arXiv:2503.07483cs.CRcs.LG2025-03被引 2

提出新型轨迹数据投毒攻击,用少量伪造用户大幅扭曲隐私保护数据

Poisoning Attacks to Local Differential Privacy Protocols for Trajectory Data

  • 设计前缀后缀优化法选择伪造轨迹,降低计算开销
  • 少量伪造用户即可显著提高目标模式出现频率
  • 揭示现有隐私协议漏洞,适合隐私安全研究者参考

轨迹数据记录个体在地理空间中的移动路径,对改善现实应用至关重要,但其收集引发严重隐私担忧。本地差分隐私(LDP)通过让用户在本地扰动数据后再共享,提供隐私保护方案。然而,现有LDP协议易受数据投毒攻击,攻击者可注入虚假数据以操纵聚合结果。本文首次分析了几种典型LDP轨迹协议的脆弱性,提出 extsc{TraP}算法——一种基于前缀-后缀方法的启发式投毒策略,有效优化伪造轨迹选择,显著降低计算复杂度。实验表明,仅需少数伪造用户,即可在扰动后的轨迹数据集中大幅增加目标模式的出现频率。本研究凸显了构建鲁棒防御机制与改进协议设计的紧迫性,以防范恶意篡改。

原文摘要 · Abstract (English)

Trajectory data, which tracks movements through geographic locations, is crucial for improving real-world applications. However, collecting such sensitive data raises considerable privacy concerns. Local differential privacy (LDP) offers a solution by allowing individuals to locally perturb their trajectory data before sharing it. Despite its privacy benefits, LDP protocols are vulnerable to data poisoning attacks, where attackers inject fake data to manipulate aggregated results. In this work, we make the first attempt to analyze vulnerabilities in several representative LDP trajectory protocols. We propose \textsc{TraP}, a heuristic algorithm for data \underline{P}oisoning attacks using a prefix-suffix method to optimize fake \underline{Tra}jectory selection, significantly reducing computational complexity. Our experimental results demonstrate that our attack can substantially increase target pattern occurrences in the perturbed trajectory dataset with few fake users. This study underscores the urgent need for robust defenses and better protocol designs to safeguard LDP trajectory data against malicious manipulation.

隐私保护数据投毒轨迹数据差分隐私

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。