Distributed Differential Privacy via Shuffling Versus Aggregation: A Curious Study

被引:2
|
作者
Wei, Yu [1 ,2 ]
Jia, Jingyu [1 ,2 ]
Wu, Yuduo [1 ,2 ]
Hu, Changhui [3 ,4 ]
Dong, Changyu [5 ]
Liu, Zheli [1 ,2 ]
Chen, Xiaofeng [6 ]
Peng, Yun [5 ]
Wang, Shaowei [5 ]
机构
[1] Nankai Univ, Coll Cyber Sci, Tianjin 300350, Peoples R China
[2] Nankai Univ, Coll Comp Sci, Minist Educ, Key Lab Data & Intelligent Syst Secur, Tianjin 300350, Peoples R China
[3] Hainan Univ, Sch Cyberspace Secur, Haikou 570228, Peoples R China
[4] Hainan Univ, Sch Cryptol, Haikou 570228, Peoples R China
[5] Guangzhou Univ, Inst Artificial Intelligence, Guangzhou 511370, Peoples R China
[6] Xidian Univ, Sch Cyber Engn, Xian 710071, Peoples R China
基金
中国国家自然科学基金; 英国工程与自然科学研究理事会;
关键词
Differential privacy; shuffle model; aggregation model; NOISE;
D O I
10.1109/TIFS.2024.3351474
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
How to achieve distributed differential privacy (DP) without a trusted central party is of great interest in both theory and practice. Recently, the shuffle model has attracted much attention. Unlike the local DP model in which the users send randomized data directly to the data collector/analyzer, in the shuffle model an intermediate untrusted shuffler is introduced to randomly permute the data, which have already been randomized by the users, before they reach the analyzer. The most appealing aspect is that while shuffling does not explicitly add more noise to the data, it can make privacy better. The privacy amplification effect in consequence means the users need to add less noise to the data than in the local DP model, but can achieve the same level of differential privacy. Thus, protocols in the shuffle model can provide better accuracy than those in the local DP model. What looks interesting to us is that the architecture of the shuffle model is similar to private aggregation, which has been studied for more than a decade. In private aggregation, locally randomized user data are aggregated by an intermediate untrusted aggregator. Thus, our question is whether aggregation also exhibits some sort of privacy amplification effect? And if so, how good is this "aggregation model" in comparison with the shuffle model. We conducted the first comparative study between the two, covering privacy amplification, functionalities, protocol accuracy, and practicality. The results as yet suggest that the new shuffle model does not have obvious advantages over the old aggregation model. On the contrary, protocols in the aggregation model outperform those in the shuffle model, sometimes significantly, in many aspects.
引用
收藏
页码:2501 / 2516
页数:16
相关论文
共 50 条
  • [1] Distributed Differential Privacy via Shuffling
    Cheu, Albert
    Smith, Adam
    Ullman, Jonathan
    Zeber, David
    Zhilyaev, Maxim
    ADVANCES IN CRYPTOLOGY - EUROCRYPT 2019, PT I, 2019, 11476 : 375 - 403
  • [2] Network Shuffling: Privacy Amplification via Random Walks
    Liew, Seng Pei
    Takahashi, Tsubasa
    Takagi, Shun
    Kato, Fumiyuki
    Cao, Yang
    Yoshikawa, Masatoshi
    PROCEEDINGS OF THE 2022 INTERNATIONAL CONFERENCE ON MANAGEMENT OF DATA (SIGMOD '22), 2022, : 773 - 787
  • [3] Spreading the Privacy Blanket: Differentially Oblivious Shuffling for Differential Privacy
    Gordon, Dov
    Katz, Jonathan
    Liang, Mingyu
    Xu, Jiayu
    APPLIED CRYPTOGRAPHY AND NETWORK SECURITY, ACNS 2022, 2022, 13269 : 501 - 520
  • [4] A Survey on Privacy Enhanced Role Based Data Aggregation via Differential Privacy
    Shaikh, Azharuddin
    Patil, Shruti
    2018 INTERNATIONAL CONFERENCE ON ADVANCES IN COMMUNICATION AND COMPUTING TECHNOLOGY (ICACCT), 2018, : 285 - 290
  • [5] From Bounded to Unbounded: Privacy Amplification via Shuffling with Dummies
    Takagi, Shun
    Kato, Fumiyuki
    Cao, Yang
    Yoshikawa, Masatoshi
    2023 IEEE 36TH COMPUTER SECURITY FOUNDATIONS SYMPOSIUM, CSF, 2023, : 457 - 472
  • [6] Distributed dynamic online learning with differential privacy via measurement
    Chen, Lin
    Ding, Xiaofeng
    Zhou, Pan
    Jin, Hai
    INFORMATION SCIENCES, 2023, 630 : 135 - 157
  • [7] Privacy Amplification via Shuffling: Unified, Simplified, and Tightened
    Wang, Shaowei
    Peng, Yun
    Li, Jin
    Wen, Zikai
    Li, Zhipeng
    Yu, Shiyu
    Wang, Di
    Yang, Wei
    PROCEEDINGS OF THE VLDB ENDOWMENT, 2024, 17 (08): : 1870 - 1883
  • [8] Privacy Amplification via Shuffling for Linear Contextual Bandits
    Garcelon, Evrard
    Chaudhuri, Kamalika
    Perchet, Vianney
    Pirotta, Matteo
    INTERNATIONAL CONFERENCE ON ALGORITHMIC LEARNING THEORY, VOL 167, 2022, 167
  • [9] Guaranteeing Differential Privacy in Distributed Fusion Estimation
    Yan, Xinhao
    Chen, Bo
    Zhang, Yuchen
    Yu, Li
    IEEE TRANSACTIONS ON AEROSPACE AND ELECTRONIC SYSTEMS, 2023, 59 (03) : 3416 - 3423
  • [10] Differential Privacy via Distributionally Robust Optimization
    Selvi, Aras
    Liu, Huikang
    Wiesemann, Wolfram
    OPERATIONS RESEARCH, 2025,