Skip to main navigation Skip to search Skip to main content

Data Poisoning in Longitudinal Local Differential Privacy: Attacks and Analysis

  • Universidade Federal do Ceará

Research output: Contribution to Book/Report typesContribution to conference proceedingspeer-review

Abstract

Local Differential Privacy (LDP) is widely deployed for large-scale telemetry, particularly for frequency monitoring. In practice, these systems operate in a longitudinal setting, where data is repeatedly collected using mechanisms such as memoization and two-round sanitization to control cumulative privacy loss. While prior work has shown that single-round LDP protocols are vulnerable to data poisoning attacks, the robustness of longitudinal LDP remains largely unexplored. In this work, we provide the first systematic analysis of data poisoning in longitudinal LDP frequency estimation. We extend existing attack models to two-round protocols and derive closed-form expressions for expected attack gain under unbiased estimation, highlighting the role of longitudinal parameters and encoding mechanisms. We further propose the Memoized Target Attack (MTA), a novel poisoning attack which exploits memoization to induce persistent and stealthier bias. Experiments across multiple protocols and datasets show that encoding mechanisms dominate robustness, and that longitudinal statefulness fundamentally reshapes the attack–defense tradeoff. We also evaluate defenses and introduce a timestamp-assisted extension of frequent-itemset anomaly detection tailored to longitudinal settings. Our results provide the first characterization of adversarial robustness in widely used longitudinal LDP systems.

Original languageEnglish
Title of host publicationData and Applications Security and Privacy XL - 40th IFIP WG 11.3 Annual Conference, DBSec 2026, Proceedings
EditorsBalaji Palanisamy, Pierangela Samarati
PublisherSpringer Science and Business Media Deutschland GmbH
Pages124-141
Number of pages18
ISBN (Print)9783032332592
DOIs
Publication statusPublished - 2026
Event40th IFIP WG 11.3 Annual Conference on Data and Applications Security and Privacy, DBSec 2026 - Arlington, United States
Duration: 28 Jul 202630 Jul 2026

Publication series

NameLecture Notes in Computer Science
Volume16576 LNCS
ISSN (Print)0302-9743
ISSN (Electronic)1611-3349

Conference

Conference40th IFIP WG 11.3 Annual Conference on Data and Applications Security and Privacy, DBSec 2026
Country/TerritoryUnited States
CityArlington
Period28/07/2630/07/26

!!!Keywords

  • Adversarial Robustness
  • Data Poisoning attacks
  • Frequency Estimation
  • Local differential privacy
  • Longitudinal Data

Fingerprint

Dive into the research topics of 'Data Poisoning in Longitudinal Local Differential Privacy: Attacks and Analysis'. These topics are generated from the title and abstract of the publication. Together, they form a unique fingerprint.

Cite this