{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,6,19]],"date-time":"2025-06-19T04:56:28Z","timestamp":1750308988200,"version":"3.41.0"},"reference-count":38,"publisher":"Association for Computing Machinery (ACM)","issue":"2","license":[{"start":{"date-parts":[[2018,10,10]],"date-time":"2018-10-10T00:00:00Z","timestamp":1539129600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"DOI":"10.13039\/100000001","name":"National Science Foundation","doi-asserted-by":"publisher","award":["CCF-1535952"],"award-info":[{"award-number":["CCF-1535952"]}],"id":[{"id":"10.13039\/100000001","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/100006133","name":"Advanced Research Projects Agency - Energy","doi-asserted-by":"publisher","award":["DE-AR0000230"],"award-info":[{"award-number":["DE-AR0000230"]}],"id":[{"id":"10.13039\/100006133","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100008530","name":"European Regional Development Fund","doi-asserted-by":"publisher","award":["GINOP-2.3.2-15-2016-00037"],"award-info":[{"award-number":["GINOP-2.3.2-15-2016-00037"]}],"id":[{"id":"10.13039\/501100008530","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["ACM Trans. Cyber-Phys. Syst."],"published-print":{"date-parts":[[2019,4,30]]},"abstract":"<jats:p>Applications that aggregate and query data from distributed embedded devices are of interest in many settings, such as smart buildings and cities, the smart power grid, and mobile health applications. However, such devices also pose serious privacy concerns due to the personal nature of the data being collected. In this article, we present an algorithm for aggregating data in a distributed manner that keeps the data on the devices themselves, releasing only sums and other aggregates to centralized operators. We offer two privacy-preserving configurations of our solution, one limited to crash failures and supporting a basic kind of aggregation; the second supporting a wider range of queries and also tolerating Byzantine behavior by compromised nodes. The former is quite fast and scalable, the latter more robust against attack and capable of offering full differential privacy for an important class of queries, but it costs more and injects noise that makes the query results slightly inaccurate. Other configurations are also possible. At the core of our approach is a new kind of overlay network (a superimposed routing structure operated by the endpoint devices). This overlay is optimally robust and convergent, and our protocols use it both for aggregation and as a general-purpose infrastructure for peer-to-peer communications.<\/jats:p>","DOI":"10.1145\/3204411","type":"journal-article","created":{"date-parts":[[2018,10,10]],"date-time":"2018-10-10T13:30:46Z","timestamp":1539178246000},"page":"1-29","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":3,"title":["Anonymous, Fault-Tolerant Distributed Queries for Smart Devices"],"prefix":"10.1145","volume":"3","author":[{"given":"Edward","family":"Tremel","sequence":"first","affiliation":[{"name":"Cornell University, Ithaca, NY, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Ken","family":"Birman","sequence":"additional","affiliation":[{"name":"Cornell University, Ithaca, NY, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Robert","family":"Kleinberg","sequence":"additional","affiliation":[{"name":"Cornell University, Ithaca, NY, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"M\u00e1rk","family":"Jelasity","sequence":"additional","affiliation":[{"name":"Hungarian Academy of Sciences and University of Szeged, Hungary"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2018,10,10]]},"reference":[{"volume-title":"Amazon S3 Availability Event","year":"2008","key":"e_1_2_1_1_1","unstructured":"2008. Amazon S3 Availability Event : July 20, 2008 . http:\/\/status.aws.amazon.com\/s3-20080720.html. Accessed : 27 Jan 2015. 2008. Amazon S3 Availability Event: July 20, 2008. http:\/\/status.aws.amazon.com\/s3-20080720.html. Accessed: 27 Jan 2015."},{"key":"e_1_2_1_2_1","series-title":"Lecture Notes in Computer Science","volume-title":"I have a DREAM&excl","author":"\u00c1cs Gergely","unstructured":"Gergely \u00c1cs and Claude Castelluccia . 2011. I have a DREAM&excl ; (DiffeRentially privatE smArt metering). In Information Hiding, Tom\u00e1\u0161 Filler, Tom\u00e1\u0161 Pevn\u00fd, Scott Craver, and Andrew Ker (Eds.). Number 6958 in Lecture Notes in Computer Science . Springer-Verlag , Berlin, Heidelberg, 118--132. Gergely \u00c1cs and Claude Castelluccia. 2011. I have a DREAM&excl; (DiffeRentially privatE smArt metering). In Information Hiding, Tom\u00e1\u0161 Filler, Tom\u00e1\u0161 Pevn\u00fd, Scott Craver, and Andrew Ker (Eds.). Number 6958 in Lecture Notes in Computer Science. Springer-Verlag, Berlin, Heidelberg, 118--132."},{"key":"e_1_2_1_3_1","volume-title":"Proceedings of the 9th Workshop on the Economics of Information Security (WEIS","author":"Anderson Ross","year":"2010","unstructured":"Ross Anderson and Shailendra Fuloria . 2010 . On the security economics of electricity metering . In Proceedings of the 9th Workshop on the Economics of Information Security (WEIS 2010). Citeseer, Harvard University. Ross Anderson and Shailendra Fuloria. 2010. On the security economics of electricity metering. In Proceedings of the 9th Workshop on the Economics of Information Security (WEIS 2010). Citeseer, Harvard University."},{"key":"e_1_2_1_4_1","doi-asserted-by":"publisher","DOI":"10.1109\/DISCEX.2001.932161"},{"key":"e_1_2_1_5_1","unstructured":"Michael Bluejay. 2013. How much electricity does my stuff use? http:\/\/michaelbluejay.com\/electricity\/howmuch.html.  Michael Bluejay. 2013. How much electricity does my stuff use? http:\/\/michaelbluejay.com\/electricity\/howmuch.html."},{"key":"e_1_2_1_6_1","doi-asserted-by":"publisher","DOI":"10.1145\/4372.4373"},{"key":"e_1_2_1_7_1","doi-asserted-by":"publisher","DOI":"10.1145\/41840.41841"},{"key":"e_1_2_1_8_1","doi-asserted-by":"crossref","unstructured":"Tim Dierks and Eric Rescorla. 2008. The Transport Layer Security (TLS) Protocol Version 1.2. RFC 5246. IETF. https:\/\/tools.ietf.org\/html\/rfc5246  Tim Dierks and Eric Rescorla. 2008. The Transport Layer Security (TLS) Protocol Version 1.2. RFC 5246. IETF. https:\/\/tools.ietf.org\/html\/rfc5246","DOI":"10.17487\/rfc5246"},{"key":"e_1_2_1_9_1","doi-asserted-by":"publisher","DOI":"10.1016\/0196-6774(82)90004-9"},{"volume-title":"The Sybil attack","author":"Douceur John R.","key":"e_1_2_1_10_1","unstructured":"John R. Douceur . 2002. The Sybil attack . In Peer-to-Peer Systems, Peter Druschel, Frans Kaashoek, and Antony Rowstron (Eds.). LNCS, Vol . 2429. Springer , Berlin, 251--260. John R. Douceur. 2002. The Sybil attack. In Peer-to-Peer Systems, Peter Druschel, Frans Kaashoek, and Antony Rowstron (Eds.). LNCS, Vol. 2429. Springer, Berlin, 251--260."},{"key":"e_1_2_1_11_1","doi-asserted-by":"publisher","DOI":"10.1007\/11787006_1"},{"key":"e_1_2_1_12_1","doi-asserted-by":"publisher","DOI":"10.1145\/1866739.1866758"},{"key":"e_1_2_1_13_1","doi-asserted-by":"publisher","DOI":"10.1007\/11761679_29"},{"key":"e_1_2_1_14_1","doi-asserted-by":"publisher","DOI":"10.1007\/11681878_14"},{"key":"e_1_2_1_15_1","first-page":"209","article-title":"On Artin\u2019s conjecture","volume":"225","author":"Hooley Christopher","year":"1967","unstructured":"Christopher Hooley . 1967 . On Artin\u2019s conjecture . Journal f\u00fcr die Reine Und Angewandte Mathematik (Crelles Journal) 225 (1967), 209 -- 220 . Christopher Hooley. 1967. On Artin\u2019s conjecture. Journal f\u00fcr die Reine Und Angewandte Mathematik (Crelles Journal) 225 (1967), 209--220.","journal-title":"Journal f\u00fcr die Reine Und Angewandte Mathematik (Crelles Journal)"},{"volume-title":"Euro-Par 2007 (LNCS), Anne-Marie Kermarrec, Luc Boug\u00e9","author":"Jelasity M\u00e1rk","key":"e_1_2_1_16_1","unstructured":"M\u00e1rk Jelasity , Geoffrey Canright , and Kenth Eng\u00f8-Monsen . 2007. Asynchronous distributed power iteration with gossip-based normalization . In Euro-Par 2007 (LNCS), Anne-Marie Kermarrec, Luc Boug\u00e9 , and Thierry Priol (Eds.), Vol. 4641 . Springer , Berlin, Heidelberg , 514--525. M\u00e1rk Jelasity, Geoffrey Canright, and Kenth Eng\u00f8-Monsen. 2007. Asynchronous distributed power iteration with gossip-based normalization. In Euro-Par 2007 (LNCS), Anne-Marie Kermarrec, Luc Boug\u00e9, and Thierry Priol (Eds.), Vol. 4641. Springer, Berlin, Heidelberg, 514--525."},{"key":"e_1_2_1_17_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.comnet.2009.03.013"},{"key":"e_1_2_1_18_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.comnet.2010.03.020"},{"key":"e_1_2_1_19_1","doi-asserted-by":"publisher","DOI":"10.1145\/1217935.1217937"},{"volume-title":"Proceedings of the 44th Annual IEEE Symposium on Foundations of Computer Science. IEEE","author":"Kempe D.","key":"e_1_2_1_20_1","unstructured":"D. Kempe , A. Dobra , and J. Gehrke . 2003. Gossip-based computation of aggregate information . In Proceedings of the 44th Annual IEEE Symposium on Foundations of Computer Science. IEEE , Cambridge, MA, 482--491. D. Kempe, A. Dobra, and J. Gehrke. 2003. Gossip-based computation of aggregate information. In Proceedings of the 44th Annual IEEE Symposium on Foundations of Computer Science. IEEE, Cambridge, MA, 482--491."},{"key":"e_1_2_1_21_1","doi-asserted-by":"crossref","unstructured":"Julia Lane Victoria Stodden Stefan Bender and Helen Nissenbaum (Eds.). 2014. Privacy Big Data and the Public Good. Cambridge University Press.  Julia Lane Victoria Stodden Stefan Bender and Helen Nissenbaum (Eds.). 2014. Privacy Big Data and the Public Good. Cambridge University Press.","DOI":"10.1017\/CBO9781107590205"},{"key":"e_1_2_1_22_1","doi-asserted-by":"publisher","DOI":"10.1109\/MPAE.2003.1192027"},{"key":"e_1_2_1_23_1","unstructured":"Lawrence Berkeley National Laboratory. 2015. Default Energy Consumption of MELs. http:\/\/hes-documentation.lbl.gov\/calculation-methodology\/calculation-of-energy-consumption\/major-appliances\/miscellaneous-equipment-energy-consumption\/default-energy-consumption-of-mels.  Lawrence Berkeley National Laboratory. 2015. Default Energy Consumption of MELs. http:\/\/hes-documentation.lbl.gov\/calculation-methodology\/calculation-of-energy-consumption\/major-appliances\/miscellaneous-equipment-energy-consumption\/default-energy-consumption-of-mels."},{"key":"e_1_2_1_24_1","doi-asserted-by":"publisher","DOI":"10.1109\/SMARTGRID.2010.5622064"},{"key":"e_1_2_1_25_1","doi-asserted-by":"publisher","DOI":"10.5555\/1298455.1298474"},{"key":"e_1_2_1_26_1","doi-asserted-by":"publisher","DOI":"10.1109\/MSP.2010.40"},{"key":"e_1_2_1_27_1","doi-asserted-by":"publisher","DOI":"10.1109\/MSP.2009.76"},{"key":"e_1_2_1_28_1","doi-asserted-by":"publisher","DOI":"10.1109\/P2P.2009.5284506"},{"key":"e_1_2_1_29_1","doi-asserted-by":"publisher","DOI":"10.1515\/integers-2012-0043"},{"key":"e_1_2_1_30_1","doi-asserted-by":"publisher","DOI":"10.1002\/cpe.2858"},{"key":"e_1_2_1_31_1","doi-asserted-by":"publisher","DOI":"10.1002\/er.1136"},{"key":"e_1_2_1_32_1","series-title":"Lecture Notes in Computer Science","volume-title":"Advances in Cryptology \u2014 EUROCRYPT\u201999, Jacques Stern (Ed.)","author":"Paillier Pascal","unstructured":"Pascal Paillier . 1999. Public-Key cryptosystems based on composite degree residuosity classes . In Advances in Cryptology \u2014 EUROCRYPT\u201999, Jacques Stern (Ed.) . Lecture Notes in Computer Science , Vol. 1592 . Springer , Berlin, Heidelberg , 223--238. Pascal Paillier. 1999. Public-Key cryptosystems based on composite degree residuosity classes. In Advances in Cryptology \u2014 EUROCRYPT\u201999, Jacques Stern (Ed.). Lecture Notes in Computer Science, Vol. 1592. Springer, Berlin, Heidelberg, 223--238."},{"key":"e_1_2_1_33_1","doi-asserted-by":"publisher","DOI":"10.1109\/49.668972"},{"key":"e_1_2_1_34_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-662-46078-8_3"},{"key":"e_1_2_1_35_1","volume-title":"National Summary Tables - AHS","author":"US Census Bureau","year":"2013","unstructured":"US Census Bureau . 2015. National Summary Tables - AHS 2013 . http:\/\/www.census.gov\/programs-surveys\/ahs\/data\/2013\/national-summary-report-and-tables\u2014ahs-2013.html. US Census Bureau. 2015. National Summary Tables - AHS 2013. http:\/\/www.census.gov\/programs-surveys\/ahs\/data\/2013\/national-summary-report-and-tables\u2014ahs-2013.html."},{"volume-title":"Number 2429 in LNCS","author":"van Renesse Robbert","key":"e_1_2_1_36_1","unstructured":"Robbert van Renesse , Kenneth Birman , Dan Dumitriu , and Werner Vogels . 2002. Scalable management and data mining using astrolabe . In Peer-to-Peer Systems, Peter Druschel, Frans Kaashoek, and Antony Rowstron (Eds.). Number 2429 in LNCS . Springer , Berlin, Heidelberg , 280--294. Robbert van Renesse, Kenneth Birman, Dan Dumitriu, and Werner Vogels. 2002. Scalable management and data mining using astrolabe. In Peer-to-Peer Systems, Peter Druschel, Frans Kaashoek, and Antony Rowstron (Eds.). Number 2429 in LNCS. Springer, Berlin, Heidelberg, 280--294."},{"key":"e_1_2_1_37_1","volume-title":"Personal Data: The Emergence of a New Asset Class","author":"Forum World Economic","year":"2011","unstructured":"World Economic Forum . 2011 . Personal Data: The Emergence of a New Asset Class . http:\/\/www3.weforum.org\/docs\/WEF_ITTC_PersonalDataNewAsset_Report_2011.pdf. World Economic Forum. 2011. Personal Data: The Emergence of a New Asset Class. http:\/\/www3.weforum.org\/docs\/WEF_ITTC_PersonalDataNewAsset_Report_2011.pdf."},{"key":"e_1_2_1_38_1","doi-asserted-by":"crossref","first-page":"8","DOI":"10.1109\/MSPEC.2011.5960144","article-title":"Saving smart meters from a backlash","volume":"48","author":"Zachary G. Pascal","year":"2011","unstructured":"G. Pascal Zachary . 2011 . Saving smart meters from a backlash . IEEE Spectrum 48 , 8 (Aug. 2011), 8--8. G. Pascal Zachary. 2011. Saving smart meters from a backlash. IEEE Spectrum 48, 8 (Aug. 2011), 8--8.","journal-title":"IEEE Spectrum"}],"container-title":["ACM Transactions on Cyber-Physical Systems"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3204411","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3204411","content-type":"application\/pdf","content-version":"vor","intended-application":"syndication"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3204411","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,18]],"date-time":"2025-06-18T21:41:13Z","timestamp":1750282873000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3204411"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2018,10,10]]},"references-count":38,"journal-issue":{"issue":"2","published-print":{"date-parts":[[2019,4,30]]}},"alternative-id":["10.1145\/3204411"],"URL":"https:\/\/doi.org\/10.1145\/3204411","relation":{},"ISSN":["2378-962X","2378-9638"],"issn-type":[{"type":"print","value":"2378-962X"},{"type":"electronic","value":"2378-9638"}],"subject":[],"published":{"date-parts":[[2018,10,10]]},"assertion":[{"value":"2016-11-01","order":0,"name":"received","label":"Received","group":{"name":"publication_history","label":"Publication History"}},{"value":"2018-03-01","order":1,"name":"accepted","label":"Accepted","group":{"name":"publication_history","label":"Publication History"}},{"value":"2018-10-10","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}