Bayesian Estimation of Differential Privacy
Santiago Zanella-Béguelin, Lukas Wutschitz, Shruti Tople, Ahmed Salem, Victor Rühle, Andrew Paverd, Mohammad Naseri, Boris Köpf, Daniel Jones
Abstract
Algorithms such as Differentially Private SGD enable training machine learning models with formal privacy guarantees. However, there is a discrepancy between the protection that such algorithms guarantee in theory and the protection they afford in practice. An emerging strand of work empirically estimates the protection afforded by differentially private training as a confidence interval for the privacy budget spent on training a model. Existing approaches derive confidence intervals for from confidence intervals for the false positive and false negative rates of membership inference attacks. Unfortunately, obtaining narrow high-confidence intervals for using this method requires an impractically large sample size and training as many models as samples. We propose a novel Bayesian method that greatly reduces sample size, and adapt and validate a heuristic to draw more than one sample per trained model. Our Bayesian method exploits the hypothesis testing interpretation of differential privacy to obtain a posterior for (not just a confidence interval) from the joint posterior of the false positive and false negative rates of membership inference attacks. For the same sample size and confidence, we derive confidence intervals for around 40% narrower than prior work. The heuristic, which we adapt from label-only DP, can be used to further reduce the number of trained models needed to get enough samples by up to 2 orders of magnitude.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext e7c0cf2a-d848-4c77-bd83-910c67687611Cited by top-tier papers24
- Privacy Auditing with One (1) Training RunThomas Steinke, Milad Nasr, Matthew JagielskiNeurIPS 2023 · 178 citations
- Label Poisoning is All You NeedRishi D. Jha, Jonathan Hayase, Sewoong OhNeurIPS 2023 · 58 citations
- One-shot Empirical Privacy Estimation for Federated LearningGalen Andrew, Peter Kairouz, Sewoong Oh, Alina Oprea et al.ICLR 2024 · 48 citations
- Unleashing the Power of Randomization in Auditing Differentially Private MLKrishna Pillutla, Galen Andrew, Peter Kairouz, H. Brendan McMahan et al.NeurIPS 2023 · 35 citations
- Nearly Tight Black-Box Auditing of Differentially Private Machine LearningMeenatchi Sundaram Muthu Selva Annamalai, Emiliano De CristofaroNeurIPS 2024 · 32 citations
Builds on15
- Deep Learning with Differential PrivacyMartín Abadi, Andy Chu, Ian J. Goodfellow, H. Brendan McMahan et al.CCS 2016 · 7,620 citations
- Membership Inference Attacks Against Machine Learning ModelsReza Shokri, Marco Stronati, Congzheng Song, Vitaly ShmatikovS&P 2017 · 5,137 citations
- The Secret Sharer: Evaluating and Testing Unintended Memorization in Neural NetworksNicholas Carlini, Chang Liu, Úlfar Erlingsson, Jernej Kos et al.USENIX Security 2019 · 1,386 citations
- Membership Inference Attacks From First PrinciplesNicholas Carlini, Steve Chien, Milad Nasr, Shuang Song et al.S&P 2022 · 1,049 citations
- Evaluating Differentially Private Machine Learning in PracticeBargav Jayaraman, David EvansUSENIX Security 2019 · 586 citations
Related papers
- Closed-Form Bounds for DP-SGD against Record-level InferenceGiovanni Cherubin, Boris Köpf, Andrew Paverd, Shruti Tople et al.USENIX Security 2024 · 2 citations
- Bounding training data reconstruction in DP-SGDJamie Hayes, Borja Balle, Saeed MahloujifarNeurIPS 2023 · 73 citations
- Quantifying identifiability to choose and audit epsilon in differentially private deep learningDaniel Bernau, Günther Eibl, Philip-William Grassal, Hannah Keller et al.VLDB 2021 · 7 citations
- Gaussian Membership Inference PrivacyTobias Leemann, Martin Pawelczyk, Gjergji KasneciNeurIPS 2023 · 29 citations
- Label-Only Membership Inference AttacksChristopher A. Choquette-Choo, Florian Tramèr, Nicholas Carlini, Nicolas PapernotICML 2021 · 628 citations
