arXiv:2509.07055cs.CRcs.LG2025-09NeurIPS被引 6

新审计方法可实时检测隐私泄露,样本量减少近百倍。

Sequentially Auditing Differential Privacy

  • 基于流式数据的实时审计,支持任意时间点验证
  • 仅需几百样本即可发现隐私漏洞,较之前降低数量级
  • 适合快速验证训练中的模型隐私,尤其适合小规模实验

我们提出一种实用的序列化差分隐私审计方法,用于评估黑箱机制的隐私保障。该方法通过处理机制输出的流数据,实现任意时间点的有效推断,同时控制第一类错误,克服了以往批量审计方法固定样本量的限制。实验表明,该方法在多种现实机制中,将检测隐私违规所需的样本量从5万降低至数百,数量级显著下降;尤为关键的是,它能在一次训练过程中识别出DP-SGD的隐私违规行为,而无需等待完整模型训练完成。

原文摘要 · Abstract (English)

We propose a practical sequential test for auditing differential privacy guarantees of black-box mechanisms. The test processes streams of mechanisms' outputs providing anytime-valid inference while controlling Type I error, overcoming the fixed sample size limitation of previous batch auditing methods. Experiments show this test detects violations with sample sizes that are orders of magnitude smaller than existing methods, reducing this number from 50K to a few hundred examples, across diverse realistic mechanisms. Notably, it identifies DP-SGD privacy violations in \textit{under} one training run, unlike prior methods needing full model training.

差分隐私审计方法实时检测

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。