EDBT 2026 Demo / reviewers in the wild / expert
Jiankai Jin
dblp:308/6408
· DBLP profile ↗
2ranked-venue papers
2as first author
2since 2021 · last 2024
0009-0009-1008-482XORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 2 · 2 first-author · 2 since 2021
Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.
| Network and information security
2 papers |
Privacy and data protection · 59% Hardware security and side channels · 41% |
Topics — the 6 heaviest of 6, each with the papers that count most for it
| Topic | Weight | Papers | Last | Evidence papers |
|---|---|---|---|---|
Privacy and data protection
differential privacy |
1.3 | 2 | 2024 | Elephants Do Not Forget: Differential Privacy with State Continuity for Privacy Budget · CCS 2024 Are We There Yet? Timing and Floating-Point Attacks on Differential Privacy Systems · SP 2022 |
Privacy and data protection › differential privacy › privacy accounting
privacy budget |
0.8 | 1 | 2024 | Elephants Do Not Forget: Differential Privacy with State Continuity for Privacy Budget · CCS 2024 |
Hardware security and side channels › trusted execution environments
state continuity |
0.8 | 1 | 2024 | Elephants Do Not Forget: Differential Privacy with State Continuity for Privacy Budget · CCS 2024 |
Hardware security and side channels
side-channel attack |
0.6 | 1 | 2022 | Are We There Yet? Timing and Floating-Point Attacks on Differential Privacy Systems · SP 2022 |
Hardware security and side channels
trusted execution environments |
0.2 | 1 | 2024 | Elephants Do Not Forget: Differential Privacy with State Continuity for Privacy Budget · CCS 2024 |
Privacy and data protection › differential privacy › differentially private deep learning
DP-SGD |
0.2 | 1 | 2022 | Are We There Yet? Timing and Floating-Point Attacks on Differential Privacy Systems · SP 2022 |
Methods — techniques the papers use, named apart from their topics
trusted execution environment · 0.8state continuity protocol · 0.8timing attack · 0.6floating-point representation attack · 0.6
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2024 | Elephants Do Not Forget: Differential Privacy with State Continuity for Privacy BudgetabstractCurrent implementations of differentially-private (DP) systems either lack support to track the global privacy budget consumed on a dataset, or fail to faithfully maintain the state continuity of this budget. We show that failure to maintain a privacy budget enables an adversary to mount replay, rollback and fork attacks --- obtaining answers to many more queries than what a secure system would allow. As a result the attacker can reconstruct secret data that DP aims to protect --- even if DP code runs in a Trusted Execution Environment (TEE). We propose ElephantDP, a system that aims to provide the same guarantees as a trusted curator in the global DP model would, albeit set in an untrusted environment. Our system relies on a state continuity module to provide protection for the privacy budget and a TEE to faithfully execute DP code and update the budget. To provide security, our protocol makes several design choices including the content of the persistent state and the order between budget updates and query answers. We prove that ElephantDP provides liveness (i.e., the protocol can restart from a correct state and respond to queries as long as the budget is not exceeded) and DP confidentiality (i.e., an attacker learns about a dataset as much as it would from interacting with a trusted curator). Our implementation and evaluation of the protocol use Intel SGX as a TEE to run the DP code and a network of TEEs to maintain state continuity. Compared to an insecure baseline, we observe 1.1--3.2× overheads and lower relative overheads for complex DP queries. Jiankai Jin, Chitchanok Chuengsatiansup, Toby C. Murray, Benjamin I. P. Rubinstein, Yuval Yarom, Olga Ohrimenko |
CCS | 1 |
| 2022 | Are We There Yet? Timing and Floating-Point Attacks on Differential Privacy SystemsabstractDifferential privacy is a de facto privacy framework that has seen adoption in practice via a number of mature software platforms. Implementation of differentially private (DP) mechanisms has to be done carefully to ensure end-to-end security guarantees. In this paper we study two implementation flaws in the noise generation commonly used in DP systems. First we examine the Gaussian mechanism’s susceptibility to a floating-point representation attack. The premise of this first vulnerability is similar to the one carried out by Mironov in 2011 against the Laplace mechanism. Our experiments show the attack’s success against DP algorithms, including deep learning models trained using differentially-private stochastic gradient descent. In the second part of the paper we study discrete counterparts of the Laplace and Gaussian mechanisms that were previously proposed to alleviate the shortcomings of floating-point representation of real numbers. We show that such implementations unfortunately suffer from another side channel: a novel timing attack. An observer that can measure the time to draw (discrete) Laplace or Gaussian noise can predict the noise magnitude, which can then be used to recover sensitive attributes. This attack invalidates differential privacy guarantees of systems implementing such mechanisms. We demonstrate that several commonly used, state-of-the-art implementations of differential privacy are susceptible to these attacks. We report success rates up to 92.56% for floating point attacks on DP-SGD, and up to 99.65% for end-to-end timing attacks on private sum protected with discrete Laplace. Finally, we evaluate and suggest partial mitigations. Jiankai Jin, Eleanor McMurtry, Benjamin I. P. Rubinstein, Olga Ohrimenko |
SP | 1 |