Publication:
Don't hash me like that: exposing and mitigating hash-induced unfairness in local differential privacy

dc.conference.dateSEP 22-24, 2025
dc.conference.locationToulouse, FRANCE
dc.contributor.departmentDepartment of Computer Engineering
dc.contributor.kuauthorBalioğlu, Berkay Kemal
dc.contributor.kuauthorKhodaie, Alireza
dc.contributor.kuauthorGürsoy, Mehmet Emre
dc.contributor.schoolcollegeinstituteCollege of Engineering
dc.date.accessioned2026-02-26T07:11:34Z
dc.date.available2026-02-25
dc.date.issued2026
dc.description.abstractLocal differential privacy (LDP) has become a widely accepted framework for privacy-preserving data collection. In LDP, many protocols rely on hash functions to implement user-side encoding and perturbation. However, the security and privacy implications of hash function selection have not been previously investigated. In this paper, we expose that the hash functions may act as a source of unfairness in LDP protocols. We show that although users operate under the same protocol and privacy budget, differences in hash functions can lead to significant disparities in vulnerability to inference and poisoning attacks. To mitigate hash-induced unfairness, we propose Fair-OLH (F-OLH), a variant of OLH that enforces an entropy-based fairness constraint on hash function selection. Experiments show that F-OLH is effective in mitigating hash-induced unfairness under acceptable time overheads.
dc.description.fulltextNo
dc.description.harvestedfromManual
dc.description.indexedbyWOS
dc.description.indexedbyScopus
dc.description.openaccessBronze OA
dc.description.publisherscopeInternational
dc.description.readpublishN/A
dc.description.sponsoredbyTubitakEuTÜBİTAK
dc.description.sponsorshipThis study was supported by The Scientific and Technological Research Council of Turkiye (TUBITAK) under grant number 123E179. The authors thank TUBITAK for their support.
dc.description.versionN/A
dc.identifier.doi10.1007/978-3-032-07901-5_2
dc.identifier.eissn1611-3349
dc.identifier.embargoNo
dc.identifier.endpage42
dc.identifier.grantno123E179
dc.identifier.isbn9783032079008
dc.identifier.isbn9783032079015
dc.identifier.issn0302-9743
dc.identifier.quartileQ4
dc.identifier.scopus2-s2.0-105020022104
dc.identifier.startpage22
dc.identifier.urihttps://doi.org/10.1007/978-3-032-07901-5_2
dc.identifier.urihttps://hdl.handle.net/20.500.14288/32413
dc.identifier.volume16056
dc.identifier.wos001656845200002
dc.keywordsPrivacy
dc.keywordsLocal differential privacy
dc.keywordsProtocol fairness
dc.keywordsInference attacks
dc.keywordsPoisoning attacks
dc.keywordsPrivacy technologies and mechanisms
dc.language.isoeng
dc.publisherSpringer
dc.relation.affiliationKoç University
dc.relation.collectionKoç University Institutional Repository
dc.relation.ispartofComputer Security – ESORICS 2025, PT IV
dc.relation.openaccessNo
dc.rightsCopyrighted
dc.subjectComputer science
dc.subjectTelecommunications
dc.titleDon't hash me like that: exposing and mitigating hash-induced unfairness in local differential privacy
dc.typeConference Proceeding
dspace.entity.typePublication
relation.isOrgUnitOfPublication89352e43-bf09-4ef4-82f6-6f9d0174ebae
relation.isOrgUnitOfPublication.latestForDiscovery89352e43-bf09-4ef4-82f6-6f9d0174ebae
relation.isParentOrgUnitOfPublication8e756b23-2d4a-4ce8-b1b3-62c794a8c164
relation.isParentOrgUnitOfPublication.latestForDiscovery8e756b23-2d4a-4ce8-b1b3-62c794a8c164

Files