Private Set Intersection (PSI) is a widely used protocol that enables two parties to securely compute a function over the intersected part of their shared datasets and has been a significant research focus over the years. However, recent studies have highlighted its vulnerability to Set Membership Inference Attacks (SMIA), where an adversary might deduce an individual's membership by invoking multiple PSI protocols. This presents a considerable risk, even in the most stringent versions of PSI, which only return the cardinality of the intersection. This paper explores the evaluation of anonymity within the PSI context. Initially, we highlight the reasons why existing works fall short in measuring privacy leakage, and subsequently propose two attack strategies that address these deficiencies. Furthermore, we provide theoretical guarantees on the performance of our proposed methods. In addition to these, we illustrate how the integration of auxiliary information, such as the sum of payloads associated with members of the intersection (PSI-SUM), can enhance attack efficiency. We conducted a comprehensive performance evaluation of various attack strategies proposed utilizing two real datasets. Our findings indicate that the methods we propose markedly enhance attack efficiency when contrasted with previous research endeavors. {The effective attacking implies that depending solely on existing PSI protocols may not provide an adequate level of privacy assurance. It is recommended to combine privacy-enhancing technologies synergistically to enhance privacy protection even further.
翻译:私有集合交集(PSI)是一种广泛使用的协议,允许两方在共享数据集的交集部分上安全地计算函数,多年来一直是重要的研究焦点。然而,近期研究揭示了其对集合成员推理攻击(SMIA)的脆弱性,在这种攻击中,对手可能通过多次调用PSI协议推断出个人的成员身份。即使在仅返回交集基数的严格版本的PSI中,这也构成了重大风险。本文探讨了PSI背景下的匿名性评估。首先,我们指出现有工作在衡量隐私泄露方面的不足,随后提出了两种应对这些缺陷的攻击策略。此外,我们提供了所提方法性能的理论保证。除了这些,我们展示了如何将辅助信息(如交集成员有效载荷的总和,即PSI-SUM)的整合用于提升攻击效率。我们利用两个真实数据集对所提出的多种攻击策略进行了全面的性能评估。结果表明,与之前的研究相比,我们提出的方法显著提高了攻击效率。有效的攻击意味着仅依赖现有的PSI协议可能无法提供足够的隐私保证。建议协同结合隐私增强技术,以进一步增强隐私保护。