AI 中文总结
本文针对多方差分隐私的连续噪声采样协议,发现采样-缩放构造的安全漏洞并发起高成功率攻击,提出基于离散偏置位采样的优化方案,实现高效安全且效用损失小的噪声采样。
AI 中文摘要
将安全多方计算(MPC)与差分隐私(DP)相结合,可让多方在无需可信 curator 的情况下发布聚合统计数据,核心基础是在有限精度算术下从连续分布中采样噪声的协议。本文重新审视连续噪声采样协议,在安全性和效率方面提出多项改进。我们首先发现广泛使用的采样-缩放构造存在漏洞:算术电路中的缩放操作将噪声限制在稀疏的、公开已知的值集合中,攻击者可通过观测发布的带噪查询,判断出产生它们的数据集。作为具体演示,我们对采用此类“有缺陷”采样协议的两个系统发起攻击:用于 DP 安全聚合的 Orchard(OSDI'20)和用于 DP 联邦学习的 DP-BREM⁺(USENIX Sec'25)。在实践中使用的任何噪声缩放器 s≥2 条件下,我们对两个系统的攻击成功率均接近 100%。我们揭示的漏洞是缩放操作固有的,直接修复要么会大幅牺牲效用,要么需添加大量精度位使采样成本显著增加。为同时解决安全性和效率问题,我们转向以单个偏置位粒度进行离散采样,对采样器进行多项优化并证明其安全性。我们的实现比现有安全离散采样器实现 4 倍至 612 倍的加速,比不安全的采样-缩放范式实现数个数量级的加速,且与理想连续机制相比效用损失可忽略不计。
英文摘要
Combining secure multi-party computation (MPC) with differential privacy (DP) enables multiple parties to release aggregate statistics without a trusted curator, and the core primitive is the protocol to sample noise from a continuous distribution under finite-precision arithmetic. In this paper, we revisit the continuous noise sampling protocols and present several improvements in both security and efficiency. We start by identifying a vulnerability in widely used sample-and-scale constructions. We demonstrate that the scaling operation in arithmetic circuits confines the noise to a sparse, publicly known set of values, so that an adversary can observe the released noisy queries and decide which dataset produced them. As concrete demonstrations, we instantiate attacks on two systems employing such ``flawed'' sampling protocols: Orchard (OSDI'20) for DP secure aggregation and DP-BREM$^+$ (USENIX Sec'25) for DP federated learning. We report a near-$100\%$ attack success rate on both systems, under any noise scaler $s\geq 2$ used in practice. The leakage we reveal is intrinsic to the scaling operation, and direct repairs either substantially sacrifice utility or add significant precision bits to make the sampling more expensive. To address the security and efficiency issues together, we turn to discrete sampling at the granularity of individual biased bits. We make several optimizations to the sampler and prove its security. Our implementation achieves $4\times \sim 612\times$ speedup over existing secure discrete samplers and orders-of-magnitude speedup over the insecure sample-and-scale paradigm, with negligible utility loss compared to the ideal continuous mechanism.