On the Inherent Anonymity of Gossiping

Rachid Guerraoui,Anne-Marie Kermarrec,Anastasiia Kucherenko,Rafael Pinot,Sasha Voitovych
2023-08-05
Abstract:Detecting the source of a gossip is a critical issue, related to identifying patient zero in an epidemic, or the origin of a rumor in a social network. Although it is widely acknowledged that random and local gossip communications make source identification difficult, there exists no general quantification of the level of anonymity provided to the source. This paper presents a principled method based on $\varepsilon$-differential privacy to analyze the inherent source anonymity of gossiping for a large class of graphs. First, we quantify the fundamental limit of source anonymity any gossip protocol can guarantee in an arbitrary communication graph. In particular, our result indicates that when the graph has poor connectivity, no gossip protocol can guarantee any meaningful level of differential privacy. This prompted us to further analyze graphs with controlled connectivity. We prove on these graphs that a large class of gossip protocols, namely cobra walks, offers tangible differential privacy guarantees to the source. In doing so, we introduce an original proof technique based on the reduction of a gossip protocol to what we call a random walk with probabilistic die out. This proof technique is of independent interest to the gossip community and readily extends to other protocols inherited from the security community, such as the Dandelion protocol. Interestingly, our tight analysis precisely captures the trade-off between dissemination time of a gossip protocol and its source anonymity.
Distributed, Parallel, and Cluster Computing,Cryptography and Security
What problem does this paper attempt to address?
The problem that this paper attempts to solve is to evaluate the intrinsic anonymity of the source in the gossip protocol (i.e., the gossip protocol) in a general communication graph by quantifying the fundamental limits of source anonymity. Specifically, the paper focuses on how to use the mathematical framework of ε - Differential Privacy (ε - DP) to analyze and quantify the level of source anonymity that the gossip protocol can provide on different types of graphs. The main objectives of the research include: 1. **Quantifying the fundamental limits of source anonymity**: The paper first determines the fundamental limits of the ε - DP level that any gossip protocol can provide on an arbitrary communication graph. The research shows that on graphs with poor connectivity, no gossip protocol can guarantee a meaningful level of differential privacy. 2. **Privacy protection on graphs with controlled connectivity**: For graphs with controlled connectivity (such as expander graphs), the paper proves that a wide class of gossip protocols (called cobra walks) can provide substantial differential privacy protection to source nodes. To this end, the author introduces an original proof technique based on "random walks with probabilistic death", which is not only of independent interest to the gossip community but can also be extended to other protocols, such as the Dandelion protocol in the blockchain. 3. **The trade - off between propagation time and privacy**: As an important by - product of the analysis, the paper precisely captures the trade - off relationship between the propagation time and privacy when a class of gossip protocols runs on sufficiently dense graphs (called approximate Ramanujan graphs). The research shows that as the parameter ρ increases, although the propagation speed increases, the privacy protection of the protocol will decrease, thus formally establishing the trade - off between privacy and propagation time. In summary, this paper aims to provide a systematic analysis framework for source anonymity in the gossip protocol by introducing and applying the concept of ε - differential privacy, and to explore the anonymity levels and limitations that these protocols can provide under different types of network structures.