This paper studies security for data aggregation in sensor networks. Current aggregation schemes were designed without security in mind and there are easy attacks against them. We examine several approaches for making these aggregation schemes more resilient against certain attacks, and we propose a mathematical framework for formally evaluating their security. Categories and Subject Descriptors D.4.6 [Operating Systems]: Security and Protection General Terms Security Keywords aggregation, sensor networks, node capture attack, multiparty computation, robust statistics, average, mean, median