Adversarial Sample-Based Approach for Tighter Privacy Auditing in Final Model-Only Scenarios

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Yoon, Sangyeon, Jeung, Wonje, No, Albert
Format: Preprint
Published: 2024
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866913704405106688
author Yoon, Sangyeon
Jeung, Wonje
No, Albert
author_facet Yoon, Sangyeon
Jeung, Wonje
No, Albert
contents Auditing Differentially Private Stochastic Gradient Descent (DP-SGD) in the final model setting is challenging and often results in empirical lower bounds that are significantly looser than theoretical privacy guarantees. We introduce a novel auditing method that achieves tighter empirical lower bounds without additional assumptions by crafting worst-case adversarial samples through loss-based input-space auditing. Our approach surpasses traditional canary-based heuristics and is effective in final model-only scenarios. Specifically, with a theoretical privacy budget of $\varepsilon = 10.0$, our method achieves empirical lower bounds of $4.914$, compared to the baseline of $4.385$ for MNIST. Our work offers a practical framework for reliable and accurate privacy auditing in differentially private machine learning.
format Preprint
id arxiv_https___arxiv_org_abs_2412_01756
institution arXiv
publishDate 2024
record_format arxiv
spellingShingle Adversarial Sample-Based Approach for Tighter Privacy Auditing in Final Model-Only Scenarios
Yoon, Sangyeon
Jeung, Wonje
No, Albert
Cryptography and Security
Machine Learning
Auditing Differentially Private Stochastic Gradient Descent (DP-SGD) in the final model setting is challenging and often results in empirical lower bounds that are significantly looser than theoretical privacy guarantees. We introduce a novel auditing method that achieves tighter empirical lower bounds without additional assumptions by crafting worst-case adversarial samples through loss-based input-space auditing. Our approach surpasses traditional canary-based heuristics and is effective in final model-only scenarios. Specifically, with a theoretical privacy budget of $\varepsilon = 10.0$, our method achieves empirical lower bounds of $4.914$, compared to the baseline of $4.385$ for MNIST. Our work offers a practical framework for reliable and accurate privacy auditing in differentially private machine learning.
title Adversarial Sample-Based Approach for Tighter Privacy Auditing in Final Model-Only Scenarios
topic Cryptography and Security
Machine Learning
url https://arxiv.org/abs/2412.01756