arXiv:2607.27815stat.MLcs.LG2026-07

提出新方法提升多项目用户在本地差分隐私下的抗攻击能力。

Robust Estimation of Sparse Numerical Vectors under Local Differential Privacy

论文配图:Robust Estimation of Sparse Numerical Vectors under Local Differential Privacy
图 1 · 摘自论文原文
  • 用随机投影+截断保护多项目数据隐私
  • 理论证明误差可控,截断阈值可进一步降低
  • 适合高风险环境中的隐私保护数据分析

本地差分隐私(LDP)协议易受投毒攻击。现有研究针对单项目用户设计了高效防御策略,但在实际中用户常拥有多个数据项。由于输出空间更大,攻击者可实施更隐蔽且强大的攻击。本文解决稀疏向量均值估计的鲁棒性问题,假设每位用户持有含 $m$ 个非零坐标的数据向量。提出随机投影与截断(RPC)方法:服务器向用户发送随机二值向量,用户将本地数据投影并截断以限制攻击者能力。为消除截断带来的偏差,我们基于细致分析提出了精确偏差表达式,无需再权衡偏差与方差,从而可进一步降低截断阈值,缩小输出空间,增强鲁棒性。我们给出了在所有可能攻击下估计误差的严格理论保证。数值实验表明,在可信环境中,本方法性能与现有方法相当或更优;在不可信环境中,对投毒攻击显著更鲁棒。

原文摘要 · Abstract (English)

Local differential privacy (LDP) protocols are vulnerable to poisoning attacks. Existing research have proposed efficient defense strategies for single-item users. However, in practice, a user may possess multiple items. The defense against poisoning attacks for multi-item users is challenging, because due to larger output spaces, the adversary can conduct more powerful attacks without being detected. In this paper, we address the robust sparse vector mean estimation problem, in which each user has a vector with $m$ nonzero coordinates. We propose Randomized Projection with Clipping (RPC). Firstly, the server sends a random binary vector to each user. The user then projects its local data on the vector, and clip the value to restrict the attacker's capability. To handle clipping bias, we propose a correction method based on a careful analysis that gives an exact expression of the bias. As a result, bias-variance tradeoff is no longer needed, thus the clipping threshold can be further reduced to shrink the output space and enhance robustness. We provide a rigorous theoretical guarantee of the estimation error under all possible attacks. Numerical experiments show that under trusted environments, our new method achieves comparable or better performance than existing methods, indicating that our method is already an efficient estimator in its own right. Under untrusted environments, our method is also significantly more robust to poisoning attacks.

隐私保护差分隐私抗攻击稀疏估计

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。