DP-Auditorium: A Large-Scale Library for Auditing Differential Privacy
William Kong, Andrés Muñoz Medina, Mónica Ribero, Umar Syed
Abstract
New regulations and increased awareness of data privacy have led to the deployment of new and more efficient differentially private mechanisms across both public institutions and industries. With the growing adoption of differential privacy, there is also a risk of introducing bugs into both the derivation of new mechanisms and their implementation. Ensuring these mechanisms is therefore crucial to ensure proper protection of data. However since differential privacy is not a property of a single output of a mechanism but a property of the mechanism itself, testing whether a mechanism is differentially private is not a trivial task. While ad hoc testing techniques exist under specific assumptions, no concerted effort has been made by the research community to develop a flexible and extendable tool for testing differentially private mechanisms. This paper introduces DP-Auditorium as a step advancing research in this direction. The main idea behind DP-Auditorium is to abstract the problem of testing differential privacy into two steps: (1) measuring the distance between distributions, and (2) finding neighboring datasets where a mechanism generates output distributions maximizing such distance. From a technical point of view, we propose three new algorithms for evaluating the distance between distributions. While these algorithms are well-known in the statistics community, we provide new estimation guarantees by leveraging the fact that we are only interested in verifying whether a mechanism is differentially private, and not on obtaining an exact estimate of the distance between two distributions. DP-Auditorium is easily extensible, as demonstrated in this paper by implementing a well-known approximate differential privacy testing algorithm to our library. Finally, we provide an extensive comparison to date of multiple testers across varying sample sizes and differential privacy parameters, demonstrating that there is no single tester that dominates all others, and that in order to ensure proper testing of mechanisms, one requires a combination of different techniques.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers2
- Sequentially Auditing Differential PrivacyTomás González Lara, Mateo Dulce-Rubio, Aaditya Ramdas, Mónica RiberoNeurIPS 2025 · 6 citations
- General-Purpose f-DP Estimation and Auditing in a Black-Box SettingÖnder Askin, Holger Dette, Martin Dunsche, Tim Kutta et al.USENIX Security 2025
Builds on12
- Deep Learning with Differential PrivacyMartín Abadi, Andy Chu, Ian J. Goodfellow, H. Brendan McMahan et al.CCS 2016 · 7,620 citations
- Evaluating Differentially Private Machine Learning in PracticeBargav Jayaraman, David EvansUSENIX Security 2019 · 586 citations
- Auditing Differentially Private Machine Learning: How Private is Private SGD?Matthew Jagielski, Jonathan R. Ullman, Alina OpreaNeurIPS 2020 · 354 citations
- Adversary Instantiation: Lower Bounds for Differentially Private Machine LearningMilad Nasr, Shuang Song, Abhradeep Thakurta, Nicolas Papernot et al.S&P 2021 · 288 citations
- GAN-Leaks: A Taxonomy of Membership Inference Attacks against Generative ModelsDingfan Chen, Ning Yu, Yang Zhang, Mario FritzCCS 2020 · 278 citations
Related papers
- Testing differential privacy with dual interpretersHengchu Zhang, Edo Roth, Andreas Haeberlen, Benjamin C. Pierce et al.OOPSLA 2020 · 15 citations
- Eureka: A General Framework for Black-box Differential Privacy EstimatorsYun Lu, Malik Magdon-Ismail, Yu Wei, Vassilis ZikasS&P 2024 · 16 citations
- Auditing -differential privacy in one runSaeed Mahloujifar, Luca Melis, Kamalika ChaudhuriICML 2025
- Sequential Auditing for f-Differential PrivacyTim Kutta, Martin Dunsche, Yu Wei, Vassilis ZikasUSENIX Security 2026
- Group and Attack: Auditing Differential PrivacyJohan Lokna, Anouk Paradis, Dimitar I. Dimitrov, Martin T. VechevCCS 2023 · 10 citations
