{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,25]],"date-time":"2026-07-25T16:58:22Z","timestamp":1784998702689,"version":"3.55.0"},"reference-count":59,"publisher":"Association for Computing Machinery (ACM)","issue":"13","content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Proc. VLDB Endow."],"published-print":{"date-parts":[[2020,9]]},"abstract":"<jats:p>When collecting information, local differential privacy (LDP) alleviates privacy concerns of users because their private information is randomized before being sent it to the central aggregator. LDP imposes large amount of noise as each user executes the randomization independently. To address this issue, recent work introduced an intermediate server with the assumption that this intermediate server does not collude with the aggregator. Under this assumption, less noise can be added to achieve the same privacy guarantee as LDP, thus improving utility for the data collection task.<\/jats:p>\n          <jats:p>This paper investigates this multiple-party setting of LDP. We analyze the system model and identify potential adversaries. We then make two improvements: a new algorithm that achieves a better privacy-utility tradeoff; and a novel protocol that provides better protection against various attacks. Finally, we perform experiments to compare different methods and demonstrate the benefits of using our proposed method.<\/jats:p>","DOI":"10.14778\/3424573.3424576","type":"journal-article","created":{"date-parts":[[2020,10,28]],"date-time":"2020-10-28T01:15:32Z","timestamp":1603847732000},"page":"3545-3558","source":"Crossref","is-referenced-by-count":32,"title":["Improving utility and security of the shuffler-based differential privacy"],"prefix":"10.14778","volume":"13","author":[{"given":"Tianhao","family":"Wang","sequence":"first","affiliation":[{"name":"Purdue University"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Bolin","family":"Ding","sequence":"additional","affiliation":[{"name":"Alibaba Group"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Min","family":"Xu","sequence":"additional","affiliation":[{"name":"University of Chicago"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Zhicong","family":"Huang","sequence":"additional","affiliation":[{"name":"Alibaba Group"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Cheng","family":"Hong","sequence":"additional","affiliation":[{"name":"Alibaba Group"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Jingren","family":"Zhou","sequence":"additional","affiliation":[{"name":"Alibaba Group"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Ninghui","family":"Li","sequence":"additional","affiliation":[{"name":"Purdue University"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Somesh","family":"Jha","sequence":"additional","affiliation":[{"name":"University of Wisconsin"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2020,10,27]]},"reference":[{"key":"e_1_2_1_1_1","unstructured":"Apple differential privacy team learning with privacy at scale. Available at https:\/\/machinelearning.apple.com\/docs\/learning-with-privacy-at-scale\/appledifferentialprivacysystem.pdf.  Apple differential privacy team learning with privacy at scale. Available at https:\/\/machinelearning.apple.com\/docs\/learning-with-privacy-at-scale\/appledifferentialprivacysystem.pdf."},{"key":"e_1_2_1_2_1","unstructured":"Frequent itemset mining dataset repository. Available at http:\/\/fimi.ua.ac.be\/data\/.  Frequent itemset mining dataset repository. Available at http:\/\/fimi.ua.ac.be\/data\/."},{"key":"e_1_2_1_3_1","unstructured":"Web search query log downloads. Available at http:\/\/www.radiounderground.net\/aol-data\/.  Web search query log downloads. Available at http:\/\/www.radiounderground.net\/aol-data\/."},{"key":"e_1_2_1_4_1","unstructured":"J. M. Abowd. Protecting the confidentiality of america's statistics: Adopting modern disclosure avoidance methods at the census bureau. https:\/\/www.census.gov\/newsroom\/blogs\/research-matters\/2018\/08\/protecting_the_confi.html 2018.  J. M. Abowd. Protecting the confidentiality of america's statistics: Adopting modern disclosure avoidance methods at the census bureau. https:\/\/www.census.gov\/newsroom\/blogs\/research-matters\/2018\/08\/protecting_the_confi.html 2018."},{"key":"e_1_2_1_5_1","volume-title":"AISTATS","author":"Acharya J.","year":"2019","unstructured":"J. Acharya , Z. Sun , and H. Zhang . Hadamard response: Estimating distributions privately, efficiently, and with little communication . In AISTATS , 2019 . J. Acharya, Z. Sun, and H. Zhang. Hadamard response: Estimating distributions privately, efficiently, and with little communication. In AISTATS, 2019."},{"key":"e_1_2_1_6_1","first-page":"13635","volume-title":"Advances in Neural Information Processing Systems","author":"Allen J.","year":"2019","unstructured":"J. Allen , B. Ding , J. Kulkarni , H. Nori , O. Ohrimenko , and S. Yekhanin . An algorithmic framework for differentially private data analysis on trusted processors . In Advances in Neural Information Processing Systems , pages 13635 -- 13646 , 2019 . J. Allen, B. Ding, J. Kulkarni, H. Nori, O. Ohrimenko, and S. Yekhanin. An algorithmic framework for differentially private data analysis on trusted processors. In Advances in Neural Information Processing Systems, pages 13635--13646, 2019."},{"key":"e_1_2_1_7_1","doi-asserted-by":"publisher","DOI":"10.1145\/2508859.2516735"},{"key":"e_1_2_1_8_1","volume-title":"Separating local & shuffled differential privacy via histograms. arXiv preprint arXiv:1909.06879","author":"Balcer V.","year":"2019","unstructured":"V. Balcer and A. Cheu . Separating local & shuffled differential privacy via histograms. arXiv preprint arXiv:1909.06879 , 2019 . V. Balcer and A. Cheu. Separating local & shuffled differential privacy via histograms. arXiv preprint arXiv:1909.06879, 2019."},{"key":"e_1_2_1_9_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-26951-7_22"},{"key":"e_1_2_1_10_1","doi-asserted-by":"publisher","DOI":"10.1145\/3372297.3417242"},{"key":"e_1_2_1_11_1","doi-asserted-by":"publisher","DOI":"10.5555\/3294771.3294989"},{"key":"e_1_2_1_12_1","doi-asserted-by":"publisher","DOI":"10.1145\/2746539.2746632"},{"key":"e_1_2_1_13_1","volume-title":"Protection against reconstruction and its applications in private federated learning. arXiv preprint arXiv:1812.00984","author":"Bhowmick A.","year":"2018","unstructured":"A. Bhowmick , J. Duchi , J. Freudiger , G. Kapoor , and R. Rogers . Protection against reconstruction and its applications in private federated learning. arXiv preprint arXiv:1812.00984 , 2018 . A. Bhowmick, J. Duchi, J. Freudiger, G. Kapoor, and R. Rogers. Protection against reconstruction and its applications in private federated learning. arXiv preprint arXiv:1812.00984, 2018."},{"key":"e_1_2_1_14_1","doi-asserted-by":"publisher","DOI":"10.5555\/3277203.3277294"},{"key":"e_1_2_1_15_1","doi-asserted-by":"publisher","DOI":"10.1145\/3132747.3132769"},{"key":"e_1_2_1_16_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-540-88313-5_13"},{"key":"e_1_2_1_17_1","doi-asserted-by":"publisher","DOI":"10.1145\/3319535.3354256"},{"key":"e_1_2_1_18_1","doi-asserted-by":"publisher","DOI":"10.5555\/3310435.3310585"},{"key":"e_1_2_1_19_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-17653-2_13"},{"key":"e_1_2_1_20_1","doi-asserted-by":"publisher","DOI":"10.1145\/3318464.3380596"},{"key":"e_1_2_1_21_1","doi-asserted-by":"publisher","DOI":"10.5555\/1770231.1770269"},{"key":"e_1_2_1_22_1","doi-asserted-by":"publisher","DOI":"10.1504\/IJACT.2008.017048"},{"key":"e_1_2_1_23_1","doi-asserted-by":"publisher","DOI":"10.5555\/3294996.3295115"},{"key":"e_1_2_1_24_1","volume-title":"One-sided differential privacy. arXiv preprint arXiv:1712.05888","author":"Doudalis S.","year":"2017","unstructured":"S. Doudalis , I. Kotsogiannis , S. Haney , A. Machanavajjhala , and S. Mehrotra . One-sided differential privacy. arXiv preprint arXiv:1712.05888 , 2017 . S. Doudalis, I. Kotsogiannis, S. Haney, A. Machanavajjhala, and S. Mehrotra. One-sided differential privacy. arXiv preprint arXiv:1712.05888, 2017."},{"key":"e_1_2_1_25_1","doi-asserted-by":"publisher","DOI":"10.1109\/FOCS.2013.53"},{"key":"e_1_2_1_26_1","doi-asserted-by":"publisher","DOI":"10.1007\/11787006_1"},{"key":"e_1_2_1_27_1","doi-asserted-by":"publisher","DOI":"10.1007\/11761679_29"},{"key":"e_1_2_1_28_1","doi-asserted-by":"publisher","DOI":"10.1145\/2660267.2660280"},{"key":"e_1_2_1_29_1","volume-title":"Encode, shuffle, analyze privacy revisited: Formalizations and empirical evaluation. arXiv preprint arXiv:2001.03618","author":"Feldman V.","year":"2020","unstructured":"\u00da. Erlingsson, V. Feldman , I. Mironov , A. Raghunathan , S. Song , K. Talwar , and A. Thakurta . Encode, shuffle, analyze privacy revisited: Formalizations and empirical evaluation. arXiv preprint arXiv:2001.03618 , 2020 . \u00da. Erlingsson, V. Feldman, I. Mironov, A. Raghunathan, S. Song, K. Talwar, and A. Thakurta. Encode, shuffle, analyze privacy revisited: Formalizations and empirical evaluation. arXiv preprint arXiv:2001.03618, 2020."},{"key":"e_1_2_1_30_1","doi-asserted-by":"publisher","DOI":"10.5555\/3310435.3310586"},{"key":"e_1_2_1_31_1","doi-asserted-by":"publisher","DOI":"10.1145\/2660267.2660348"},{"key":"e_1_2_1_32_1","doi-asserted-by":"publisher","DOI":"10.1515\/popets-2017-0047"},{"key":"e_1_2_1_33_1","volume-title":"On the power of multiple anonymous messages. arXiv preprint arXiv:1908.11358","author":"Ghazi B.","year":"2019","unstructured":"B. Ghazi , N. Golowich , R. Kumar , R. Pagh , and A. Velingker . On the power of multiple anonymous messages. arXiv preprint arXiv:1908.11358 , 2019 . B. Ghazi, N. Golowich, R. Kumar, R. Pagh, and A. Velingker. On the power of multiple anonymous messages. arXiv preprint arXiv:1908.11358, 2019."},{"key":"e_1_2_1_34_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-45724-2_27"},{"key":"e_1_2_1_35_1","doi-asserted-by":"publisher","DOI":"10.1109\/CNS.2019.8802778"},{"key":"e_1_2_1_36_1","volume-title":"ICDE","author":"Gu X.","year":"2020","unstructured":"X. Gu , M. Li , L. Xiong , and Y. Cao . Providing input-discriminative protection for local differential privacy . In ICDE , 2020 . X. Gu, M. Li, L. Xiong, and Y. Cao. Providing input-discriminative protection for local differential privacy. In ICDE, 2020."},{"key":"e_1_2_1_37_1","volume-title":"Secure and utility-aware data collection with condensed local differential privacy. arXiv preprint arXiv:1905.06361","author":"Gursoy M. E.","year":"2019","unstructured":"M. E. Gursoy , A. Tamersoy , S. Truex , W. Wei , and L. Liu . Secure and utility-aware data collection with condensed local differential privacy. arXiv preprint arXiv:1905.06361 , 2019 . M. E. Gursoy, A. Tamersoy, S. Truex, W. Wei, and L. Liu. Secure and utility-aware data collection with condensed local differential privacy. arXiv preprint arXiv:1905.06361, 2019."},{"key":"e_1_2_1_38_1","doi-asserted-by":"publisher","DOI":"10.1145\/3133956.3134030"},{"key":"e_1_2_1_39_1","doi-asserted-by":"publisher","DOI":"10.5555\/2051002.2051027"},{"key":"e_1_2_1_40_1","doi-asserted-by":"publisher","DOI":"10.1109\/FOCS.2010.14"},{"key":"e_1_2_1_41_1","first-page":"3","article-title":"Federated learning: Collaborative machine learning without centralized training data","author":"McMahan B.","year":"2017","unstructured":"B. McMahan and D. Ramage . Federated learning: Collaborative machine learning without centralized training data . Google Research Blog , 3 , 2017 . B. McMahan and D. Ramage. Federated learning: Collaborative machine learning without centralized training data. Google Research Blog, 3, 2017.","journal-title":"Google Research Blog"},{"key":"e_1_2_1_42_1","volume-title":"Efficient private statistics with succinct sketches. arXiv preprint arXiv:1508.06110","author":"Melis L.","year":"2015","unstructured":"L. Melis , G. Danezis , and E. De Cristofaro . Efficient private statistics with succinct sketches. arXiv preprint arXiv:1508.06110 , 2015 . L. Melis, G. Danezis, and E. De Cristofaro. Efficient private statistics with succinct sketches. arXiv preprint arXiv:1508.06110, 2015."},{"key":"e_1_2_1_43_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-03356-8_8"},{"key":"e_1_2_1_44_1","doi-asserted-by":"publisher","DOI":"10.5555\/3361338.3361468"},{"key":"e_1_2_1_45_1","doi-asserted-by":"publisher","DOI":"10.5555\/1756123.1756146"},{"key":"e_1_2_1_46_1","doi-asserted-by":"publisher","DOI":"10.1109\/TIT.1978.1055817"},{"key":"e_1_2_1_47_1","doi-asserted-by":"publisher","DOI":"10.1145\/3318462"},{"key":"e_1_2_1_48_1","doi-asserted-by":"publisher","DOI":"10.1145\/3341301.3359660"},{"key":"e_1_2_1_49_1","volume-title":"Integrated public use microdata series: Version 9.0 [database]","author":"Ruggles S.","year":"2019","unstructured":"S. Ruggles , S. Flood , R. Goeken , J. Grover , E. Meyer , J. Pacas , and M. Sobek . Integrated public use microdata series: Version 9.0 [database] , 2019 . S. Ruggles, S. Flood, R. Goeken, J. Grover, E. Meyer, J. Pacas, and M. Sobek. Integrated public use microdata series: Version 9.0 [database], 2019."},{"key":"e_1_2_1_50_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICDE.2018.00079"},{"key":"e_1_2_1_51_1","doi-asserted-by":"publisher","DOI":"10.1109\/INFOCOM.2017.8056977"},{"key":"e_1_2_1_52_1","doi-asserted-by":"publisher","DOI":"10.5555\/3241189.3241247"},{"key":"e_1_2_1_53_1","doi-asserted-by":"publisher","DOI":"10.1145\/3299869.3319891"},{"key":"e_1_2_1_54_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2018.00035"},{"key":"e_1_2_1_55_1","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2019.2927695"},{"key":"e_1_2_1_56_1","doi-asserted-by":"publisher","DOI":"10.5555\/3241189.3241247"},{"key":"e_1_2_1_57_1","doi-asserted-by":"publisher","DOI":"10.1080\/01621459.1965.10480775"},{"key":"e_1_2_1_58_1","doi-asserted-by":"publisher","DOI":"10.14778\/3407790.3407859"},{"key":"e_1_2_1_59_1","volume-title":"Answering multi-dimensional range queries under local differential privacy. arXiv preprint arXiv:2009.06538","author":"Yang J.","year":"2020","unstructured":"J. Yang , T. Wang , N. Li , X. Cheng , and S. Su . Answering multi-dimensional range queries under local differential privacy. arXiv preprint arXiv:2009.06538 , 2020 . J. Yang, T. Wang, N. Li, X. Cheng, and S. Su. Answering multi-dimensional range queries under local differential privacy. arXiv preprint arXiv:2009.06538, 2020."}],"container-title":["Proceedings of the VLDB Endowment"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.14778\/3424573.3424576","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2022,12,28]],"date-time":"2022-12-28T09:18:16Z","timestamp":1672219096000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.14778\/3424573.3424576"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2020,9]]},"references-count":59,"journal-issue":{"issue":"13","published-print":{"date-parts":[[2020,9]]}},"alternative-id":["10.14778\/3424573.3424576"],"URL":"https:\/\/doi.org\/10.14778\/3424573.3424576","relation":{},"ISSN":["2150-8097"],"issn-type":[{"value":"2150-8097","type":"print"}],"subject":[],"published":{"date-parts":[[2020,9]]}}}