TY - GEN
T1 - Data Poisoning in Longitudinal Local Differential Privacy
T2 - 40th IFIP WG 11.3 Annual Conference on Data and Applications Security and Privacy, DBSec 2026
AU - Marreiras Neto, Antônio A.
AU - Arcolezi, Héber H.
AU - Machado, Javam C.
N1 - Publisher Copyright:
© IFIP International Federation for Information Processing 2026.
PY - 2026
Y1 - 2026
N2 - Local Differential Privacy (LDP) is widely deployed for large-scale telemetry, particularly for frequency monitoring. In practice, these systems operate in a longitudinal setting, where data is repeatedly collected using mechanisms such as memoization and two-round sanitization to control cumulative privacy loss. While prior work has shown that single-round LDP protocols are vulnerable to data poisoning attacks, the robustness of longitudinal LDP remains largely unexplored. In this work, we provide the first systematic analysis of data poisoning in longitudinal LDP frequency estimation. We extend existing attack models to two-round protocols and derive closed-form expressions for expected attack gain under unbiased estimation, highlighting the role of longitudinal parameters and encoding mechanisms. We further propose the Memoized Target Attack (MTA), a novel poisoning attack which exploits memoization to induce persistent and stealthier bias. Experiments across multiple protocols and datasets show that encoding mechanisms dominate robustness, and that longitudinal statefulness fundamentally reshapes the attack–defense tradeoff. We also evaluate defenses and introduce a timestamp-assisted extension of frequent-itemset anomaly detection tailored to longitudinal settings. Our results provide the first characterization of adversarial robustness in widely used longitudinal LDP systems.
AB - Local Differential Privacy (LDP) is widely deployed for large-scale telemetry, particularly for frequency monitoring. In practice, these systems operate in a longitudinal setting, where data is repeatedly collected using mechanisms such as memoization and two-round sanitization to control cumulative privacy loss. While prior work has shown that single-round LDP protocols are vulnerable to data poisoning attacks, the robustness of longitudinal LDP remains largely unexplored. In this work, we provide the first systematic analysis of data poisoning in longitudinal LDP frequency estimation. We extend existing attack models to two-round protocols and derive closed-form expressions for expected attack gain under unbiased estimation, highlighting the role of longitudinal parameters and encoding mechanisms. We further propose the Memoized Target Attack (MTA), a novel poisoning attack which exploits memoization to induce persistent and stealthier bias. Experiments across multiple protocols and datasets show that encoding mechanisms dominate robustness, and that longitudinal statefulness fundamentally reshapes the attack–defense tradeoff. We also evaluate defenses and introduce a timestamp-assisted extension of frequent-itemset anomaly detection tailored to longitudinal settings. Our results provide the first characterization of adversarial robustness in widely used longitudinal LDP systems.
KW - Adversarial Robustness
KW - Data Poisoning attacks
KW - Frequency Estimation
KW - Local differential privacy
KW - Longitudinal Data
UR - https://www.scopus.com/pages/publications/105046981821
U2 - 10.1007/978-3-032-33260-8_7
DO - 10.1007/978-3-032-33260-8_7
M3 - Contribution to conference proceedings
AN - SCOPUS:105046981821
SN - 9783032332592
T3 - Lecture Notes in Computer Science
SP - 124
EP - 141
BT - Data and Applications Security and Privacy XL - 40th IFIP WG 11.3 Annual Conference, DBSec 2026, Proceedings
A2 - Palanisamy, Balaji
A2 - Samarati, Pierangela
PB - Springer Science and Business Media Deutschland GmbH
Y2 - 28 July 2026 through 30 July 2026
ER -