Eureka: A General Framework for Black-box Differential Privacy Estimators
Yun Lu, Malik Magdon-Ismail, Yu Wei, Vassilis Zikas
摘要
Differential privacy (DP) is a key tool in privacypreserving data analysis. Yet it remains challenging for nonprivacy-experts to prove the DP of their algorithms. We propose a methodology for domain experts with limited data privacy background to empirically estimate the privacy of an arbitrary mechanism. Our Eureka moment is a new linkwhich we prove-between the problems of DP parameterestimation and Bayes optimal classifiers in ML, which we believe can be of independent interest. Our estimator uses this link to achieve two desirable properties: (1) black-box, i.e., it does not require knowledge of the underlying mechanism, and (2) it has a theoretically-proven accuracy, depending on the underlying classifier used, allowing plug-and-play use of different classifiers.
More concretely, motivated by the impossibility of the above task for unrestricted input domains (which we prove), we introduce a natural, application-inspired relaxation of DP which we term relative DP. Intuitively, relative DP defines a mechanism's privacy relative to an input set T , circumventing the above impossibility when T is finite. Importantly, it preserves the key intuitive privacy guarantee of DP while enjoying a number of desirable DP properties-scalability, composition, and robustness to post-processing. We then devise a black-box poly-time (ε, δ)-relative DP estimator for any poly-size Tthe first privacy estimator to support mechanisms with large output spaces while having tight accuracy bounds. As a result of independent interest, we generalize our theory to develop the first Distributional Differential Privacy (DDP) estimator.
We benchmark our estimator in a proof-of-concept implementation. First, using kNN as the classifier we show that our method (1) produces a tight, analytically computed (ε, δ)-DP trade-off of low-dimensional Laplace and Gaussian mechanisms-the first to do so, (2) accurately estimates the privacy spectrum of DDP mechanisms, and (3) can verify a DP mechanism's implementations, e.g., Sparse Vector Technique, Noisy Histogram, and Noisy max. Our implementation and experiments demonstrate the potential of our framework, and highlight its computational bottlenecks in estimating DP, e.g., in terms of the size of δ and the data dimensionality. Our second, neural-network-based instantiation makes a first step in showing that our method can be extended to mechanisms with high-dimensional outputs.
-
We remark that [3] uses the notion of privacy profile for a quantity highly related to the privacy spectrum.
-
To avoid clutter, when the context is clear, we drop M from the notation, e.g., δ(ε) instead of δ M (ε).
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了最后一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper7
- Group and Attack: Auditing Differential PrivacyJohan Lokna, Anouk Paradis, Dimitar I. Dimitrov, Martin T. VechevCCS 2023 · 被引用 10 次
- Sequentially Auditing Differential PrivacyTomás González Lara, Mateo Dulce-Rubio, Aaditya Ramdas, Mónica RiberoNeurIPS 2025 · 被引用 6 次
- Understanding Disclosure Risk in Differential Privacy with Applications to Noise Calibration and AuditingPatricia Guerra-Balboa, Annika Sauer, Héber Hwang Arcolezi, Thorsten StrufeVLDB 2026
- Asymptotic Optimality of the High-Dimensional Gaussian Mechanism and Improved Low-Dimensional Mechanisms for Differential PrivacyAlexander Bienstock, Antigoni Polychroniadou, Yu WeiICML 2026
- General-Purpose f-DP Estimation and Auditing in a Black-Box SettingÖnder Askin, Holger Dette, Martin Dunsche, Tim Kutta 等USENIX Security 2025
它引用的顶会 Paper6
- Detecting Violations of Differential PrivacyZeyu Ding, Yuxin Wang, Guanhong Wang, Danfeng Zhang 等CCS 2018 · 被引用 156 次
- DP-Finder: Finding Differential Privacy Violations by Sampling and OptimizationBenjamin Bichsel, Timon Gehr, Dana Drachsler-Cohen, Petar Tsankov 等CCS 2018 · 被引用 82 次
- DP-Sniper: Black-Box Discovery of Differential Privacy Violations using ClassifiersBenjamin Bichsel, Samuel Steffen, Ilija Bogunovic, Martin T. VechevS&P 2021 · 被引用 53 次
- CheckDP: An Automated and Integrated Approach for Proving Differential Privacy or Finding Precise CounterexamplesYuxin Wang, Zeyu Ding, Daniel Kifer, Danfeng ZhangCCS 2020 · 被引用 31 次
- Statistical Quantification of Differential Privacy: A Local ApproachÖnder Askin, Tim Kutta, Holger DetteS&P 2022 · 被引用 19 次
相关 Paper
- Fast Private Kernel Density Estimation via Locality Sensitive QuantizationTal Wagner, Yonatan Naamad, Nina MishraICML 2023 · 被引用 11 次
- Instance-optimal Mean Estimation Under Differential PrivacyZiyue Huang, Yuting Liang, Ke YiNeurIPS 2021 · 被引用 74 次
- Lower Bounds for Rényi Differential Privacy in a Black-Box SettingTim Kutta, Önder Askin, Martin DunscheS&P 2024 · 被引用 7 次
- DP-Auditorium: A Large-Scale Library for Auditing Differential PrivacyWilliam Kong, Andrés Muñoz Medina, Mónica Ribero, Umar SyedS&P 2024 · 被引用 14 次
- Bayesian Differential Privacy for Machine LearningAleksei Triastcyn, Boi FaltingsICML 2020 · 被引用 79 次
