Frequency-guard: defense against data poisoning attacks to local differential privacy protocols

Jingyi Ge, Jianming Wu, Ping Zhao · 2025

Local Differential Privacy (LDP) allows users to perturb data locally before submission to untrusted data aggregators while protecting individual privacy. However, LDP protocols for basic data analytic tasks like frequency estimation and mean-variance estimation are susceptible to data poisoning attacks, where the attacker can compromise statistical estimates through the manipulation of data from fake users. In this work, we propose a frequency-based defense that employs the Discrete Cosine Transform (DCT) to transform the dataset into the frequency domain, focusing on low-frequency components, and then applies a density-based clustering algorithm to identify and eliminate manipulated data segments. Our approach is evaluated on five datasets and the results indicate a significant reduction in the impact of data poisoning attacks compared to existing defenses. The proposed defense demonstrates enhanced accuracy in two fundamental tasks of frequency estimation and mean-variance estimation, offering a robust solution to secure LDP protocols.

Read the paper · More papers on PaperTik