One-shot Empirical Privacy Estimation for Federated Learning

Fuente: arXiv
Salvato in:
Dettagli Bibliografici
Autori principali: Andrew, Galen, Kairouz, Peter, Oh, Sewoong, Oprea, Alina, McMahan, H. Brendan, Suriyakumar, Vinith M.
Natura: Preprint
Pubblicazione: 2023
Soggetti:
Accesso online:
Tags: Aggiungi Tag
Nessun Tag, puoi essere il primo ad aggiungerne!!
_version_ 1866911845082726400
author Andrew, Galen
Kairouz, Peter
Oh, Sewoong
Oprea, Alina
McMahan, H. Brendan
Suriyakumar, Vinith M.
author_facet Andrew, Galen
Kairouz, Peter
Oh, Sewoong
Oprea, Alina
McMahan, H. Brendan
Suriyakumar, Vinith M.
contents Privacy estimation techniques for differentially private (DP) algorithms are useful for comparing against analytical bounds, or to empirically measure privacy loss in settings where known analytical bounds are not tight. However, existing privacy auditing techniques usually make strong assumptions on the adversary (e.g., knowledge of intermediate model iterates or the training data distribution), are tailored to specific tasks, model architectures, or DP algorithm, and/or require retraining the model many times (typically on the order of thousands). These shortcomings make deploying such techniques at scale difficult in practice, especially in federated settings where model training can take days or weeks. In this work, we present a novel "one-shot" approach that can systematically address these challenges, allowing efficient auditing or estimation of the privacy loss of a model during the same, single training run used to fit model parameters, and without requiring any a priori knowledge about the model architecture, task, or DP training algorithm. We show that our method provides provably correct estimates for the privacy loss under the Gaussian mechanism, and we demonstrate its performance on well-established FL benchmark datasets under several adversarial threat models.
format Preprint
id arxiv_https___arxiv_org_abs_2302_03098
institution arXiv
publishDate 2023
record_format arxiv
spellingShingle One-shot Empirical Privacy Estimation for Federated Learning
Andrew, Galen
Kairouz, Peter
Oh, Sewoong
Oprea, Alina
McMahan, H. Brendan
Suriyakumar, Vinith M.
Machine Learning
Cryptography and Security
Privacy estimation techniques for differentially private (DP) algorithms are useful for comparing against analytical bounds, or to empirically measure privacy loss in settings where known analytical bounds are not tight. However, existing privacy auditing techniques usually make strong assumptions on the adversary (e.g., knowledge of intermediate model iterates or the training data distribution), are tailored to specific tasks, model architectures, or DP algorithm, and/or require retraining the model many times (typically on the order of thousands). These shortcomings make deploying such techniques at scale difficult in practice, especially in federated settings where model training can take days or weeks. In this work, we present a novel "one-shot" approach that can systematically address these challenges, allowing efficient auditing or estimation of the privacy loss of a model during the same, single training run used to fit model parameters, and without requiring any a priori knowledge about the model architecture, task, or DP training algorithm. We show that our method provides provably correct estimates for the privacy loss under the Gaussian mechanism, and we demonstrate its performance on well-established FL benchmark datasets under several adversarial threat models.
title One-shot Empirical Privacy Estimation for Federated Learning
topic Machine Learning
Cryptography and Security
url https://arxiv.org/abs/2302.03098