Nearly Tight Black-Box Auditing of Differentially Private Machine Learning
Meenatchi Sundaram Muthu Selva Annamalai, Emiliano De Cristofaro
Abstract
This paper presents an auditing procedure for the Differentially Private Stochastic Gradient Descent (DP-SGD) algorithm in the black-box threat model that is substantially tighter than prior work. The main intuition is to craft worst-case initial model parameters, as DP-SGD's privacy analysis is agnostic to the choice of the initial model parameters. For models trained on MNIST and CIFAR-10 at theoretical , our auditing procedure yields empirical estimates of and , respectively, on a 1,000-record sample and and on the full datasets. By contrast, previous audits were only (relatively) tight in stronger white-box models, where the adversary can access the model's inner parameters and insert arbitrary gradients. Overall, our auditing procedure can offer valuable insight into how the privacy analysis of DP-SGD could be improved and detect bugs and DP violations in real-world implementations. The source code needed to reproduce our experiments is available at https://github.com/spalabucr/bb-audit-dpsgd.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 3d1035a7-5b8a-49a7-bbe6-540c4092f338Cited by top-tier papers12
- To Shuffle or not to Shuffle: Auditing DP-SGD with ShufflingMeenatchi Sundaram Muthu Selva Annamalai, Borja Balle, Jamie Hayes, Emiliano De CristofaroNDSS 2026 · 11 citations
- Optimizing Canaries for Privacy Auditing with Metagradient DescentMatteo Boglioni, Terrance Liu, Andrew Ilyas, Steven WuICLR 2026 · 7 citations
- Tighter Privacy Auditing of DP-SGD in the Hidden State Threat ModelTudor Ioan Cebere, Aurélien Bellet, Nicolas PapernotICLR 2025 · 1 citation
- DPImageBench: A Unified Benchmark for Differentially Private Image SynthesisChen Gong, Kecen Li, Zinan Lin, Tianhao WangCCS 2025 · 1 citation
- Understanding Disclosure Risk in Differential Privacy with Applications to Noise Calibration and AuditingPatricia Guerra-Balboa, Annika Sauer, Héber Hwang Arcolezi, Thorsten StrufeVLDB 2026
Builds on23
- Deep Learning with Differential PrivacyMartín Abadi, Andy Chu, Ian J. Goodfellow, H. Brendan McMahan et al.CCS 2016 · 7,620 citations
- Membership Inference Attacks Against Machine Learning ModelsReza Shokri, Marco Stronati, Congzheng Song, Vitaly ShmatikovS&P 2017 · 5,137 citations
- Membership Inference Attacks From First PrinciplesNicholas Carlini, Steve Chien, Milad Nasr, Shuang Song et al.S&P 2022 · 1,049 citations
- Evaluating Differentially Private Machine Learning in PracticeBargav Jayaraman, David EvansUSENIX Security 2019 · 586 citations
- Auditing Differentially Private Machine Learning: How Private is Private SGD?Matthew Jagielski, Jonathan R. Ullman, Alina OpreaNeurIPS 2020 · 354 citations
Related papers
- Tight Auditing of Differentially Private Machine LearningMilad Nasr, Jamie Hayes, Thomas Steinke, Borja Balle et al.USENIX Security 2023
- Revisiting Differentially Private Hyper-parameter TuningZihang Xiang, Tianhao Wang, Cheng-Long Wang, Di WangNDSS 2026 · 7 citations
- "What do you want from theory alone?" Experimenting with Tight Auditing of Differentially Private Synthetic Data GenerationMeenatchi Sundaram Muthu Selva Annamalai, Georgi Ganev, Emiliano De CristofaroUSENIX Security 2024 · 24 citations
- The Last Iterate Advantage: Empirical Auditing and Principled Heuristic Analysis of Differentially Private SGDMilad Nasr, Thomas Steinke, Borja Balle, Christopher A. Choquette-Choo et al.ICLR 2025
- Sequentially Auditing Differential PrivacyTomás González Lara, Mateo Dulce-Rubio, Aaditya Ramdas, Mónica RiberoNeurIPS 2025 · 6 citations
