation, and the Laplace mechanism is a famous instance of differentially private mechanisms used to deal with numerical data. In this paper, we find that differential privacy does not take the linear property of queries into account, resulting in unexpected information leakage. Specifically, the linear property makes it possible to divide one query into two queries, such as q(D) = q(D-1)+ q(D-2) if D = D-1 boolean OR D-2 and D-1 boolean OR D-2 = phi. If attackers try to obtain an answer to q(D), they can not only issue the query q(D) but also issue q(D-1) and calculate q(D-2) by themselves as long as they know D-2. Through different divisions of one query, attackers can obtain multiple different answers to the same query from differentially private mechanisms. However, from the attackers' perspective and differentially private mechanisms' perspective, the total consumed privacy budget is different if divisions are delicately designed. This difference leads to unexpected information leakage because the privacy budget is the key parameter for controlling the amount of information that is legally released from differentially private mechanisms. To demonstrate unexpected information leakage, we present a membership inference attack against the Laplace mechanism. Specifically, under the constraints of differential privacy, we propose a method for obtaining multiple independent identically distributed samples of answers to queries that satisfy the linear property. The proposed method is based on a linear property and some background knowledge of the attackers. When the background knowledge is sufficient, the proposed method can obtain a sufficient number of samples from differentially private mechanisms such that the total consumed privacy budget can be made unreasonably large. Based on the obtained samples, a hypothesis testing method is used to determine whether a target record is in a target dataset.
引用
收藏
页码:3123 / 3137
页数:15
相关论文
共 50 条
  • [1] Linear Queries Estimation with Local Differential Privacy
    Bassily, Raef
    22ND INTERNATIONAL CONFERENCE ON ARTIFICIAL INTELLIGENCE AND STATISTICS, VOL 89, 2019, 89 : 721 - 729
  • [2] Optimizing Linear Counting Queries Under Differential Privacy
    Li, Chao
    Hay, Michael
    Rastogi, Vibhor
    Miklau, Gerome
    McGregor, Andrew
    PODS 2010: PROCEEDINGS OF THE TWENTY-NINTH ACM SIGMOD-SIGACT-SIGART SYMPOSIUM ON PRINCIPLES OF DATABASE SYSTEMS, 2010, : 123 - 134
  • [3] Differential Privacy and the Fat-Shattering Dimension of Linear Queries
    Roth, Aaron
    APPROXIMATION, RANDOMIZATION, AND COMBINATORIAL OPTIMIZATION: ALGORITHMS AND TECHNIQUES, 2010, 6302 : 683 - 695
  • [4] Optimizing Batch Linear Queries under Exact and Approximate Differential Privacy
    Yuan, Ganzhao
    Zhang, Zhenjie
    Winslett, Marianne
    Xiao, Xiaokui
    Yang, Yin
    Hao, Zhifeng
    ACM TRANSACTIONS ON DATABASE SYSTEMS, 2015, 40 (02):
  • [5] The matrix mechanism: optimizing linear counting queries under differential privacy
    Chao Li
    Gerome Miklau
    Michael Hay
    Andrew McGregor
    Vibhor Rastogi
    The VLDB Journal, 2015, 24 : 757 - 781
  • [6] The matrix mechanism: optimizing linear counting queries under differential privacy
    Li, Chao
    Miklau, Gerome
    Hay, Michael
    McGregor, Andrew
    Rastogi, Vibhor
    VLDB JOURNAL, 2015, 24 (06): : 757 - 781
  • [7] A workload-adaptive mechanism for linear queries under local differential privacy
    McKenna, Ryan
    Maity, Raj Kumar
    Mazumdar, Arya
    Miklau, Gerome
    PROCEEDINGS OF THE VLDB ENDOWMENT, 2020, 13 (11): : 1905 - 1918
  • [8] On the effectiveness of differential privacy to continuous queries
    Department of Mathematics, Indian Institute of Technology Guwahati, Assam, Guwahati
    781039, India
    Serv. Oriented Comput. Appl., 1863,
  • [9] On the effectiveness of differential privacy to continuous queries
    Ghoshal, Puspanjali
    Dhaka, Mohit
    Sairam, Ashok Singh
    SERVICE ORIENTED COMPUTING AND APPLICATIONS, 2024, 18 (04) : 381 - 395
  • [10] GANobfuscator: Mitigating Information Leakage Under GAN via Differential Privacy
    Xu, Chugui
    Ren, Ju
    Zhang, Deyu
    Zhang, Yaoxue
    Qin, Zhan
    Ren, Kui
    IEEE TRANSACTIONS ON INFORMATION FORENSICS AND SECURITY, 2019, 14 (09) : 2358 - 2371