Widespread Underestimation of Sensitivity in Differentially Private Libraries and How to Fix It
Sílvia Casacuberta, Michael Shoemate, Salil P. Vadhan, Connor Wagaman
Abstract
We identify a new class of vulnerabilities in implementations of differential privacy. Specifically, they arise when computing basic statistics such as sums, thanks to discrepancies between the implemented arithmetic using finite data types (namely, ints or floats) and idealized arithmetic over the reals or integers. These discrepancies cause the sensitivity of the implemented statistics (i.e., how much one individual's data can affect the result) to be much larger than the sensitivity we expect. Consequently, essentially all differential privacy libraries fail to introduce enough noise to meet the requirements of differential privacy, and we show that this may be exploited in realistic attacks that can extract individual-level information from private query systems. In addition to presenting these vulnerabilities, we also provide a number of solutions, which modify or constrain the way in which the sum is implemented in order to recover the idealized or near-idealized bounds on sensitivity.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 11d9943d-2c4c-4f8f-abb5-974aad7a4b0bCited by top-tier papers13
- Causes and Effects of Unanticipated Numerical Deviations in Neural Network Inference FrameworksAlexander Schlögl, Nora Hofer, Rainer BöhmeNeurIPS 2023 · 31 citations
- Group and Attack: Auditing Differential PrivacyJohan Lokna, Anouk Paradis, Dimitar I. Dimitrov, Martin T. VechevCCS 2023 · 10 citations
- An Optimal and Scalable Matrix Mechanism for Noisy Marginals under Convex Loss FunctionsYingtai Xiao, Guanlin He, Danfeng Zhang, Daniel KiferNeurIPS 2023 · 8 citations
- Elephants Do Not Forget: Differential Privacy with State Continuity for Privacy BudgetJiankai Jin, Chitchanok Chuengsatiansup, Toby Murray, Benjamin I. P. Rubinstein et al.CCS 2024 · 4 citations
- A Framework for Differential Privacy Against Timing AttacksZachary Ratliff, Salil P. VadhanCCS 2024 · 3 citations
Builds on4
- Deep Learning with Differential PrivacyMartín Abadi, Andy Chu, Ian J. Goodfellow, H. Brendan McMahan et al.CCS 2016 · 7,620 citations
- The Discrete Gaussian for Differential PrivacyClément L. Canonne, Gautam Kamath, Thomas SteinkeNeurIPS 2020 · 355 citations
- Are We There Yet? Timing and Floating-Point Attacks on Differential Privacy SystemsJiankai Jin, Eleanor McMurtry, Benjamin I. P. Rubinstein, Olga OhrimenkoS&P 2022 · 57 citations
- Implementing the Exponential Mechanism with Base-2 Differential PrivacyChristina IlventoCCS 2020 · 2 citations
Related papers
- Timing Attacks on Differential Privacy are PracticalZachary Ratliff, Nicolás Berrios, James MickensCCS 2025
- Residual Sensitivity for Differentially Private Multi-Way JoinsWei Dong, Ke YiSIGMOD 2021 · 32 citations
- DP-PQD: Privately Detecting Per-Query Gaps In Synthetic Data Generated By Black-Box MechanismsShweta Patwa, Danyu Sun, Amir Gilad, Ashwin Machanavajjhala et al.VLDB 2024 · 2 citations
- Counting Distinct Elements Under Person-Level Differential PrivacyThomas Steinke, Alexander KnopNeurIPS 2023 · 4 citations
- An Uncertainty Principle is a Price of Privacy-Preserving MicrodataJohn M. Abowd, Robert Ashmead, Ryan Cumings-Menon, Simson L. Garfinkel et al.NeurIPS 2021 · 17 citations
