Pith. sign in

REVIEW 3 cited by

CANIFE: Crafting Canaries for Empirical Privacy Measurement in Federated Learning

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv 2210.02912 v2 pith:2BP5PPK5 submitted 2022-10-06 cs.LG cs.CR

classification cs.LGcs.CR
keywords modelprivacycanifeempiricallearningmodelsupdatescanaries
verification ladder T0 review T1 audit T2 compute T3 formal
0 comments
read the original abstract

Federated Learning (FL) is a setting for training machine learning models in distributed environments where the clients do not share their raw data but instead send model updates to a server. However, model updates can be subject to attacks and leak private information. Differential Privacy (DP) is a leading mitigation strategy which involves adding noise to clipped model updates, trading off performance for strong theoretical privacy guarantees. Previous work has shown that the threat model of DP is conservative and that the obtained guarantees may be vacuous or may overestimate information leakage in practice. In this paper, we aim to achieve a tighter measurement of the model exposure by considering a realistic threat model. We propose a novel method, CANIFE, that uses canaries - carefully crafted samples by a strong adversary to evaluate the empirical privacy of a training round. We apply this attack to vision models trained on CIFAR-10 and CelebA and to language models trained on Sent140 and Shakespeare. In particular, in realistic FL scenarios, we demonstrate that the empirical per-round epsilon obtained with CANIFE is 4-5x lower than the theoretical bound.

Discussion (0). Sign in to comment.

Forward citations

Cited by 3 Pith papers

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score. Full citation record

  1. Tight Privacy Audit in One Run

    cs.CR 2025-09 reject novelty 7.0 of 10

    A one-run privacy audit claims tight lower bounds for general DP algorithms, but the core dominance proof is invalid.

  2. UniAud: A Unified Auditing Framework for High Auditing Power and Utility with One Training Run

    cs.CR 2025-07 conditional novelty 6.0 of 10

    UniAud uses synthetic uncorrelated canaries and self-comparison inference to reach near-optimal empirical epsilon lower bounds in one black-box DP audit run, while UniAud++ improves the utility-auditing trade-off via ...

  3. Relative Position Matters: Trajectory Prediction and Planning with Polar Representation

    cs.RO 2025-08 unverdicted novelty 5.0 of 10

    Polar coordinate representation is claimed to improve trajectory prediction and planning, with top results on Argoverse 2 and nuPlan, but only the abstract was reviewable.

Pith tools