CANIFE: Crafting Canaries for Empirical Privacy Measurement in Federated Learning
Samuel Maddock, Alexandre Sablayrolles, Pierre Stock
Abstract
Federated Learning (FL) is a setting for training machine learning models in distributed environments where the clients do not share their raw data but instead send model updates to a server. However, model updates can be subject to attacks and leak private information. Differential Privacy (DP) is a leading mitigation strategy which involves adding noise to clipped model updates, trading off performance for strong theoretical privacy guarantees. Previous work has shown that the threat model of DP is conservative and that the obtained guarantees may be vacuous or may overestimate information leakage in practice. In this paper, we aim to achieve a tighter measurement of the model exposure by considering a realistic threat model. We propose a novel method, CANIFE, that uses canaries - carefully crafted samples by a strong adversary to evaluate the empirical privacy of a training round. We apply this attack to vision models trained on CIFAR-10 and CelebA and to language models trained on Sent140 and Shakespeare. In particular, in realistic FL scenarios, we demonstrate that the empirical per-round epsilon obtained with CANIFE is 4-5x lower than the theoretical bound.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext eea57c4a-da8b-44ca-bfb3-93eeacf5fd8aCited by top-tier papers13
- Privacy Auditing with One (1) Training RunThomas Steinke, Milad Nasr, Matthew JagielskiNeurIPS 2023 · 178 citations
- One-shot Empirical Privacy Estimation for Federated LearningGalen Andrew, Peter Kairouz, Sewoong Oh, Alina Oprea et al.ICLR 2024 · 48 citations
- Unleashing the Power of Randomization in Auditing Differentially Private MLKrishna Pillutla, Galen Andrew, Peter Kairouz, H. Brendan McMahan et al.NeurIPS 2023 · 35 citations
- Nearly Tight Black-Box Auditing of Differentially Private Machine LearningMeenatchi Sundaram Muthu Selva Annamalai, Emiliano De CristofaroNeurIPS 2024 · 32 citations
- Confidential-DPproof: Confidential Proof of Differentially Private TrainingAli Shahin Shamsabadi, Gefei Tan, Tudor Cebere, Aurélien Bellet et al.ICLR 2024 · 24 citations
Builds on24
- Deep Learning with Differential PrivacyMartín Abadi, Andy Chu, Ian J. Goodfellow, H. Brendan McMahan et al.CCS 2016 · 7,620 citations
- Membership Inference Attacks Against Machine Learning ModelsReza Shokri, Marco Stronati, Congzheng Song, Vitaly ShmatikovS&P 2017 · 5,137 citations
- Practical Secure Aggregation for Privacy-Preserving Machine LearningKallista A. Bonawitz, Vladimir Ivanov, Ben Kreuter, Antonio Marcedone et al.CCS 2017 · 3,936 citations
- SCAFFOLD: Stochastic Controlled Averaging for Federated LearningSai Praneeth Karimireddy, Satyen Kale, Mehryar Mohri, Sashank J. Reddi et al.ICML 2020 · 3,875 citations
- Extracting Training Data from Large Language ModelsNicholas Carlini, Florian Tramèr, Eric Wallace, Matthew Jagielski et al.USENIX Security 2021 · 2,866 citations
Related papers
- Make Landscape Flatter in Differentially Private Federated LearningYifan Shi, Yingqi Liu, Kang Wei, Li Shen et al.CVPR 2023
- OptiFluence: Principled Design of Privacy CanariesMohammad Yaghini, Michael Aerni, Junrui Zhang, Nicolas Papernot et al.ICML 2026
- Local and Central Differential Privacy for Robustness and Privacy in Federated LearningMohammad Naseri, Jamie Hayes, Emiliano De CristofaroNDSS 2022
- Towards the Robustness of Differentially Private Federated LearningTao Qi, Huili Wang, Yongfeng HuangAAAI 2024 · 30 citations
- Unraveling the Connections between Privacy and Certified Robustness in Federated Learning Against Poisoning AttacksChulin Xie, Yunhui Long, Pin-Yu Chen, Qinbin Li et al.CCS 2023 · 12 citations
