In white-box DP-SGD, canary-aligned signals form a sequence of random variables whose normalized sum is asymptotically Gaussian, enabling a new one-run auditing framework with tighter privacy lower bounds.
arXiv preprint arXiv:2509.08704 (2025)
2 Pith papers cite this work. Polarity classification is still indexing.
2
Pith papers citing it
years
2026 2representative citing papers
DP-SGD with expected or batch averaging (EASGM or ASGM) has weaker privacy guarantees than the standard subsampled Gaussian mechanism analysis, confirmed by theoretical re-analysis and audits of libraries including Opacus.
citing papers explorer
-
Let's Ask Gauss: Improved One-Run Privacy Auditing
In white-box DP-SGD, canary-aligned signals form a sequence of random variables whose normalized sum is asymptotically Gaussian, enabling a new one-run auditing framework with tighter privacy lower bounds.
-
Rethinking the Security of DP-SGD: A Corrected Analysis of Differentially Private Machine Learning
DP-SGD with expected or batch averaging (EASGM or ASGM) has weaker privacy guarantees than the standard subsampled Gaussian mechanism analysis, confirmed by theoretical re-analysis and audits of libraries including Opacus.