Bounding training data reconstruction in DP-SGD
Jamie Hayes, Borja Balle, Saeed Mahloujifar
Abstract
Differentially private training offers a protection which is usually interpreted as a guarantee against membership inference attacks. By proxy, this guarantee extends to other threats like reconstruction attacks attempting to extract complete training examples. Recent works provide evidence that if one does not need to protect against membership attacks but instead only wants to protect against training data reconstruction, then utility of private models can be improved because less noise is required to protect against these more ambitious attacks. We investigate this further in the context of DP-SGD, a standard algorithm for private deep learning, and provide an upper bound on the success of any reconstruction attack against DP-SGD together with an attack that empirically matches the predictions of our bound. Together, these two results open the door to fine-grained investigations on how to set the privacy parameters of DP-SGD in practice to protect against reconstruction attacks. Finally, we use our methods to demonstrate that different settings of the DP-SGD parameters leading to the same DP guarantees can result in significantly different success rates for reconstruction, indicating that the DP guarantee alone might not be a good proxy for controlling the protection against reconstruction attacks.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 07984f0e-d765-4962-809f-c9b6775811e8Cited by top-tier papers21
- Unleashing the Power of Randomization in Auditing Differentially Private MLKrishna Pillutla, Galen Andrew, Peter Kairouz, H. Brendan McMahan et al.NeurIPS 2023 · 35 citations
- Attack-Aware Noise Calibration for Differential PrivacyBogdan Kulynych, Juan Felipe Gómez, Georgios Kaissis, Flávio P. Calmon et al.NeurIPS 2024 · 23 citations
- Understanding Deep Gradient Leakage via Inversion Influence FunctionsHaobo Zhang, Junyuan Hong, Yuyang Deng, Mehrdad Mahdavi et al.NeurIPS 2023 · 16 citations
- Unifying Re-Identification, Attribute Inference, and Data Reconstruction Risks in Differential PrivacyBogdan Kulynych, Juan Felipe Gómez, Georgios Kaissis, Jamie Hayes et al.NeurIPS 2025 · 15 citations
- Beyond the Calibration Point: Mechanism Comparison in Differential PrivacyGeorgios Kaissis, Stefan Kolek, Borja Balle, Jamie Hayes et al.ICML 2024 · 11 citations
Builds on23
- Deep Learning with Differential PrivacyMartín Abadi, Andy Chu, Ian J. Goodfellow, H. Brendan McMahan et al.CCS 2016 · 7,620 citations
- Membership Inference Attacks Against Machine Learning ModelsReza Shokri, Marco Stronati, Congzheng Song, Vitaly ShmatikovS&P 2017 · 5,137 citations
- Extracting Training Data from Large Language ModelsNicholas Carlini, Florian Tramèr, Eric Wallace, Matthew Jagielski et al.USENIX Security 2021 · 2,866 citations
- Inverting Gradients - How easy is it to break privacy in federated learning?Jonas Geiping, Hartmut Bauermeister, Hannah Dröge, Michael MoellerNeurIPS 2020 · 1,822 citations
- The Secret Sharer: Evaluating and Testing Unintended Memorization in Neural NetworksNicholas Carlini, Chang Liu, Úlfar Erlingsson, Jernej Kos et al.USENIX Security 2019 · 1,386 citations
Related papers
- Closed-Form Bounds for DP-SGD against Record-level InferenceGiovanni Cherubin, Boris Köpf, Andrew Paverd, Shruti Tople et al.USENIX Security 2024 · 2 citations
- Bounding Training Data Reconstruction in Private (Deep) LearningChuan Guo, Brian Karrer, Kamalika Chaudhuri, Laurens van der MaatenICML 2022 · 66 citations
- DPSUR: Accelerating Differentially Private Stochastic Gradient Descent Using Selective Update and ReleaseJie Fu, Qingqing Ye, Haibo Hu, Zhili Chen et al.VLDB 2024 · 34 citations
- Adversary Instantiation: Lower Bounds for Differentially Private Machine LearningMilad Nasr, Shuang Song, Abhradeep Thakurta, Nicolas Papernot et al.S&P 2021 · 288 citations
- Machine Learning with Privacy for Protected AttributesSaeed Mahloujifar, Chuan Guo, G. Edward Suh, Kamalika ChaudhuriS&P 2025
