Ping Zhao, Jingyi Ge, Xu Liao, Kejia Sun, Anqi Zhang · ACM Transactions on Knowledge Discovery from Data 2026 · 2026
DOI: 10.1145/3820775
Counts differ because each database indexes a different set of publications. We treat OpenAlex as the canonical count; Google Scholar is not shown (no API, and crawling it violates its ToS).
Local Differential Privacy (LDP) enables users to perturb data locally from the untrusted data collectors. Recent studies validate the vulnerability of LDP to data poisoning attacks where an attacker injects the deliberately crafted data into the LDP protocols to manipulate the results of data analytic tasks. In this work, we advance the knowledge by proposing the disguised data poisoning attack against the three state-of-the-art LDP protocols, i.e., Optimized Unary Encoding, Prefix Extending Method, and Piecewise Mechanism, that manipulates the results of three popular data analytic tasks, Frequency Estimation, Heavy Hitter Identification, and Mean-Variance Estimation, and moreover can disguise the attack behavior by deeply considering the inherent properties of LDP protocols. The main idea is to bundle the target item with the neighboring items, and leverage the enhancement of the target item to drive sophisticated changes within its neighboring items to maximize the attack gain and disguise the attack behavior. Both the theoretical analysis and the experimental results validate the superior performance of our attack compared to the five existing attacks on five datasets. Furthermore, we explore an defense to mitigate the proposed attack, using the Discrete Cosine Transform, \(\alpha\) sampling, and clustering in frequency domain. The extensive results validate the effectiveness of the proposed defense on five datasets in some scenarios, compared to two latest existing defenses. But, in other cases, the proposed defense is not very effective, and thus new defenses in the further are needed.
No comments yet — start the discussion below.