Pith. sign in

REVIEW 9 cited by

Debugging Differential Privacy: A Case Study for Privacy Auditing

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv 2202.12219 v2 pith:O2QP4L3X submitted 2022-02-24 cs.LG

classification cs.LG
keywords privacyauditingdifferentialdifferentiallyprivatecasefindimplementation
verification ladder T0 review T1 audit T2 compute T3 formal
0 comments
read the original abstract

Differential Privacy can provide provable privacy guarantees for training data in machine learning. However, the presence of proofs does not preclude the presence of errors. Inspired by recent advances in auditing which have been used for estimating lower bounds on differentially private algorithms, here we show that auditing can also be used to find flaws in (purportedly) differentially private schemes. In this case study, we audit a recent open source implementation of a differentially private deep learning algorithm and find, with 99.99999999% confidence, that the implementation does not satisfy the claimed differential privacy guarantee.

Discussion (0). Sign in to comment.

Forward citations

Cited by 9 Pith papers

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score.

  1. Auditing Apple's DifferentialPrivacy.framework: Implementation Bugs, Misconfigurations, and Practical Risks

    cs.CR 2026-05 accept novelty 8.0 of 10

    Audit finds DP violations in 5 of 9 mechanisms in Apple's framework due to insecure floating-point samplers and disabled local DP in secure aggregation, impacting 87% of macOS Sonoma and 68% of Sequoia data collection.

  2. Privacy Auditing with Zero (0) Training Run

    cs.CR 2026-05 unverdicted novelty 8.0 of 10

    Zero-Run auditing supplies valid lower bounds on differential privacy parameters from fixed member and non-member datasets by modeling and correcting distribution-shift confounding via causal-inference techniques.

  3. Auditing Apple's DifferentialPrivacy.framework: Implementation Bugs, Misconfigurations, and Practical Risks

    cs.CR 2026-05 conditional novelty 7.0 of 10

    Client-side audit of Apple's closed-source DP framework finds floating-point sampler bugs and misconfigurations that violate DP guarantees in 5 of 9 mechanisms, affecting 87% of data collection on Sonoma and 68% on Sequoia.

  4. Tight Privacy Audit in One Run

    cs.CR 2025-09 reject novelty 7.0 of 10

    A one-run privacy audit claims tight lower bounds for general DP algorithms, but the core dominance proof is invalid.

  5. Natural Identifiers for Privacy and Data Audits in Large Language Models

    cs.LG 2026-06 unverdicted novelty 6.0 of 10

    Introduces natural identifiers (NIDs) from common training data to support post-hoc differential privacy auditing and dataset inference for LLMs without retraining or private held-out sets.

  6. Auditing Approximate Machine Unlearning for Differentially Private Models

    cs.LG 2025-08 conditional novelty 6.0 of 10

    Approximate machine unlearning can raise the privacy risk of retained samples in differentially private models, according to a new augmentation-based membership inference audit.

  7. Optimizing Canaries for Privacy Auditing with Metagradient Descent

    cs.LG 2025-07 conditional novelty 6.0 of 10

    Optimized canary examples, crafted by metagradient descent on a small non-private model, more than double empirical epsilon lower bounds in black-box DP-SGD privacy audits on CIFAR-10.

  8. UniAud: A Unified Auditing Framework for High Auditing Power and Utility with One Training Run

    cs.CR 2025-07 conditional novelty 6.0 of 10

    UniAud uses synthetic uncorrelated canaries and self-comparison inference to reach near-optimal empirical epsilon lower bounds in one black-box DP audit run, while UniAud++ improves the utility-auditing trade-off via ...

  9. Membership Inference Attacks as Privacy Tools: Reliability, Disparity and Ensemble

    cs.LG 2025-06 conditional novelty 6.0 of 10

    MIAs expose different members depending on attack method and random seed; the paper quantifies this with coverage/stability and shows ensembling attacks yields stronger, more reliable privacy checks.

Pith tools