iDP隐私保护可被他人选择影响,导致用户隐私暴露风险上升。
Your Privacy Depends on Others: Collusion Vulnerabilities in Individual Differential Privacy
- iDP机制中个体隐私风险受他人隐私设置影响,非仅自身预算决定。
- 实测显示62%目标用户隐私泄露风险显著升高,攻击者可利用此漏洞。
- 提出新隐私合约,用Δ-散度提供超额风险上限,增强系统可控性。
个体差分隐私(iDP)承诺用户自主掌控隐私,但实际中存在未被重视的共谋漏洞:基于采样的iDP机制虽满足形式隐私保障,但个体隐私风险不仅取决于自身隐私预算,更关键地受所有其他数据贡献者隐私选择的影响。这导致隐私控制承诺与集体决定现实之间产生脱节。我们实证发现,某些隐私偏好分布会无意中放大个体的隐私风险,即使其形式保障达标。此外,这种额外风险可被攻击者利用:中心化或合谋攻击者可刻意选择隐私预算,以放大目标个体的脆弱性。最重要的是,该攻击完全在差分隐私保证范围内进行,隐藏了额外风险。实验表明,对62%的目标个体成功实施了攻击,显著提升其成员推断敏感性。为此,我们提出(ε_i, δ_i, Δ)-iDP隐私契约,使用Δ-散度为用户提供超额风险的硬上限,同时保持机制设计灵活性。研究揭示了当前iDP范式的基本挑战,亟需重新审视iDP系统的架构、审计、沟通与部署方式,以实现超额风险的透明与可控。
原文摘要 · Abstract (English)
Individual Differential Privacy (iDP) promises users control over their privacy, but this promise can be broken in practice. We reveal a previously overlooked vulnerability in sampling-based iDP mechanisms: while conforming to the iDP guarantees, an individual's privacy risk is not solely governed by their own privacy budget, but critically depends on the privacy choices of all other data contributors. This creates a mismatch between the promise of individual privacy control and the reality of a system where risk is collectively determined. We demonstrate empirically that certain distributions of privacy preferences can unintentionally inflate the privacy risk of individuals, even when their formal guarantees are met. Moreover, this excess risk provides an exploitable attack vector. A central adversary or a set of colluding adversaries can deliberately choose privacy budgets to amplify vulnerabilities of targeted individuals. Most importantly, this attack operates entirely within the guarantees of DP, hiding this excess vulnerability. Our empirical evaluation demonstrates successful attacks against 62% of targeted individuals, substantially increasing their membership inference susceptibility. To mitigate this, we propose $(\varepsilon_i,δ_i,\overlineΔ)$-iDP a privacy contract that uses $Δ$-divergences to provide users with a hard upper bound on their excess vulnerability, while offering flexibility to mechanism design. Our findings expose a fundamental challenge to the current paradigm, demanding a re-evaluation of how iDP systems are designed, audited, communicated, and deployed to make excess risks transparent and controllable.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。