Optimizing Canaries for Privacy Auditing with Metagradient Descent

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Boglioni, Matteo, Liu, Terrance, Ilyas, Andrew, Wu, Zhiwei Steven
Format: Preprint
Published: 2025
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866912495104425984
author Boglioni, Matteo
Liu, Terrance
Ilyas, Andrew
Wu, Zhiwei Steven
author_facet Boglioni, Matteo
Liu, Terrance
Ilyas, Andrew
Wu, Zhiwei Steven
contents In this work we study black-box privacy auditing, where the goal is to lower bound the privacy parameter of a differentially private learning algorithm using only the algorithm's outputs (i.e., final trained model). For DP-SGD (the most successful method for training differentially private deep learning models), the canonical approach auditing uses membership inference-an auditor comes with a small set of special "canary" examples, inserts a random subset of them into the training set, and then tries to discern which of their canaries were included in the training set (typically via a membership inference attack). The auditor's success rate then provides a lower bound on the privacy parameters of the learning algorithm. Our main contribution is a method for optimizing the auditor's canary set to improve privacy auditing, leveraging recent work on metagradient optimization. Our empirical evaluation demonstrates that by using such optimized canaries, we can improve empirical lower bounds for differentially private image classification models by over 2x in certain instances. Furthermore, we demonstrate that our method is transferable and efficient: canaries optimized for non-private SGD with a small model architecture remain effective when auditing larger models trained with DP-SGD.
format Preprint
id arxiv_https___arxiv_org_abs_2507_15836
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle Optimizing Canaries for Privacy Auditing with Metagradient Descent
Boglioni, Matteo
Liu, Terrance
Ilyas, Andrew
Wu, Zhiwei Steven
Machine Learning
Cryptography and Security
In this work we study black-box privacy auditing, where the goal is to lower bound the privacy parameter of a differentially private learning algorithm using only the algorithm's outputs (i.e., final trained model). For DP-SGD (the most successful method for training differentially private deep learning models), the canonical approach auditing uses membership inference-an auditor comes with a small set of special "canary" examples, inserts a random subset of them into the training set, and then tries to discern which of their canaries were included in the training set (typically via a membership inference attack). The auditor's success rate then provides a lower bound on the privacy parameters of the learning algorithm. Our main contribution is a method for optimizing the auditor's canary set to improve privacy auditing, leveraging recent work on metagradient optimization. Our empirical evaluation demonstrates that by using such optimized canaries, we can improve empirical lower bounds for differentially private image classification models by over 2x in certain instances. Furthermore, we demonstrate that our method is transferable and efficient: canaries optimized for non-private SGD with a small model architecture remain effective when auditing larger models trained with DP-SGD.
title Optimizing Canaries for Privacy Auditing with Metagradient Descent
topic Machine Learning
Cryptography and Security
url https://arxiv.org/abs/2507.15836