Lune

CCS2023顶会

Group and Attack: Auditing Differential Privacy

Johan Lokna, Anouk Paradis, Dimitar I. Dimitrov, Martin T. Vechev

2023年份
10被引次数
12顶会引用

摘要

𝜖, 𝛿) differential privacy has seen increased adoption recently, especially in private machine learning applications. While this privacy definition allows provably limiting the amount of information leaked by an algorithm, practical implementations of differentially private algorithms often contain subtle vulnerabilities. This motivates the need for effective tools that can audit (𝜖, 𝛿) differential privacy algorithms before deploying them in the real world. However, existing state-of-the-art-tools for auditing (𝜖, 𝛿) differential privacy directly extend the tools for 𝜖-differential privacy by fixing either 𝜖 or 𝛿 in the violation search, inherently restricting their ability to efficiently discover violations of (𝜖, 𝛿) differential privacy. We present a novel method to efficiently discover (𝜖, 𝛿) differential privacy violations based on the key insight that many (𝜖, 𝛿) pairs can be grouped as they result in the same algorithm. Crucially, our method is orthogonal to existing approaches and, when combined, results in a faster and more precise violation search. We implemented our approach in a tool called Delta-Siege and demonstrated its effectiveness by discovering vulnerabilities in most of the evaluated frameworks, several of which were previously unknown. Further, in 84% of cases, Delta-Siege outperforms existing state-of-the-art auditing tools. Finally, we show how Delta-Siege outputs can be used to find the precise root cause of vulnerabilities, an option no other differential privacy testing tool currently offers. CCS CONCEPTS • Security and privacy → Privacy-preserving protocols; • Mathematics of computing → Statistical software.

问问这篇 Paper

智能体会读完全文。

Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。

可以从这些问题问起

智能体调用

Luneget_paper_fulltext

在 Lune 里问

免费开始,无需绑卡

引用它的顶会 Paper12

问问它们各自怎么用它

它引用的顶会 Paper16

相关 Paper

黄昏的海面,两侧是细线勾勒的悬崖