On the Inherent Anonymity of Gossiping

📅 2023-08-04
🏛️ International Symposium on Distributed Computing
📈 Citations: 4
Influential: 1
📄 PDF
🤖 AI Summary
This work addresses the lack of a general quantitative framework for source anonymity in gossip protocols. We establish, for the first time, tight fundamental limits on source anonymity for arbitrary graphs under ε-differential privacy. To achieve this, we introduce a novel reduction paradigm—“random walk with probabilistic extinction”—which enables rigorous differential privacy analysis of classic gossip protocols such as Cobra Walk. Our theoretical analysis precisely characterizes the intrinsic trade-off between dissemination latency and source anonymity. We prove that graphs with low connectivity cannot provide meaningful source anonymity, whereas Cobra Walk achieves nontrivial ε-differential privacy on graphs with controllable connectivity. The results are tight, scalable, and have been successfully applied to analyze real-world anonymity protocols—including Dandelion—providing foundational theoretical support for the design and evaluation of anonymous communication systems.
📝 Abstract
Detecting the source of a gossip is a critical issue, related to identifying patient zero in an epidemic, or the origin of a rumor in a social network. Although it is widely acknowledged that random and local gossip communications make source identification difficult, there exists no general quantification of the level of anonymity provided to the source. This paper presents a principled method based on $varepsilon$-differential privacy to analyze the inherent source anonymity of gossiping for a large class of graphs. First, we quantify the fundamental limit of source anonymity any gossip protocol can guarantee in an arbitrary communication graph. In particular, our result indicates that when the graph has poor connectivity, no gossip protocol can guarantee any meaningful level of differential privacy. This prompted us to further analyze graphs with controlled connectivity. We prove on these graphs that a large class of gossip protocols, namely cobra walks, offers tangible differential privacy guarantees to the source. In doing so, we introduce an original proof technique based on the reduction of a gossip protocol to what we call a random walk with probabilistic die out. This proof technique is of independent interest to the gossip community and readily extends to other protocols inherited from the security community, such as the Dandelion protocol. Interestingly, our tight analysis precisely captures the trade-off between dissemination time of a gossip protocol and its source anonymity.
Problem

Research questions and friction points this paper is trying to address.

Quantifying source anonymity limits in gossip protocols
Analyzing differential privacy in graphs with controlled connectivity
Exploring trade-off between dissemination time and source anonymity
Innovation

Methods, ideas, or system contributions that make the work stand out.

Uses differential privacy for source anonymity quantification
Introduces cobra walks for tangible privacy guarantees
Reduces gossip protocols to random walks with die out
🔎 Similar Papers
R
R. Guerraoui
Ecole Polytechnique Fédérale de Lausanne (EPFL), Switzerland
Anne-Marie Kermarrec
Anne-Marie Kermarrec
Professor, EPFL
Distributed systemssocial networksgossip protocols
A
A. Kucherenko
Ecole Polytechnique Fédérale de Lausanne (EPFL), Switzerland
R
Rafael Pinot
Ecole Polytechnique Fédérale de Lausanne (EPFL), Switzerland
S
S. Voitovych
University of Toronto, Canada