This paper revisits the continuous noise sampling protocols and makes several improvements in both security and efficiency and turns to discrete sampling at the granularity of individual biased bits to address the security and efficiency issues together.
Abstract
Combining secure multi-party computation (MPC) with differential privacy (DP) enables multiple parties to release aggregate statistics without a trusted curator, and the core primitive is the protocol to sample noise from a continuous distribution under finite-precision arithmetic. In this paper, we revisit the continuous noise sampling protocols and present several improvements in both security and efficiency. We start by identifying a vulnerability in widely used sample-and-scale constructions. We demonstrate that the scaling operation in arithmetic circuits confines the noise to a sparse, publicly known set of values, so that an adversary can observe the released noisy queries and decide which dataset produced them. As concrete demonstrations, we instantiate attacks on two systems employing such ``flawed''sampling protocols: Orchard (OSDI'20) for DP secure aggregation and DP-BREM$^+$ (USENIX Sec'25) for DP federated learning. We report a near-$100\%$ attack success rate on both systems, under any noise scaler $s\geq 2$ used in practice. The leakage we reveal is intrinsic to the scaling operation, and direct repairs either substantially sacrifice utility or add significant precision bits to make the sampling more expensive. To address the security and efficiency issues together, we turn to discrete sampling at the granularity of individual biased bits. We make several optimizations to the sampler and prove its security. Our implementation achieves $4\times \sim 612\times$ speedup over existing secure discrete samplers and orders-of-magnitude speedup over the insecure sample-and-scale paradigm, with negligible utility loss compared to the ideal continuous mechanism.
The proposed Secure Multiparty Computation protocol enables collaborative training of linear and logistic regression models while providing formal privacy guarantees for participant data, and adapts the iterative gradient descent algorithm to operate securely over secretly shared vectors.
It is shown that input DP is orthogonal to model confidentiality and that the local-DP premise required for shuffle amplification cannot hold under correctness-bounded noise, and that the leaked spectra enable fingerprinting, lineage attribution, and improved logit-based extraction, while suppressing them destroys infe...
Linear-decomposition attacks can break public-key schemes without recovering the secret algebraic action: when a target public state lies in a known linear span, its decomposition coefficients transfer through the unknown action to reveal the shared value. We study a setting in which the adversary uses only the public...
SVIiT is described as communication-reduced relative to the evaluated MPC baselines rather than universally lightweight, and its present practical scope is primarily high-bandwidth LAN or provider-edge deployments.
Tingting Chen· ICST Transactions on Scalabl...· 0 citations
Private Evolution (PE) generates high-fidelity synthetic data in federated settings without exposing users'raw data. It aggregates clipped user votes over a shared candidate bank into a differentially private histogram, with noise calibrated to the worst-case user contribution. However, it is unclear whether an adversa...
Sai Aparna Aketi, Enayat Ullah, Shripad Gade· 0 citations
We use cookies to run the site and, with your consent, for analytics and to show ads.
See our Cookie Policy.