Tighter Privacy Auditing of Differentially Private Stochastic Gradient Descent in the Hidden State Threat Model

Fuente: Zenodo
Gespeichert in:
Bibliographische Detailangaben
1. Verfasser: Bhuekar, Apeksha
Format: Recurso digital
Veröffentlicht: Zenodo 2026
Online-Zugang:
Tags: Tag hinzufügen
Keine Tags, Fügen Sie den ersten Tag hinzu!
_version_ 1866901794723987456
author Bhuekar, Apeksha
author_facet Bhuekar, Apeksha
contents <p>We address the problem of empirical privacy auditing for differentially private stochas-</p> <p>tic gradient descent (DP-SGD) under the hidden state threat model, where adversaries only observe</p> <p>the final model parameters. Our work introduces a gradient-crafting framework that enables tighter</p> <p>auditing by allowing adversaries to pre-specify worst-case gradient sequences without access to interme-</p> <p>diate training checkpoints. We demonstrate that when a data point is used at every optimization step,</p> <p>hiding intermediate models provides no privacy amplification beyond standard composition bounds.</p> <p>For less frequent data usage patterns, we identify regimes where privacy amplification may occur for</p> <p>non-convex problems, though the effect is weaker than in convex settings. Our findings clarify the actual</p> <p>privacy loss in practical DP-SGD deployments and provide foundational insights for improved privacy</p> <p>accounting in the hidden state model.</p>
format Recurso digital
id zenodo_https___doi_org_10_5281_zenodo_18157025
institution Zenodo
language
publishDate 2026
publisher Zenodo
record_format zenodo
spellingShingle Tighter Privacy Auditing of Differentially Private Stochastic Gradient Descent in the Hidden State Threat Model
Bhuekar, Apeksha
<p>We address the problem of empirical privacy auditing for differentially private stochas-</p> <p>tic gradient descent (DP-SGD) under the hidden state threat model, where adversaries only observe</p> <p>the final model parameters. Our work introduces a gradient-crafting framework that enables tighter</p> <p>auditing by allowing adversaries to pre-specify worst-case gradient sequences without access to interme-</p> <p>diate training checkpoints. We demonstrate that when a data point is used at every optimization step,</p> <p>hiding intermediate models provides no privacy amplification beyond standard composition bounds.</p> <p>For less frequent data usage patterns, we identify regimes where privacy amplification may occur for</p> <p>non-convex problems, though the effect is weaker than in convex settings. Our findings clarify the actual</p> <p>privacy loss in practical DP-SGD deployments and provide foundational insights for improved privacy</p> <p>accounting in the hidden state model.</p>
title Tighter Privacy Auditing of Differentially Private Stochastic Gradient Descent in the Hidden State Threat Model
url https://doi.org/10.5281/zenodo.18157025