Tighter Privacy Auditing of Differentially Private Stochastic Gradient Descent in the Hidden State Threat Model
Fuente:
Zenodo
Gespeichert in:
| 1. Verfasser: | |
|---|---|
| Format: | Recurso digital |
| Veröffentlicht: |
Zenodo
2026
|
| Online-Zugang: | |
| Tags: |
Tag hinzufügen
Keine Tags, Fügen Sie den ersten Tag hinzu!
|
| _version_ | 1866901794723987456 |
|---|---|
| author | Bhuekar, Apeksha |
| author_facet | Bhuekar, Apeksha |
| contents | <p>We address the problem of empirical privacy auditing for differentially private stochas-</p> <p>tic gradient descent (DP-SGD) under the hidden state threat model, where adversaries only observe</p> <p>the final model parameters. Our work introduces a gradient-crafting framework that enables tighter</p> <p>auditing by allowing adversaries to pre-specify worst-case gradient sequences without access to interme-</p> <p>diate training checkpoints. We demonstrate that when a data point is used at every optimization step,</p> <p>hiding intermediate models provides no privacy amplification beyond standard composition bounds.</p> <p>For less frequent data usage patterns, we identify regimes where privacy amplification may occur for</p> <p>non-convex problems, though the effect is weaker than in convex settings. Our findings clarify the actual</p> <p>privacy loss in practical DP-SGD deployments and provide foundational insights for improved privacy</p> <p>accounting in the hidden state model.</p> |
| format | Recurso digital |
| id | zenodo_https___doi_org_10_5281_zenodo_18157025 |
| institution | Zenodo |
| language | |
| publishDate | 2026 |
| publisher | Zenodo |
| record_format | zenodo |
| spellingShingle | Tighter Privacy Auditing of Differentially Private Stochastic Gradient Descent in the Hidden State Threat Model Bhuekar, Apeksha <p>We address the problem of empirical privacy auditing for differentially private stochas-</p> <p>tic gradient descent (DP-SGD) under the hidden state threat model, where adversaries only observe</p> <p>the final model parameters. Our work introduces a gradient-crafting framework that enables tighter</p> <p>auditing by allowing adversaries to pre-specify worst-case gradient sequences without access to interme-</p> <p>diate training checkpoints. We demonstrate that when a data point is used at every optimization step,</p> <p>hiding intermediate models provides no privacy amplification beyond standard composition bounds.</p> <p>For less frequent data usage patterns, we identify regimes where privacy amplification may occur for</p> <p>non-convex problems, though the effect is weaker than in convex settings. Our findings clarify the actual</p> <p>privacy loss in practical DP-SGD deployments and provide foundational insights for improved privacy</p> <p>accounting in the hidden state model.</p> |
| title | Tighter Privacy Auditing of Differentially Private Stochastic Gradient Descent in the Hidden State Threat Model |
| url | https://doi.org/10.5281/zenodo.18157025 |