Auditing $f$-Differential Privacy in One Run

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Mahloujifar, Saeed, Melis, Luca, Chaudhuri, Kamalika
Format: Preprint
Published: 2024
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866909370709704704
author Mahloujifar, Saeed
Melis, Luca
Chaudhuri, Kamalika
author_facet Mahloujifar, Saeed
Melis, Luca
Chaudhuri, Kamalika
contents Empirical auditing has emerged as a means of catching some of the flaws in the implementation of privacy-preserving algorithms. Existing auditing mechanisms, however, are either computationally inefficient requiring multiple runs of the machine learning algorithms or suboptimal in calculating an empirical privacy. In this work, we present a tight and efficient auditing procedure and analysis that can effectively assess the privacy of mechanisms. Our approach is efficient; similar to the recent work of Steinke, Nasr, and Jagielski (2023), our auditing procedure leverages the randomness of examples in the input dataset and requires only a single run of the target mechanism. And it is more accurate; we provide a novel analysis that enables us to achieve tight empirical privacy estimates by using the hypothesized $f$-DP curve of the mechanism, which provides a more accurate measure of privacy than the traditional $ε,δ$ differential privacy parameters. We use our auditing procure and analysis to obtain empirical privacy, demonstrating that our auditing procedure delivers tighter privacy estimates.
format Preprint
id arxiv_https___arxiv_org_abs_2410_22235
institution arXiv
publishDate 2024
record_format arxiv
spellingShingle Auditing $f$-Differential Privacy in One Run
Mahloujifar, Saeed
Melis, Luca
Chaudhuri, Kamalika
Machine Learning
Cryptography and Security
Empirical auditing has emerged as a means of catching some of the flaws in the implementation of privacy-preserving algorithms. Existing auditing mechanisms, however, are either computationally inefficient requiring multiple runs of the machine learning algorithms or suboptimal in calculating an empirical privacy. In this work, we present a tight and efficient auditing procedure and analysis that can effectively assess the privacy of mechanisms. Our approach is efficient; similar to the recent work of Steinke, Nasr, and Jagielski (2023), our auditing procedure leverages the randomness of examples in the input dataset and requires only a single run of the target mechanism. And it is more accurate; we provide a novel analysis that enables us to achieve tight empirical privacy estimates by using the hypothesized $f$-DP curve of the mechanism, which provides a more accurate measure of privacy than the traditional $ε,δ$ differential privacy parameters. We use our auditing procure and analysis to obtain empirical privacy, demonstrating that our auditing procedure delivers tighter privacy estimates.
title Auditing $f$-Differential Privacy in One Run
topic Machine Learning
Cryptography and Security
url https://arxiv.org/abs/2410.22235