Group and Attack: Auditing Differential Privacy
Johan Lokna, Anouk Paradis, Dimitar I. Dimitrov, Martin T. Vechev
摘要
𝜖, 𝛿) differential privacy has seen increased adoption recently, especially in private machine learning applications. While this privacy definition allows provably limiting the amount of information leaked by an algorithm, practical implementations of differentially private algorithms often contain subtle vulnerabilities. This motivates the need for effective tools that can audit (𝜖, 𝛿) differential privacy algorithms before deploying them in the real world. However, existing state-of-the-art-tools for auditing (𝜖, 𝛿) differential privacy directly extend the tools for 𝜖-differential privacy by fixing either 𝜖 or 𝛿 in the violation search, inherently restricting their ability to efficiently discover violations of (𝜖, 𝛿) differential privacy. We present a novel method to efficiently discover (𝜖, 𝛿) differential privacy violations based on the key insight that many (𝜖, 𝛿) pairs can be grouped as they result in the same algorithm. Crucially, our method is orthogonal to existing approaches and, when combined, results in a faster and more precise violation search. We implemented our approach in a tool called Delta-Siege and demonstrated its effectiveness by discovering vulnerabilities in most of the evaluated frameworks, several of which were previously unknown. Further, in 84% of cases, Delta-Siege outperforms existing state-of-the-art auditing tools. Finally, we show how Delta-Siege outputs can be used to find the precise root cause of vulnerabilities, an option no other differential privacy testing tool currently offers. CCS CONCEPTS • Security and privacy → Privacy-preserving protocols; • Mathematics of computing → Statistical software.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper12
- Nearly Tight Black-Box Auditing of Differentially Private Machine LearningMeenatchi Sundaram Muthu Selva Annamalai, Emiliano De CristofaroNeurIPS 2024 · 被引用 32 次
- "What do you want from theory alone?" Experimenting with Tight Auditing of Differentially Private Synthetic Data GenerationMeenatchi Sundaram Muthu Selva Annamalai, Georgi Ganev, Emiliano De CristofaroUSENIX Security 2024 · 被引用 24 次
- Beyond the Calibration Point: Mechanism Comparison in Differential PrivacyGeorgios Kaissis, Stefan Kolek, Borja Balle, Jamie Hayes 等ICML 2024 · 被引用 11 次
- Sequentially Auditing Differential PrivacyTomás González Lara, Mateo Dulce-Rubio, Aaditya Ramdas, Mónica RiberoNeurIPS 2025 · 被引用 6 次
- Graphical vs. Deep Generative Models: Measuring the Impact of Differentially Private Mechanisms and Budgets on UtilityGeorgi Ganev, Kai Xu, Emiliano De CristofaroCCS 2024 · 被引用 5 次
它引用的顶会 Paper16
- Membership Inference Attacks From First PrinciplesNicholas Carlini, Steve Chien, Milad Nasr, Shuang Song 等S&P 2022 · 被引用 1,049 次
- Label-Only Membership Inference AttacksChristopher A. Choquette-Choo, Florian Tramèr, Nicholas Carlini, Nicolas PapernotICML 2021 · 被引用 628 次
- The Discrete Gaussian for Differential PrivacyClément L. Canonne, Gautam Kamath, Thomas SteinkeNeurIPS 2020 · 被引用 355 次
- Auditing Differentially Private Machine Learning: How Private is Private SGD?Matthew Jagielski, Jonathan R. Ullman, Alina OpreaNeurIPS 2020 · 被引用 354 次
- AIM: An Adaptive and Iterative Mechanism for Differentially Private Synthetic DataRyan McKenna, Brett Mullins, Daniel Sheldon, Gerome MiklauVLDB 2022 · 被引用 136 次
相关 Paper
- A General Framework for Auditing Differentially Private Machine LearningFred Lu, Joseph Munoz, Maya Fuchs, Tyler LeBlond 等NeurIPS 2022 · 被引用 57 次
- DP-Sniper: Black-Box Discovery of Differential Privacy Violations using ClassifiersBenjamin Bichsel, Samuel Steffen, Ilija Bogunovic, Martin T. VechevS&P 2021 · 被引用 53 次
- Auditing -differential privacy in one runSaeed Mahloujifar, Luca Melis, Kamalika ChaudhuriICML 2025
- Detecting Violations of Differential PrivacyZeyu Ding, Yuxin Wang, Guanhong Wang, Danfeng Zhang 等CCS 2018 · 被引用 156 次
- Sequential Auditing for f-Differential PrivacyTim Kutta, Martin Dunsche, Yu Wei, Vassilis ZikasUSENIX Security 2026
