Crowdsourcing applications are vulnerable to Sybil attacks where attackers create many accounts to submit bogus or malicious data at scale. The traditional approach to manage Sybil attacks is privacy invasive since it requires contributors to identify themselves when contributing data. In this paper we present a new reporting protocol which supports the anonymous submission of data to crowdsourcing systems by honest contributors, while identifying malicious individuals who attempt to submit multiple reports. Our approach builds on Chaum’s digital cash, and we demonstrate its practicality and deployability on mobile devices based on its low storage, network, runtime, and power requirements.
We thank Daniel Hugenroth for his help in obtaining mobile device power consumption measurements. We are grateful to anonymous reviewers for their feedback. We acknowledge and thank Fundación Mapfre Guanarteme and Nokia Bell Labs for their generous financial support. The views, opinions and findings in this paper are those of the authors and not necessarily those of our funders.
