REVIEW 5 cited by
Debugging Differential Privacy: A Case Study for Privacy Auditing
Not yet reviewed by Pith; the record is open.
This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.
SPECIMEN: schema-true, not a live event
T0 review · schema-true
One-sentence machine reading of the paper's core claim.
pith:XXXXXXXX · record.json · timestamp
read the original abstract
Differential Privacy can provide provable privacy guarantees for training data in machine learning. However, the presence of proofs does not preclude the presence of errors. Inspired by recent advances in auditing which have been used for estimating lower bounds on differentially private algorithms, here we show that auditing can also be used to find flaws in (purportedly) differentially private schemes. In this case study, we audit a recent open source implementation of a differentially private deep learning algorithm and find, with 99.99999999% confidence, that the implementation does not satisfy the claimed differential privacy guarantee.
Forward citations
Cited by 5 Pith papers
-
Tight Privacy Audit in One Run
A one-run privacy audit claims tight lower bounds for general DP algorithms, but the core dominance proof is invalid.
-
Auditing Approximate Machine Unlearning for Differentially Private Models
Approximate machine unlearning can raise the privacy risk of retained samples in differentially private models, according to a new augmentation-based membership inference audit.
-
Optimizing Canaries for Privacy Auditing with Metagradient Descent
Optimized canary examples, crafted by metagradient descent on a small non-private model, more than double empirical epsilon lower bounds in black-box DP-SGD privacy audits on CIFAR-10.
-
UniAud: A Unified Auditing Framework for High Auditing Power and Utility with One Training Run
UniAud uses synthetic uncorrelated canaries and self-comparison inference to reach near-optimal empirical epsilon lower bounds in one black-box DP audit run, while UniAud++ improves the utility-auditing trade-off via ...
-
Membership Inference Attacks as Privacy Tools: Reliability, Disparity and Ensemble
MIAs expose different members depending on attack method and random seed; the paper quantifies this with coverage/stability and shows ensembling attacks yields stronger, more reliable privacy checks.
Discussion (0). Sign in to comment.