Analyzing Privacy Leakage in Machine Learning via Multiple Hypothesis Testing: A Lesson From Fano
Chuan Guo, Alexandre Sablayrolles, Maziar Sanjabi
Abstract
Differential privacy (DP) is by far the most widely accepted framework for mitigating privacy risks in machine learning. However, exactly how small the privacy parameter needs to be to protect against certain privacy risks in practice is still not well-understood. In this work, we study data reconstruction attacks for discrete data and analyze it under the framework of multiple hypothesis testing. We utilize different variants of the celebrated Fano's inequality to derive upper bounds on the inferential power of a data reconstruction adversary when the model is trained differentially privately. Importantly, we show that if the underlying private data takes values from a set of size , then the target privacy parameter can be before the adversary gains significant inferential power. Our analysis offers theoretical evidence for the empirical effectiveness of DP against data reconstruction attacks even at relatively large values of .
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 165a8d9a-9254-4e12-9ce5-dd0774b9940bCited by top-tier papers9
- Bounding training data reconstruction in DP-SGDJamie Hayes, Borja Balle, Saeed MahloujifarNeurIPS 2023 · 73 citations
- Initialization Matters: Privacy-Utility Analysis of Overparameterized Neural NetworksJiayuan Ye, Zhenyu Zhu, Fanghui Liu, Reza Shokri et al.NeurIPS 2023 · 19 citations
- Unifying Re-Identification, Attribute Inference, and Data Reconstruction Risks in Differential PrivacyBogdan Kulynych, Juan Felipe Gómez, Georgios Kaissis, Jamie Hayes et al.NeurIPS 2025 · 15 citations
- Information Flow Control in Machine Learning through Modular Model ArchitectureTrishita Tiwari, Suchin Gururangan, Chuan Guo, Weizhe Hua et al.USENIX Security 2024 · 12 citations
- Differentially Private Representation Learning via Image CaptioningTom Sander, Yaodong Yu, Maziar Sanjabi, Alain Oliviero Durmus et al.ICML 2024 · 9 citations
Builds on18
- Deep Learning with Differential PrivacyMartín Abadi, Andy Chu, Ian J. Goodfellow, H. Brendan McMahan et al.CCS 2016 · 7,620 citations
- Membership Inference Attacks Against Machine Learning ModelsReza Shokri, Marco Stronati, Congzheng Song, Vitaly ShmatikovS&P 2017 · 5,137 citations
- Extracting Training Data from Large Language ModelsNicholas Carlini, Florian Tramèr, Eric Wallace, Matthew Jagielski et al.USENIX Security 2021 · 2,866 citations
- Inverting Gradients - How easy is it to break privacy in federated learning?Jonas Geiping, Hartmut Bauermeister, Hannah Dröge, Michael MoellerNeurIPS 2020 · 1,822 citations
- Comprehensive Privacy Analysis of Deep Learning: Passive and Active White-box Inference Attacks against Centralized and Federated LearningMilad Nasr, Reza Shokri, Amir HoumansadrS&P 2019 · 1,778 citations
Related papers
- Bounding Training Data Reconstruction in Private (Deep) LearningChuan Guo, Brian Karrer, Kamalika Chaudhuri, Laurens van der MaatenICML 2022 · 66 citations
- Reconstructing Training Data with Informed AdversariesBorja Balle, Giovanni Cherubin, Jamie HayesS&P 2022 · 214 citations
- Defending Against Data Reconstruction Attacks in Federated Learning: An Information Theory ApproachQi Tan, Qi Li, Yi Zhao, Zhuotao Liu et al.USENIX Security 2024 · 10 citations
- Adversary Instantiation: Lower Bounds for Differentially Private Machine LearningMilad Nasr, Shuang Song, Abhradeep Thakurta, Nicolas Papernot et al.S&P 2021 · 288 citations
- Understanding Disclosure Risk in Differential Privacy with Applications to Noise Calibration and AuditingPatricia Guerra-Balboa, Annika Sauer, Héber Hwang Arcolezi, Thorsten StrufeVLDB 2026
