Robustness evaluation method and system for triangle counting protocol under local differential privacy
By designing attack methods in social networks and evaluating the robustness of the triangle counting protocol, the false alarm strategy of fake users is adjusted according to the sparsity or density of the graph, which solves the problem of insufficient robustness of existing protocols and achieves more accurate statistics and protocol optimization.
Patent Information
- Application Number
- CN202511505722.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-10-21
- Publication Date
- 2026-01-30
AI Technical Summary
Existing triangular counting protocols under local differential privacy are not robust enough against attacks, making them difficult to effectively evaluate and optimize. Attackers can mislead the server's statistical results by modifying data.
The attack method is designed to evaluate the robustness of the triangle counting protocol by randomly selecting fake users in the social network and ordering them to lie about edge information. Different attack strategies are selected according to the sparsity or density of the graph to maximize or minimize the attack effect. The robustness of the protocol is measured by absolute error and relative error.
The robustness of the triangle counting protocol was effectively evaluated, and optimization schemes were provided to improve the protocol's resistance to attacks. By adjusting the false alarm strategy of fake users based on the sparsity or density of the decision graph, the accuracy of statistics and the robustness of the protocol were improved.
Smart Images

Figure CN121435271A_ABST
Abstract
Description
Technical Field
[0001] This invention belongs to the field of data security, specifically relating to a robustness evaluation method and system for a triangle counting protocol under local differential privacy. Background Technology
[0002] As a classic statistical method for graph data, various triangle counting methods can securely and efficiently complete triangle counting statistics while protecting the privacy of individual users, thus laying a solid foundation for analyzing various attributes and corresponding social research in social networks. In these statistical methods, to protect the privacy of users in the social network, the protocol statistics process must satisfy Local Differential Privacy (LDP). That is, each user processes their raw data locally before uploading it to the server for merging and statistics. Due to certain interests, attackers may modify the data uploaded to the server to mislead it into making incorrect statistics. Therefore, the robustness of different counting protocols becomes crucial for accurate statistics. To implement an evaluation mechanism that can detect the robustness of triangle counting protocols, we can draw on existing poisoning attack strategies targeting differential privacy and design attack methods to attack various triangle counting protocols. Specifically, we randomly select some users from all local users to become fake users, and represent the set of all fake users as... The attack manipulates the accuracy of the triangle counting protocol by instructing fake users to misreport the number of edges they possess. The deviation in the server's final triangle count reflects the effectiveness of the attack. The robustness of the triangle counting protocol is evaluated based on the effectiveness of the attack; poor attack effectiveness indicates strong robustness, and vice versa. Based on the robustness evaluation results of various protocols, further analysis can be conducted to identify areas for optimization to improve robustness. Summary of the Invention
[0003] The purpose of this invention is to provide a robustness evaluation method and system for triangle counting protocols under local differential privacy. This invention targets triangle counting protocols in social network graphs and, drawing on existing poisoning attack strategies for differential privacy, designs an attack method to attack various triangle counting protocols. Specifically, it randomly selects some users from all local users to become fake users, and represents the set of all fake users as follows: The attack manipulates the triangle counting protocol by instructing fake users to misreport the number of edges they possess, thus influencing the server's accuracy in calculating the number of triangles. The deviation in the server's final triangle count reflects the effectiveness of the attack. The robustness of the triangle counting protocol is evaluated based on the effectiveness of the attack; a poor attack indicates strong robustness, while a good attack indicates weak robustness, thereby achieving the goal of robustness assessment.
[0004] To achieve the above objectives, the present invention adopts the following technical solution: Robustness evaluation methods for triangle counting protocols under local differential privacy include: Step 1: Select an attack strategy; Consider a scenario involving triangle counting based on local differential privacy on an undirected graph of a social network. Using a real-world social network as a context, each user is treated as a point on the graph, represented as... ,in Indicates the user serial number; when two users and If two points know each other, then there exists an edge between them. ;like ,but By user What it possesses; the entire social network is abstractly represented as an undirected graph. The set of edges in the graph is represented as The point set is represented as There are three users in the entire undirected graph. If all three points know each other, then these three points form a triangle with three sides. The method for counting the number of triangles in an undirected graph of a social network is called a protocol, denoted as [symbol missing]. These agreements are in the diagram The number of triangles counted above is denoted as Suppose that in this undirected social network graph, all users know each other, meaning there is an edge between any two points. In this case, the triangle count in the undirected social network graph is at its maximum value, denoted as . Conversely, assuming the social network is undirected and all users are strangers to each other (i.e., there are no edges between any two points), then the triangle count in the undirected social network is at its minimum, denoted as [missing value]. ; Step 2: Modeling IPA for attack input methods; Based on the attack strategy in step 1, first determine whether the undirected graph of the social network is a sparse or dense graph. If it is determined to be a sparse graph, then instruct all fake users to connect all controllable edges to maximize the triangle count result after the attack, making the triangle count result after the false report as close as possible to the desired result. If the graph is determined to be dense, then all fake users are ordered to disconnect all controllable edges to minimize the triangle count result after the attack, ensuring that the triangle count result after the false report is as close as possible to the desired result. ; Step 3: Modeling OPA for attack output methods; According to the attack strategy in step 1, the attack strategy needs to be determined by judging whether the graph is sparse or dense. If it is determined to be a sparse graph, all fake users are ordered to connect all controllable edges to maximize the triangle count result after the attack. If it is determined to be a dense graph, the fake user with the largest index is ordered to connect all controllable edges, and all fake users except the fake user with the largest index are ordered to cancel all controllable edge connections to minimize the triangle count result after the attack. Step 4: Measure the attack effectiveness and analyze potential optimization solutions; After the attack scheme was determined, input attack IPA and output attack OPA were performed on different triangle counting protocols on the real datasets IMDB and Orkut. The final attack effect of different attack schemes was measured. If the attack effect was better, it indicated that the protocol was less robust; conversely, if the attack effect was worse, it indicated that the protocol was more robust.
[0005] A further improvement of this invention is that, in step 1, the post-attack diagram is represented as follows: The user being attacked is called a fake user, denoted as . Let the set of all edges owned by the fake user at this time be denoted as That is, to find
[0006] Let the edges owned by the fake user before and after the attack be represented as follows: and ; and These represent the number of triangles in the graph before and after the attack that contain edges affected by the fake user; and Let represent the number of triangles completely unaffected by the fake users before and after the attack; the total number of triangles is a combination of whether or not they were affected by the fake users, so the formula simplifies to...
[0007] The number of triangles that were completely unaffected by the fake users before and after the attack will not be affected, indicating that... and They are equal, and this equation can be further simplified to:
[0008] The goal of the attack is to make the final calculation result of the above equation equal to... The absolute value of the difference is the smallest.
[0009] A further improvement of this invention is that, in step 1, the evaluator determines a further attack strategy based on whether the graph used in the actual application is a sparse or dense graph, including: Step 1.1: If the graph used in the actual application is determined to be a sparse graph, since the number of edges controlled by the user in the original graph is relatively small, in order to widen the difference in the number of triangles before and after the attack, the strategy is to increase the number of fake user-controlled edges in the undirected graph to widen this difference, that is, to let... and maximizing the triangle counting results The absolute value of the difference is minimized, thus maximizing the impact of the attack; Step 1.2: If the graph used in the actual application is determined to be a dense graph, since the number of edges controlled by the user in the original graph is relatively large, the strategy is changed to reduce the number of edges controlled by the fake user in the undirected graph to increase the difference in the number of triangles before and after the attack, i.e., let... and the minimized triangle counting results The absolute value of the difference is minimized, thereby maximizing the impact of the attack.
[0010] A further improvement of this invention is that the attack input scheme in step 2 determines whether the graph is sparse or dense, and estimates... Determine the quantity; based on and The actual meaning is that, based on the number of edges controlled by fake users, they are divided into three categories, denoted by subscripts representing the number of edges controlled by fake users, as follows: Sort the three points of the triangle in ascending order of their index numbers. , In the edge set The middle belongs to the point The edge, with Represents graph density, Indicates that all serial numbers are compared Large points; Represented as
[0011] Represented as
[0012] The triangle shown can be directly counted by fake users because all three sides are controlled by them; the attack result will be shown in the image below. And the original image The estimate can be obtained by adding the three variables calculated in the previous step. and Then, based on the estimation results, a determination is made between dense and sparse graphs; if If the graph is large enough, it is considered a sparse graph; otherwise, it is considered a dense graph.
[0013] A further improvement of this invention lies in that, in the attack output scheme of step 3, a determination is made between sparse and dense graphs, wherein the result is obtained through estimation. , and The value is used to determine the result; where This means: Selecting the user with the highest label from all fake users and connecting them to all controllable edges, while disconnecting all controllable edges for the remaining fake users, this results in the final graph containing triangles with edges controlled by the fake users. This represents an estimate of the number of triangles, initialized to 0. Let each triplet represent any combination of three points, sorted in ascending order. Assuming these triplets can form a virtual triangle, the actual number of virtual triangles is estimated by comparing the number of edges controlled by the dummy user within the virtual triangle with the number of connected variables in the real world. Finally, by iterating through all triplets, the estimated number of triangles can be obtained. ,according to , and The actual meaning is to iterate through the triples to estimate their values; based on the estimation results, determine whether it is a dense or sparse graph; if If the graph is sparse, then it is classified as a sparse graph; otherwise, it is classified as a dense graph.
[0014] A further improvement of the present invention is that all ternary components are divided into three categories: all three edges are controlled by fake users, two edges are controlled by fake users, and only one edge is controlled by fake users. Step 3.1: If all three sides of the virtual triangle are controlled by the fake user, that is, the two larger points... All are fake users; therefore, if the actual number of connected edges is 3, then in the number of triangles... Add to If the actual number of connected edges is 2, then in Reduce If the actual number of connected edges is 1, then in Add to If there are actually no edges connecting them, then in Reduce by 1; Step 3.2: If two sides of the virtual triangle are controlled by the fake user, i.e., the largest point... These are fake users, and the second largest point... This does not belong to a fake user; if the actual number of connected edges is 2, then in Add to If the actual number of connected edges is 1, then in Reduce If there are actually no edges connecting them, then in Add to ; Step 3.3: If only one edge of the virtual triangle is controlled by the fake user, that is, the largest point... They are not fake users, and this is the second largest point. This belongs to a fake user; if the actual number of connected edges is 1, then in Add to If there are actually no edges connecting them, then in Reduce .
[0015] A further improvement of this invention lies in the analysis of attack effectiveness practices and potential optimization methods in step 4, and the selection of attack effectiveness measurement indicators; the selection of absolute error. relative error As a metric for measuring attack effectiveness, among which
[0016]
[0017] By calculating the absolute error caused by the attack and relative error To assess the robustness of different protocols.
[0018] A robustness evaluation system for triangular counting protocols under local differential privacy includes: Attack strategy unit selection: Consider the scenario of triangle counting based on local differential privacy on an undirected graph of a social network. Using a real-world social network as the background, each user is treated as a point on the graph, represented as... ,in Indicates the user serial number; when two users and If two points know each other, then there exists an edge between them. ;like ,but By user What it possesses; the entire social network is abstractly represented as an undirected graph. The set of edges in the graph is represented as The point set is represented as There are three users in the entire undirected graph. If all three points know each other, then these three points form a triangle with three sides. The method for counting the number of triangles in an undirected graph of a social network is called a protocol, denoted as [symbol missing]. These agreements are in the diagram The number of triangles counted above is denoted as Suppose that in this undirected social network graph, all users know each other, meaning there is an edge between any two points. In this case, the triangle count in the undirected social network graph is at its maximum value, denoted as . Conversely, assuming the social network is undirected and all users are strangers to each other (i.e., there are no edges between any two points), then the triangle count in the undirected social network is at its minimum, denoted as [missing value]. ; The IPA unit for modeling attack input methods: Based on the attack strategy in the attack strategy selection unit, it first determines whether the undirected graph of the social network is a sparse or dense graph. If it is determined to be a sparse graph, it commands all fake users to connect all controllable edges to maximize the triangle count result after the attack, making the triangle count result after the false alarm as close as possible to the target. If the graph is determined to be dense, then all fake users are ordered to disconnect all controllable edges to minimize the triangle count result after the attack, ensuring that the triangle count result after the false report is as close as possible to the desired result. ; For the modeling of the attack output method, the OPA unit needs to determine the attack strategy by judging whether the graph is sparse or dense, based on the attack strategy in the attack strategy selection unit. If it is determined to be a sparse graph, all fake users are ordered to connect all controllable edges to maximize the triangle count result after the attack. If it is determined to be a dense graph, the fake user with the largest index is ordered to connect all controllable edges, and all fake users except the fake user with the largest index are ordered to cancel all controllable edge connections to minimize the triangle count result after the attack. Unit for measuring attack effectiveness and analyzing potential optimization schemes: After the attack scheme is determined, input attack IPA and output attack OPA are performed on different triangle counting protocols on the real datasets IMDB and Orkut; the final attack effectiveness of different attack schemes is measured. If the attack effectiveness is better, it indicates that the protocol is less robust; conversely, if the attack effectiveness is worse, it indicates that the protocol is more robust.
[0019] A further improvement of this invention is that, in the attack strategy selection unit, the post-attack diagram is represented as follows: The user being attacked is called a fake user, denoted as . Let the set of all edges owned by the fake user at this time be denoted as That is, to find
[0020] Let the edges owned by the fake user before and after the attack be represented as follows: and ; and These represent the number of triangles in the graph before and after the attack that contain edges affected by the fake user; and Let represent the number of triangles completely unaffected by the fake users before and after the attack; the total number of triangles is a combination of whether or not they were affected by the fake users, so the formula simplifies to...
[0021] The number of triangles that were completely unaffected by the fake users before and after the attack will not be affected, indicating that... and They are equal, and this equation can be further simplified to:
[0022] The goal of the attack is to make the final calculation result of the above equation equal to... The absolute value of the difference is the smallest.
[0023] A further improvement of this invention is that, in the attack strategy selection unit, the evaluator determines a further attack strategy based on whether the graph used in the actual application is a sparse graph or a dense graph, including: Step 1.1: If the graph used in the actual application is determined to be a sparse graph, since the number of edges controlled by the user in the original graph is relatively small, in order to widen the difference in the number of triangles before and after the attack, the strategy is to increase the number of fake user-controlled edges in the undirected graph to widen this difference, that is, to let... and maximizing the triangle counting results The absolute value of the difference is minimized, thus maximizing the impact of the attack; Step 1.2: If the graph used in the actual application is determined to be a dense graph, since the number of edges controlled by the user in the original graph is relatively large, the strategy is changed to reduce the number of edges controlled by the fake user in the undirected graph to increase the difference in the number of triangles before and after the attack, i.e., let... and the minimized triangle counting results The absolute value of the difference is minimized, thereby maximizing the impact of the attack.
[0024] Compared with the prior art, the present invention has at least the following beneficial technical effects: This invention provides a robustness evaluation method and system for triangle counting protocols under local differential privacy. Targeting triangle counting protocols in social network graphs, and drawing on existing poisoning attack strategies for differential privacy, an attack method is designed to attack various triangle counting protocols. Specifically, some users are randomly selected from all local users to become fake users, and the set of all fake users is represented as... The attack manipulates the accuracy of the triangle counting protocol by instructing fake users to misreport the number of edges they possess. The deviation in the server's final triangle count reflects the effectiveness of the attack. The robustness of the triangle counting protocol is evaluated based on the effectiveness of the attack; poor attack effectiveness indicates strong robustness, while good attack effectiveness indicates weak robustness, allowing for further analysis and optimization of the protocol to improve robustness.
[0025] Furthermore, the evaluator designed attack methods to maximize the statistical error before and after the attack. By determining whether the graph is dense or sparse, different false alarm strategies for fake users were identified to optimize the attack effect. The attack methods targeting the triangle counting protocol under local differential privacy are divided into two types: attack input and attack output.
[0026] Furthermore, the robustness of each protocol can be determined by the attack results. After evaluating and analyzing the robustness of each protocol, further optimization methods can be designed based on its robustness and attack strategies. The attack methods also provide relevant reference factors, allowing for further reflection and optimization based on the designed attack methods with better results, leading to more robust protocol mechanisms. Attached Figure Description
[0027] To more clearly illustrate the specific embodiments of the present invention or the technical solutions in the prior art, the drawings used in the description of the specific embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are some embodiments of the present invention. For those skilled in the art, other drawings can be obtained from these drawings without creative effort.
[0028] Figure 1 This is a flowchart illustrating the method of the present invention.
[0029] Figure 2 This is a schematic diagram of the logical architecture of the present invention.
[0030] Figure 3 This is a graph showing the trend of attack effectiveness after the privacy budget is changed according to the present invention.
[0031] Figure 4 This is a graph showing the trend of attack effectiveness after changing the proportion of fake users in this invention.
[0032] Figure 5 This is a structural block diagram of the system of the present invention. Detailed Implementation
[0033] In the following description, only certain exemplary embodiments are briefly described. As those skilled in the art will recognize, the described embodiments can be modified in various ways without departing from the spirit or scope of the invention. Therefore, the drawings and description are considered to be exemplary in nature and not restrictive.
[0034] In the description of this invention, it should be understood that, when used in this specification and the appended claims, the terms "comprising" and "including" indicate the presence of the described features, integrals, steps, operations, elements and / or components, but do not exclude the presence or addition of one or more other features, integrals, steps, operations, elements, components and / or collections thereof.
[0035] It should also be understood that the terminology used in this specification is for the purpose of describing particular embodiments only and is not intended to limit the invention. As used in this specification and the appended claims, the singular forms “a,” “an,” and “the” are intended to include the plural forms unless the context clearly indicates otherwise.
[0036] It should also be further understood that the term "and / or" as used in this specification and the appended claims refers to any combination of one or more of the associated listed items and all possible combinations, and includes such combinations.
[0037] The accompanying drawings illustrate various structural schematic diagrams according to embodiments disclosed in this invention. These drawings are not to scale, and some details have been enlarged for clarity, and some details may have been omitted. The shapes of the various regions and layers shown in the drawings, as well as their relative sizes and positional relationships, are merely exemplary and may deviate from reality due to manufacturing tolerances or technical limitations. Furthermore, those skilled in the art can design regions / layers with different shapes, sizes, and relative positions as needed.
[0038] The embodiments of the present invention will now be described in detail with reference to the accompanying drawings.
[0039] Example 1 Reference Figure 1 The robustness evaluation method for the triangular counting protocol under local differential privacy provided in this embodiment specifically includes the following steps: Step 1: Select an attack strategy; First, an effective attack mechanism needs to be designed. To achieve the best possible attack effect, the statistical error after the attack should be maximized. This requires converting the verbal description into a mathematical expression and representing the post-attack graphically as follows: The user being attacked is called a fake user, denoted as . Let the set of all edges owned by the fake user at this time be denoted as That is, to find
[0040] It can be seen that the edges affected before and after the attack are all owned by the fake user. We represent the edges owned by the fake user before and after the attack as follows: and ; and These represent the number of triangles in the graph before and after the attack that contain edges affected by the fake user; and This represents the number of triangles that were completely unaffected by the fake users before and after the attack. By deduction, the total number of triangles is a combination of the two parts: whether or not they were affected by the fake users. Therefore, the objective expression can be simplified to...
[0041] Further reasoning reveals that the number of triangles completely unaffected by the fake users before and after the attack remains unchanged. and Since they are equal, the objective function can be further simplified to:
[0042] The goal of the attack is to maximize the target result. To achieve this strategy, two feasible attack methods can be employed: attack input and attack output. The attack input method is called IPA, which directly modifies the original data uploaded to the server by the fake user, encrypting it according to a privacy protection protocol before uploading it to the server. The attack output method is called OPA, which directly modifies the encrypted data that the fake user intends to upload to the server; this process is not restricted by encryption protocols. The following will model these two attack methods separately.
[0043] At the same time, to determine the attack strategy, it is also necessary to determine whether the graph used in the actual application is a sparse graph or a dense graph. The specific steps are as follows. Step 1.1: If the graph used in the actual application is determined to be a sparse graph, since the number of edges in the original graph is relatively small, in order to increase the difference in the number of triangles before and after the attack, the strategy is to increase the number of edges as much as possible to widen this difference, that is, to make... Make it as large as possible to maximize the impact of the attack; Step 1.2: If the graph used in the actual application is determined to be a dense graph, since there are many edges in the original graph, the strategy changes to minimizing the number of edges to increase the difference in the number of triangles before and after the attack, i.e., making... To minimize the impact of an attack, the target size should be kept as small as possible.
[0044] Step 2: Modeling the attack input method (IPA); Based on the analysis in step 1, to maximize the difference in the number of triangles counted before and after the attack, it is necessary to first determine whether the graph is sparse or dense, and then adopt relevant strategies based on the graph type. The determination method is as follows: If the graph has a certain density, it is considered a sparse graph; otherwise, it is considered a dense graph. Therefore, it is necessary to... and The quantity needs to be estimated. The estimation method is presented below. according to and The actual meaning can be further subdivided into three categories according to the number of edges controlled by fake users, denoted by a subscript representing the number of edges controlled by fake users, as follows: Sort the three points of the triangle in ascending order of their indexes. , In the edge set The middle belongs to the point The edge, with Represents graph density, Indicates that all serial numbers are compared Large points, It can be represented as
[0045] It can be represented as
[0046] The triangle shown has three sides controlled by fake users, allowing the specific number to be directly calculated by the fake users. (The image after the attack is shown.) And the original image The sum of the three variables calculated above will give the value that needs to be estimated. and Then, based on the estimation results, a dense or sparse graph is determined, and the fake users are instructed to falsely report the corresponding results according to the strategy in step 1. If it is determined to be a sparse graph, the false report result is made as large as possible, and all fake users can be instructed to connect all controllable edges; if it is determined to be a dense graph, the false report result is made as small as possible, and all fake users can be instructed to cancel the connection of all controllable edges.
[0047] Step 3: Modeling the attack output method (OPA); Similar to the attack input modeling scheme, based on the analysis in step 1, the attack strategy needs to be determined by judging whether the graph is sparse or dense. The determination method at this point is: if... If the graph is sparse, it is classified as a sparse graph; otherwise, it is classified as a dense graph. and The meaning of is the same as in the previous text. This means that, given the scenario where the user with the highest label among all fake users is selected and all edges they can control are connected, while the remaining fake users have all their controllable edges removed, the final graph contains the number of triangles whose edges are controlled by the fake users. Similarly, to determine the type of graph, it is necessary to... , and Make the corresponding estimates.
[0048] Design the estOPA algorithm for , and Perform an estimation. Use `cnt` to represent the estimated number of triangles, initialized to 0. Let represent any combination of three points, ordered in ascending order. Assuming this triplet can form a triangle, then based on the number of edges controlled by the dummy user in this virtual triangle, all triplets can be divided into three categories. The following estimation method is proposed for each of these three categories based on the actual number of connected edges: Step 3.1: All three sides of the virtual triangle are controlled by the fake user, that is, the two larger points... These are all fake users. So, if the actual number of connected edges is 3, then the number of triangles... Add to If the actual number of connected edges is 2, then in Reduce If the actual number of connected edges is 1, then in Add to If there are actually no edges connecting them, then in Reduce by 1.
[0049] Step 3.2: Two sides of the virtual triangle are controlled by the fake user, i.e., the largest point... These are fake users, and the second largest point... This does not belong to a fake user. If the actual number of connected edges is 2, then in... Add to If the actual number of connected edges is 1, then in Reduce If there are actually no edges connecting them, then in Add to .
[0050] Step 3.3: Only one edge of the virtual triangle is controlled by the fake user, that is, the largest point... They are not fake users, and this is the second largest point. This is a fake user. If the actual number of connected edges is 1, then... Add to If there are actually no edges connecting them, then in Reduce .
[0051] The final estimated number of triangles can be obtained by iterating through all the triples. ,according to , and In practice, the graph is traversed using triples to estimate their values. Based on the estimation results, a dense or sparse graph is determined, and then, according to the strategy in step 1, fake users are instructed to report the corresponding false results. If the graph is determined to be sparse, the false report result is maximized, and all fake users are instructed to connect all controllable edges. If the graph is determined to be dense, the false report result is minimized, and all fake users except the one with the largest index are instructed to unconnect all controllable edges, while the fake user with the largest index connects all controllable edges.
[0052] Step 4: Measure the attack effectiveness and analyze potential optimization solutions; After determining the attack strategy, input attack IPA and output attack OPA were performed on different triangle counting protocols on the real datasets IMDB and Orkut. Absolute error was selected. relative error As a metric for measuring attack effectiveness, among which
[0053]
[0054] By calculating the absolute error caused by the attack and relative error To assess the robustness of different protocols. and The larger the value, the better the attack effect. It has been proven that under the same attack strategy, different protocols exhibit varying degrees of robustness. Furthermore, overall, when faced with attack input strategies, and A smaller value indicates a weaker attack effect and relatively stronger robustness of the protocol; however, when faced with attack output strategies, and A larger value indicates a more effective attack and relatively poor protocol performance. Further optimization solutions can be proposed. For example, considering that most social network graphs in reality are sparse, the corresponding attack strategy is to maximize the number of connections between fake users. Therefore, the degree of fake user nodes will be very high. Before the server performs statistical calculations, nodes with excessively high degrees can be filtered based on their degree, treating them as abnormal nodes that have already been attacked. Ignoring these abnormal nodes during calculations will help improve the accuracy of the final calculations, thereby enhancing the robustness of the protocol.
[0055] In the description of this invention, it should be understood that the term "fake user" refers to a user selected during an attack who will report false information to the server; "local differential privacy" refers to two datasets with only one data inconsistency obtaining probabilistically similar computational results after performing a specified computation; and "robustness evaluation method" refers to the evaluation party judging the robustness of the algorithm by assessing the attack effects of different attack methods on the triangle counting protocol.
[0056] To test the impact of different privacy budgets and the proportion of fake users on the evaluation method, the real-world datasets IMDB and Orkut were used. The data size was set to 10,000, meaning 10,000 nodes and their connecting edges were randomly sampled from all nodes to serve as the graph data for statistics. The attack targets were five classic triangle counting methods from published papers: LocalRR, LocalRR+, Local2Rounds, ARRONes, and Local2Rounds+. The first two methods are single-round counting, while the latter three are two-round counting. In the two-round counting, if an attack output strategy is selected, the number of triangles can be directly modified, leading to an infinitely large attack error. Therefore, in the two-round counting method attack, only the attack input strategy was experimentally verified, not the attack output strategy. The control group was the traditional attack method REA, specifically: regardless of whether the graph is sparse or dense, the fake users' strategy was to select edges that they could control with a 50% probability of connection.
[0057] First, keeping the proportion of fake users constant, we changed the privacy budget and observed the trend of statistical error changes after the attack. Experiments were conducted on two datasets, targeting the LocalRR protocol. The final experimental results are as follows: Figure 3As shown, the larger the privacy budget, the smaller the error caused by the attack. Meanwhile, both IPA (Input Attack Policy) and OPA (Output Attack Policy) are more effective than the control group REA. In the one-round counting protocol, OPA is more effective than IPA. Furthermore, by changing the attack target to other protocols and conducting further experiments, the robustness of different protocols can be determined based on the magnitude of the attack error in different counting protocols. It can be seen that in the one-round counting protocol, LocalRR and LocalRR+ have almost the same robustness; in the two-round protocol, Local2Rounds and Local2Rounds+ also have almost the same robustness, but are generally more robust than ARRONes. Overall, the robustness of the one-round counting protocol is higher than that of the two-round counting protocol.
[0058] Then, keeping the privacy budget unchanged, the proportion of fake users was varied, and the trend of statistical error after the attack was observed. Experiments were conducted on two datasets, again using the LocalRR protocol as the attack target. The final experimental results are as follows: Figure 4 As shown, the higher the proportion of fake users, the greater the error caused by the attack. Meanwhile, both IPA (Input Attack Policy) and OPA (Output Attack Policy) are more effective than the control group REA. In the one-round counting protocol, OPA is more effective than IPA. Furthermore, by changing the attack target to other protocols and conducting further experiments, the robustness of different protocols can be determined based on the magnitude of the error caused by the attack in different counting protocols. It can be seen that in the one-round counting protocol, LocalRR and LocalRR+ have almost the same robustness; in the two-round protocol, Local2Rounds and Local2Rounds+ also have almost the same robustness, but overall, they are more robust than ARRONs. The overall robustness of the one-round counting protocol is higher than that of the two-round counting protocol.
[0059] Reference Figure 2 This invention provides a robustness evaluation method for a triangle counting protocol under local differential privacy. The logical method includes three stages: attack scheme exploration, attack scheme implementation, and attack effect analysis. To improve the effectiveness of the attack strategy, the graph type is first determined—whether it is a dense or sparse graph—before instructing the fake user to select different attack strategies. To facilitate the implementation of the attack scheme, parameters that are difficult to count directly are estimated, simplifying the attack implementation steps, improving the feasibility and effectiveness of the attack, and facilitating subsequent robustness evaluation and analysis.
[0060] Example 2 Reference Figure 5The robustness evaluation system for the triangular counting protocol under local differential privacy provided in this embodiment includes: Attack strategy unit selection: Consider the scenario of triangle counting based on local differential privacy on an undirected graph of a social network. Using a real-world social network as the background, each user is treated as a point on the graph, represented as... ,in Indicates the user serial number; when two users and If two points know each other, then there exists an edge between them. ;like ,but By user What it possesses; the entire social network is abstractly represented as an undirected graph. The set of edges in the graph is represented as The point set is represented as There are three users in the entire undirected graph. If all three points know each other, then these three points form a triangle with three sides. The method for counting the number of triangles in an undirected graph of a social network is called a protocol, denoted as [symbol missing]. These agreements are in the diagram The number of triangles counted above is denoted as Suppose that in this undirected social network graph, all users know each other, meaning there is an edge between any two points. In this case, the triangle count in the undirected social network graph is at its maximum value, denoted as . Conversely, assuming the social network is undirected and all users are strangers to each other (i.e., there are no edges between any two points), then the triangle count in the undirected social network is at its minimum, denoted as [missing value]. ; The IPA unit for modeling attack input methods: Based on the attack strategy in the attack strategy selection unit, it first determines whether the undirected graph of the social network is a sparse or dense graph. If it is determined to be a sparse graph, it commands all fake users to connect all controllable edges to maximize the triangle count result after the attack, making the triangle count result after the false alarm as close as possible to the target. If the graph is determined to be dense, then all fake users are ordered to disconnect all controllable edges to minimize the triangle count result after the attack, ensuring that the triangle count result after the false report is as close as possible to the desired result. ; For the modeling of the attack output method, the OPA unit needs to determine the attack strategy by judging whether the graph is sparse or dense, based on the attack strategy in the attack strategy selection unit. If it is determined to be a sparse graph, all fake users are ordered to connect all controllable edges to maximize the triangle count result after the attack. If it is determined to be a dense graph, the fake user with the largest index is ordered to connect all controllable edges, and all fake users except the fake user with the largest index are ordered to cancel all controllable edge connections to minimize the triangle count result after the attack. Unit for measuring attack effectiveness and analyzing potential optimization schemes: After the attack scheme is determined, input attack IPA and output attack OPA are performed on different triangle counting protocols on the real datasets IMDB and Orkut; the final attack effectiveness of different attack schemes is measured. If the attack effectiveness is better, it indicates that the protocol is less robust; conversely, if the attack effectiveness is worse, it indicates that the protocol is more robust.
[0061] In the attack strategy selection unit of this embodiment, the post-attack graph is represented as follows: The user being attacked is called a fake user, denoted as . Let the set of all edges owned by the fake user at this time be denoted as That is, to find
[0062] Let the edges owned by the fake user before and after the attack be represented as follows: and ; and These represent the number of triangles in the graph before and after the attack that contain edges affected by the fake user; and Let represent the number of triangles completely unaffected by the fake users before and after the attack; the total number of triangles is a combination of whether or not they were affected by the fake users, so the formula simplifies to...
[0063] The number of triangles that were completely unaffected by the fake users before and after the attack will not be affected, indicating that... and They are equal, and this equation can be further simplified to:
[0064] The goal of the attack is to make the final calculation result of the above equation equal to... The absolute value of the difference is the smallest.
[0065] In the attack strategy selection unit of this embodiment, the evaluator determines further attack strategies based on whether the graph used in the actual application is a sparse graph or a dense graph, including: Step 1.1: If the graph used in the actual application is determined to be a sparse graph, since the number of edges controlled by the user in the original graph is relatively small, in order to widen the difference in the number of triangles before and after the attack, the strategy is to increase the number of fake user-controlled edges in the undirected graph to widen this difference, that is, to let... and maximizing the triangle counting results The absolute value of the difference is minimized, thus maximizing the impact of the attack; Step 1.2: If the graph used in the actual application is determined to be a dense graph, since the number of edges controlled by the user in the original graph is relatively large, the strategy is changed to reduce the number of edges controlled by the fake user in the undirected graph to increase the difference in the number of triangles before and after the attack, i.e., let... and the minimized triangle counting results The absolute value of the difference is minimized, thereby maximizing the impact of the attack.
[0066] The foregoing has shown and described the basic principles, main features, and advantages of the present invention. It will be apparent to those skilled in the art that the invention is not limited to the details of the exemplary embodiments described above, and that the invention can be implemented in other specific forms without departing from its spirit or essential characteristics. Therefore, the embodiments should be considered illustrative and non-limiting in all respects, and the scope of the invention is defined by the appended claims rather than the foregoing description. Thus, all variations falling within the meaning and scope of equivalents of the claims are intended to be included within the scope of the invention. No reference numerals in the claims should be construed as limiting the scope of the claims.
[0067] Furthermore, it should be understood that although this specification describes embodiments, not every embodiment contains only one independent technical solution. This narrative style is merely for clarity. Those skilled in the art should consider the specification as a whole, and the technical solutions in each embodiment can be appropriately combined to form other embodiments that can be understood by those skilled in the art. The above content is only for illustrating the technical concept of the present invention and should not be construed as limiting the scope of protection of the present invention. Any modifications made based on the technical concept proposed in this invention shall fall within the scope of protection of the claims of this invention.
Claims
1. A method for robustness evaluation of a triangle counting protocol under local differential privacy, characterized in that, Comprising: Step 1, selecting an attack strategy; Consider the scenario of triangle counting on social network undirected graph based on local differential privacy, taking the social network in the actual scenario as the background, regarding each user as a point on the graph, denoted as , where represents the user serial number; when two users and know each other, there is an edge between the two points; if , then is owned by the user ; the entire social network is abstractly represented as an undirected graph , the edge set of the graph is represented as , and the point set is represented as ; There are three users in the whole undirected graph If each pair of users knows each other, then there are three edges between the three points, forming a triangle; the method of counting the number of triangles in the social network undirected graph becomes a protocol, denoted as ; the number of triangles counted by these protocols on the graph is denoted as ; suppose that in the social network undirected graph, all users know each other, that is, there is an edge between any two points, then at this time, the triangle count result in the social network undirected graph is the maximum value, denoted as ; on the contrary, suppose that in the social network undirected graph, all users do not know each other, that is, there is no edge between any two points, then at this time, the triangle count result in the social network undirected graph is the minimum value, denoted as ; Step 2, modeling IPA for attack input method; According to the attack strategy in step 1, first determine whether the type of the social network undirected graph is a sparse graph or a dense graph, if it is determined as a sparse graph, command all fake users to connect all controllable edges to maximize the triangle count result after the attack, let the false report triangle count result be closest to ; If the dense graph is determined, all fake users are commanded to cancel the connection of all controllable edges to minimize the triangle count result after the attack, so that the triangle count result after the attack is closest to ; Step 3, modeling OPA for attack output method; According to the attack strategy in step 1, it is necessary to determine the attack strategy by judging the sparse graph and the dense graph; If it is judged as a sparse graph, all fake users are commanded to connect all the edges that can be controlled to maximize the triangle count result after the attack; If it is judged as a dense graph, the fake user with the largest serial number is commanded to connect all the edges that can be controlled, and all the fake users except the fake user with the largest serial number are commanded to cancel the connection of all the edges that can be controlled to minimize the triangle count result after the attack; Step 4, measuring the attack effect and analyzing potential optimization schemes; After the attack scheme is determined, input attack IPA and output attack OPA are performed on different triangle count protocols on real data sets IMDB and Orkut; the final attack effect of different attack schemes is measured, and the better the attack effect is, the worse the protocol robustness is; on the contrary, the worse the attack effect is, the better the protocol robustness is.
2. The method of claim 1, wherein, In step 1, the graph after the attack is represented as The user attacked by the attacker is called a fake user, denoted as The set of edges owned by the fake user at this time is denoted as That is, find Let denote the number of edges owned by the fake user before and after the attack, respectively. and ; and denote the number of triangles in the graph that contain edges owned by the fake user before and after the attack, respectively. and denote the number of triangles that are completely unaffected by the fake user before and after the attack, respectively; the total number of triangles is the combination of these two parts, so the formula is simplified as The number of triangles that are not affected at all by the fake users before and after the attack is not affected, and thus and are equal, and thus the equation is further simplified to So the goal of the attack is to minimize the absolute value of the difference between the final result of the above equation and the final result of the above equation.
3. The method of claim 2, wherein, In step 1, the evaluator determines the further attack strategy according to whether the graph applied in practice is a sparse graph or a dense graph, including: Step 1.1, if the determined actual application graph is a sparse graph, since the number of edges in the original graph is small, in order to expand the difference in the number of triangles before and after the attack, the strategy is to increase the number of false user control edges in the undirected graph to expand this difference, that is, to let and maximize the absolute value of the difference of the triangle count results , so as to obtain the maximum attack impact; Step 1.2, if the determined actual application graph is a dense graph, since the number of edges in the original graph is large, the strategy is changed to reduce the number of edges controlled by the false user in the undirected graph to enlarge the difference in the number of triangles before and after the attack, i.e. let and the minimized triangle count result The absolute value of the difference is minimized, so that the attack impact is maximized.
4. The method of claim 3, wherein, The attack input scheme in step 2 determines whether the graph is sparse or dense, and estimates the difference. Determine the quantity; based on and The actual meaning is that, based on the number of edges controlled by fake users, they are divided into three categories, denoted by subscripts representing the number of edges controlled by fake users, as follows: Sort the three points of the triangle in ascending order of their index numbers. , In the edge set The middle belongs to the point The edge, with Represents graph density, Indicates that all serial numbers are compared Large points; is represented as is represented as The triangle represented by the three edges can be directly counted by the fake user since all the three edges are controlled by the fake user; the three variables calculated in the original graph and the graph after attack are added to obtain the estimated and , and then according to the estimation result, the dense graph and the sparse graph are determined; if , it is considered as a sparse graph, otherwise it is considered as a dense graph.
5. The method of claim 4, wherein, In the attack output scheme in step 3, the sparse graph or the dense graph is determined by estimating the values of , and ; wherein represents the meaning that among all the fake users, the fake user with the largest label is selected and all controllable edges are connected, and the remaining fake users cancel the connection of all controllable edges, and the final graph formed contains the triangle count of the edges controlled by the fake users; using to represent the estimated triangle number, initialized to 0, using to represent any three-point combination, and sorting in ascending order, assuming that the virtual triangle can be formed, then according to the number of edges controlled by the fake users in the virtual triangle, compared with the number of connected edges in the actual situation, the actual number of the virtual triangle is estimated, and finally all the triplets are traversed to obtain the final estimated triangle number , according to the actual meanings of , and , the values of the triplets are estimated by traversing the triplets; according to the estimation result, the dense graph and the sparse graph are determined; if , then the graph is determined as a sparse graph, otherwise it is determined as a dense graph.
6. The method of claim 5, wherein, All triples are divided into three categories, that is, three edges are controlled by fake users, two edges are controlled by fake users, and only one edge is controlled by fake users; Step 3.1: If all three sides of the virtual triangle are controlled by the fake user, that is, the two larger points... All are fake users; therefore, if the actual number of connected edges is 3, then in the number of triangles... Add to If the actual number of connected edges is 2, then in Reduce If the actual number of connected edges is 1, then in Add to If there is actually no edge connection, then in Reduce by 1; Step 3.2, if two edges of the virtual triangle are controlled by the fake user, i.e. the largest point in the virtual triangle belongs to the fake user, while the second largest point does not belong to the fake user; in this case, if the number of actually connected edges is 2, then add to the virtual triangle; if the number of actually connected edges is 1, then subtract from the virtual triangle ; if the number of actually connected edges is 0, then do nothing ; If there is no edge connection in reality, then add on ; Step 3.3, if only 1 edge of the virtual triangle is controlled by the fake user, i.e. the largest point is not the fake user, but the second largest point is the fake user; in this case, if the number of edges actually connected is 1, then add to ; if there are no edges actually connected, then subtract from .
7. The method of claim 6, wherein, The attack effect practice and potential optimization method analysis in step 4 select attack effect measurement indicators; select absolute error , relative error as attack effect measurement indicators, wherein The robustness of different protocols is evaluated by calculating the absolute error and relative error caused by an attack.
8. A robustness evaluation system for a triangle counting protocol under local differential privacy, characterized in that, Comprising: Attack strategy unit selection: Consider the scenario of triangle counting based on local differential privacy on an undirected graph of a social network. Using a real-world social network as the background, each user is treated as a point on the graph, represented as... ,in Indicates the user serial number; when two users and If two points know each other, then there exists an edge between them. ;like ,but By user What it possesses; the entire social network is abstractly represented as an undirected graph. The set of edges in the graph is represented as The point set is represented as ; There are three users in the whole undirected graph If each pair of users knows each other, then there are three edges between the three points, forming a triangle; the method of counting the number of triangles in the social network undirected graph becomes a protocol, denoted as ; the number of triangles counted by these protocols on the graph is denoted as ; assuming that all users in the social network undirected graph know each other, that is, there is an edge between any two points, then at this time, the triangle count result in the social network undirected graph is the maximum value, denoted as ; on the contrary, assuming that all users in the social network undirected graph do not know each other, that is, there is no edge between any two points, then at this time, the triangle count result in the social network undirected graph is the minimum value, denoted as ; The modeling IPA unit for the attack input method: according to the attack strategy in the selected attack strategy unit, first determine whether the type of the social network undirected graph is a sparse graph or a dense graph, if it is determined to be a sparse graph, command all fake users to connect all controllable edges to maximize the triangle count result after the attack, and let the false report triangle count result be closest to ; If the dense graph is determined, all fake users are commanded to cancel the connection of all controllable edges to minimize the triangle count result after the attack, so that the triangle count result after the attack is closest to ; The modeling OPA unit for attack output method: according to the attack strategy in the selecting attack strategy unit, it is necessary to determine the attack strategy by judging the sparse graph and the dense graph; If it is judged as a sparse graph, all fake users are commanded to connect all the edges that can be controlled to maximize the triangle count result after the attack; If it is judged as a dense graph, the fake user with the largest serial number is commanded to connect all the edges that can be controlled, and all the fake users except the fake user with the largest serial number are commanded to cancel the connection of all the edges that can be controlled to minimize the triangle count result after the attack; The measuring attack effect and analyzing potential optimization schemes unit: after the attack scheme is determined, input attack IPA and output attack OPA are performed on different triangle count protocols on real data sets IMDB and Orkut; the final attack effect of different attack schemes is measured, and the better the attack effect is, the worse the protocol robustness is; on the contrary, the worse the attack effect is, the better the protocol robustness is.
9. The robust evaluation system of local differential privacy lower triangle count protocol according to claim 8, wherein, In the selecting attack strategy unit, the graph after attack is represented as The user attacked by the attacker is called a false user, denoted as The set of edges owned by the false user at this time is denoted as That is, Let the number of edges owned by the fake user before and after the attack be denoted as and respectively. and denote the number of triangles in the graph that contain edges affected by the fake user before and after the attack respectively. and denote the number of triangles that are completely unaffected by the fake user before and after the attack respectively. The total number of triangles is the combination of these two parts, so the formula is simplified as The number of triangles that are not affected at all by the fake users before and after the attack is not affected, and it is known that and are equal, and thus the equation is further simplified to So the goal of the attack is to minimize the absolute value of the difference between the final result of the above equation and the final result of the above equation.
10. The robust evaluation system of local differential privacy lower triangle count protocol according to claim 9, wherein, In the selecting attack strategy unit, the evaluator determines the further attack strategy according to whether the graph applied in practice is a sparse graph or a dense graph, including: Step 1.1, if the determined actual application graph is a sparse graph, since the number of edges in the original graph is small, in order to expand the difference in the number of triangles before and after the attack, the strategy is to increase the number of false user control edges in the undirected graph to expand this difference, that is, to let and maximize the absolute value of the difference between the triangle count results , so as to obtain the maximum attack impact; Step 1.2, if the determined actual application graph is a dense graph, since the number of edges in the original graph is large, the strategy is changed to reduce the number of edges controlled by the false user in the undirected graph to enlarge the difference in the number of triangles before and after the attack, i.e. let and the minimized triangle count result The absolute value of the difference is minimized, so that the attack impact is maximized.