Pith. sign in

REVIEW 2 cited by

Auditing Private Prediction

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv 2402.09403 v1 pith:AHPON5JL submitted 2024-02-14 cs.CR

classification cs.CR
keywords privacyauditingleakagepredictionprivatealgorithmsadversariesbound
verification ladder T0 review T1 audit T2 compute T3 formal

Signed reviews

No signed human review yet.

0 comments
read the original abstract

Differential privacy (DP) offers a theoretical upper bound on the potential privacy leakage of analgorithm, while empirical auditing establishes a practical lower bound. Auditing techniques exist forDP training algorithms. However machine learning can also be made private at inference. We propose thefirst framework for auditing private prediction where we instantiate adversaries with varying poisoningand query capabilities. This enables us to study the privacy leakage of four private prediction algorithms:PATE [Papernot et al., 2016], CaPC [Choquette-Choo et al., 2020], PromptPATE [Duan et al., 2023],and Private-kNN [Zhu et al., 2020]. To conduct our audit, we introduce novel techniques to empiricallyevaluate privacy leakage in terms of Renyi DP. Our experiments show that (i) the privacy analysis ofprivate prediction can be improved, (ii) algorithms which are easier to poison lead to much higher privacyleakage, and (iii) the privacy leakage is significantly lower for adversaries without query control than thosewith full control.

Discussion (0). Continue with ORCID to comment.

Forward citations

Cited by 2 Pith papers

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score. Full citation record

  1. Federated One-Shot Learning with Data Privacy and Objective-Hiding

    cs.CR 2025-04 conditional novelty 7.0 of 10

    A three-stage protocol combining secret sharing and graph-based PIR hides both the federator's target objective and clients' labels in one-shot federated learning.

  2. Enhancing One-run Privacy Auditing with Quantile Regression-Based Membership Inference

    cs.LG 2025-06 conditional novelty 4.0 of 10

    Applying quantile regression based membership inference scoring to one-run black-box DP-SGD auditing yields tighter empirical privacy lower bounds on CIFAR-10, though the gains are uneven and the efficiency claim is o...

Pith tools