Augmented Shuffle Protocols for Accurate and Robust Frequency Estimation under Differential Privacy
Existing differentially private (DP) shuffling models face two critical challenges: poor robustness against local data poisoning attacks—especially under small ε—and vulnerability to privacy budget inflation when the data collector colludes with users. This paper proposes an enhanced shuffling framework that achieves pure ε-DP frequency estimation while provably resisting collusion. Our method introduces a universal protocol requiring no local noise injection, integrates randomized sampling and virtual data injection, and employs an asymmetric two-sided geometric distribution for virtual counts—ensuring strict ε-DP and effectively mitigating poisoning effects. We provide formal theoretical proofs establishing both ε-DP compliance and robustness against adversarial poisoning. Empirical evaluation demonstrates that, under identical privacy budgets, our approach improves estimation accuracy by 15–30% over state-of-the-art methods, achieving a superior balance among utility, computational efficiency, and rigorous privacy guarantees.