Revealing the True Cost of Locally Differentially Private Protocols: An Auditing Perspective
arXiv:2309.01597 · doi:10.56553/popets-2024-0110
Abstract
While the existing literature on Differential Privacy (DP) auditing predominantly focuses on the centralized model (e.g., in auditing the DP-SGD algorithm), we advocate for extending this approach to audit Local DP (LDP). To achieve this, we introduce the LDP-Auditor framework for empirically estimating the privacy loss of locally differentially private mechanisms. This approach leverages recent advances in designing privacy attacks against LDP frequency estimation protocols. More precisely, through the analysis of numerous state-of-the-art LDP protocols, we extensively explore the factors influencing the privacy audit, such as the impact of different encoding and perturbation functions. Additionally, we investigate the influence of the domain size and the theoretical privacy loss parameters and on local privacy estimation. In-depth case studies are also conducted to explore specific aspects of LDP auditing, including distinguishability attacks on LDP protocols for longitudinal studies and multidimensional data. Finally, we present a notable achievement of our LDP-Auditor framework, which is the discovery of a bug in a state-of-the-art LDP Python package. Overall, our LDP-Auditor framework as well as our study offer valuable insights into the sources of randomness and information loss in LDP protocols. These contributions collectively provide a realistic understanding of the local privacy loss, which can help practitioners in selecting the LDP mechanism and privacy parameters that best align with their specific requirements. We open-sourced LDP-Auditor in \url{https://github.com/hharcolezi/ldp-audit}.
Accepted at PETS 2024
References in corpus (24)
- The NumPy array: a structure for efficient numerical computation
- RAPPOR: Randomized Aggregatable Privacy-Preserving Ordinal Response
- Collecting Telemetry Data Privately
- Auditing Differentially Private Machine Learning: How Private is Private SGD?
- Mutual Information Optimally Local Private Discrete Distribution Estimation
- Frequency Estimation under Local Differential Privacy [Experiments, Analysis and Benchmarks]
- Improving the utility of locally differentially private protocols for longitudinal and multidimensional frequency estimates
- Random Sampling Plus Fake Data: Multidimensional Frequency Estimates With Local Differential Privacy
- On the Risks of Collecting Multidimensional Data Under Local Differential Privacy
- Tight Auditing of Differentially Private Machine Learning
- Bayes Security: A Not So Average Metric
- Locality-Sensitive Hashing Does Not Guarantee Privacy! Attacks on Google's FLoC and the MinHash Hierarchy System
- Toward Evaluating Re-identification Risks in the Local Privacy Model
- Debugging Differential Privacy: A Case Study for Privacy Auditing
- Privacy Auditing with One (1) Training Run
- A General Framework for Auditing Differentially Private Machine Learning
- One-shot Empirical Privacy Estimation for Federated Learning
- Pool Inference Attacks on Local Differential Privacy: Quantifying the Privacy Guarantees of Apple's Count Mean Sketch in Practice
- Unleashing the Power of Randomization in Auditing Differentially Private ML
- Castell: Scalable Joint Probability Estimation of Multi-dimensional Data Randomized with Local Differential Privacy
- CANIFE: Crafting Canaries for Empirical Privacy Measurement in Federated Learning
- On the (Im)Possibility of Estimating Various Notions of Differential Privacy
- PANORAMIA: Privacy Auditing of Machine Learning Models without Retraining
- Tighter Privacy Auditing of DP-SGD in the Hidden State Threat Model