Auditing Differential Privacy in the Black-Box Setting

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Shi, Kaining, Ma, Cong
Format: Preprint
Published: 2025
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866909574714359808
author Shi, Kaining
Ma, Cong
author_facet Shi, Kaining
Ma, Cong
contents This paper introduces a novel theoretical framework for auditing differential privacy (DP) in a black-box setting. Leveraging the concept of $f$-differential privacy, we explicitly define type I and type II errors and propose an auditing mechanism based on conformal inference. Our approach robustly controls the type I error rate under minimal assumptions. Furthermore, we establish a fundamental impossibility result, demonstrating the inherent difficulty of simultaneously controlling both type I and type II errors without additional assumptions. Nevertheless, under a monotone likelihood ratio (MLR) assumption, our auditing mechanism effectively controls both errors. We also extend our method to construct valid confidence bands for the trade-off function in the finite-sample regime.
format Preprint
id arxiv_https___arxiv_org_abs_2503_12045
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle Auditing Differential Privacy in the Black-Box Setting
Shi, Kaining
Ma, Cong
Methodology
Cryptography and Security
Machine Learning
This paper introduces a novel theoretical framework for auditing differential privacy (DP) in a black-box setting. Leveraging the concept of $f$-differential privacy, we explicitly define type I and type II errors and propose an auditing mechanism based on conformal inference. Our approach robustly controls the type I error rate under minimal assumptions. Furthermore, we establish a fundamental impossibility result, demonstrating the inherent difficulty of simultaneously controlling both type I and type II errors without additional assumptions. Nevertheless, under a monotone likelihood ratio (MLR) assumption, our auditing mechanism effectively controls both errors. We also extend our method to construct valid confidence bands for the trade-off function in the finite-sample regime.
title Auditing Differential Privacy in the Black-Box Setting
topic Methodology
Cryptography and Security
Machine Learning
url https://arxiv.org/abs/2503.12045