{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2024:MJRZH5OFRBXSVW4U5FLT7KHEXU","short_pith_number":"pith:MJRZH5OF","schema_version":"1.0","canonical_sha256":"626393f5c5886f2adb94e9573fa8e4bd299855be1b9c8f7109e4b517345625ab","source":{"kind":"arxiv","id":"2405.14457","version":3},"attestation_state":"computed","paper":{"title":"Tighter Privacy Auditing of DP-SGD in the Hidden State Threat Model","license":"http://creativecommons.org/licenses/by/4.0/","headline":"","cross_cats":["cs.CR"],"primary_cat":"cs.LG","authors_text":"Aur\\'elien Bellet, Nicolas Papernot, Tudor Cebere","submitted_at":"2024-05-23T11:38:38Z","abstract_excerpt":"Machine learning models can be trained with formal privacy guarantees via differentially private optimizers such as DP-SGD. In this work, we focus on a threat model where the adversary has access only to the final model, with no visibility into intermediate updates. In the literature, this hidden state threat model exhibits a significant gap between the lower bound from empirical privacy auditing and the theoretical upper bound provided by privacy accounting. To challenge this gap, we propose to audit this threat model with adversaries that craft a gradient sequence designed to maximize the pr"},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"2405.14457","kind":"arxiv","version":3},"metadata":{"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.LG","submitted_at":"2024-05-23T11:38:38Z","cross_cats_sorted":["cs.CR"],"title_canon_sha256":"e588c2db54b3468c362e6d897df5f8fbd6418b1e89eec2a30d14342b5ef0e49c","abstract_canon_sha256":"3a32b672aa79e8fd1e319535ce49b3b0ae39585fca2e083d88378bd0af498cb2"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-07-05T11:11:32.199408Z","signature_b64":"FAQoxI8XsMBlWvuyL4asrdurQcm+TvdzOu7JQUxTlHOKIHRE/vanUdo7XDBExdFc5kuefgNKaOBwHq7jd+XEDg==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"626393f5c5886f2adb94e9573fa8e4bd299855be1b9c8f7109e4b517345625ab","last_reissued_at":"2026-07-05T11:11:32.198889Z","signature_status":"signed_v1","first_computed_at":"2026-07-05T11:11:32.198889Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"Tighter Privacy Auditing of DP-SGD in the Hidden State Threat Model","license":"http://creativecommons.org/licenses/by/4.0/","headline":"","cross_cats":["cs.CR"],"primary_cat":"cs.LG","authors_text":"Aur\\'elien Bellet, Nicolas Papernot, Tudor Cebere","submitted_at":"2024-05-23T11:38:38Z","abstract_excerpt":"Machine learning models can be trained with formal privacy guarantees via differentially private optimizers such as DP-SGD. In this work, we focus on a threat model where the adversary has access only to the final model, with no visibility into intermediate updates. In the literature, this hidden state threat model exhibits a significant gap between the lower bound from empirical privacy auditing and the theoretical upper bound provided by privacy accounting. To challenge this gap, we propose to audit this threat model with adversaries that craft a gradient sequence designed to maximize the pr"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2405.14457","kind":"arxiv","version":3},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2405.14457/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"2405.14457","created_at":"2026-07-05T11:11:32.198950+00:00"},{"alias_kind":"arxiv_version","alias_value":"2405.14457v3","created_at":"2026-07-05T11:11:32.198950+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2405.14457","created_at":"2026-07-05T11:11:32.198950+00:00"},{"alias_kind":"pith_short_12","alias_value":"MJRZH5OFRBXS","created_at":"2026-07-05T11:11:32.198950+00:00"},{"alias_kind":"pith_short_16","alias_value":"MJRZH5OFRBXSVW4U","created_at":"2026-07-05T11:11:32.198950+00:00"},{"alias_kind":"pith_short_8","alias_value":"MJRZH5OF","created_at":"2026-07-05T11:11:32.198950+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":1,"internal_anchor_count":0,"sample":[{"citing_arxiv_id":"2506.00158","citing_title":"Privacy Amplification in Differentially Private Zeroth-Order Optimization with Hidden States","ref_index":7,"is_internal_anchor":false}]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/MJRZH5OFRBXSVW4U5FLT7KHEXU","json":"https://pith.science/pith/MJRZH5OFRBXSVW4U5FLT7KHEXU.json","graph_json":"https://pith.science/api/pith-number/MJRZH5OFRBXSVW4U5FLT7KHEXU/graph.json","events_json":"https://pith.science/api/pith-number/MJRZH5OFRBXSVW4U5FLT7KHEXU/events.json","paper":"https://pith.science/paper/MJRZH5OF"},"agent_actions":{"view_html":"https://pith.science/pith/MJRZH5OFRBXSVW4U5FLT7KHEXU","download_json":"https://pith.science/pith/MJRZH5OFRBXSVW4U5FLT7KHEXU.json","view_paper":"https://pith.science/paper/MJRZH5OF","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=2405.14457&json=true","fetch_graph":"https://pith.science/api/pith-number/MJRZH5OFRBXSVW4U5FLT7KHEXU/graph.json","fetch_events":"https://pith.science/api/pith-number/MJRZH5OFRBXSVW4U5FLT7KHEXU/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/MJRZH5OFRBXSVW4U5FLT7KHEXU/action/timestamp_anchor","attest_storage":"https://pith.science/pith/MJRZH5OFRBXSVW4U5FLT7KHEXU/action/storage_attestation","attest_author":"https://pith.science/pith/MJRZH5OFRBXSVW4U5FLT7KHEXU/action/author_attestation","sign_citation":"https://pith.science/pith/MJRZH5OFRBXSVW4U5FLT7KHEXU/action/citation_signature","submit_replication":"https://pith.science/pith/MJRZH5OFRBXSVW4U5FLT7KHEXU/action/replication_record"}},"created_at":"2026-07-05T11:11:32.198950+00:00","updated_at":"2026-07-05T11:11:32.198950+00:00"}