arXiv:2605.21938cs.LGcs.CR2026-05

提出首个最优的瑞尼差分隐私审计方法,精准评估模型隐私泄露风险。

Optimal Guarantees for Auditing Rényi Differentially Private Machine Learning

  • 基于假设检验与变分估计,直接计算邻近执行间的瑞尼散度。
  • 在小到中等瑞尼阶数下,审计精度显著优于现有黑盒方法。
  • 理论证明样本复杂度近乎最优,适合高要求隐私验证场景。

我们研究声称具备瑞尼差分隐私(RDP)保证的机器学习算法的黑盒审计问题。提出一种基于假设检验的审计框架,利用多斯克尔-瓦拉达汉(DV)变分估计器,直接估算邻近执行间的瑞尼散度。分析给出了通过类别受限的DV估计器进行RDP审计的显式非渐近置信区间,将统计估计误差与算法隐私泄漏分离。证明了匹配的极小极大下界,表明我们的样本复杂度保证在对数因子范围内信息论最优,从而首次建立了基于DV估计器审计RDP的最优性。实验上,我们在完全黑盒设置下实例化该框架用于审计DP-SGD,在MNIST和CIFAR-10数据集上,覆盖广泛隐私范围,相比之前最先进的黑盒方法,在小至中等瑞尼阶数下均实现显著的实证下界提升,这些阶数下的精确审计最具挑战性。

原文摘要 · Abstract (English)

We study black-box auditing for machine learning algorithms that claim R \ 'enyi differential privacy (RDP) guarantees. We introduce an auditing framework, based on hypothesis testing, that directly estimates Rényi divergence between neighboring executions using the Donsker-Varadhan (DV) variational estimator. Our analysis yields explicit and non-asymptotic confidence intervals for RDP auditing via class-restricted DV estimators, separating statistical estimation error from algorithmic privacy leakage. We prove matching minimax lower bounds showing that, up to logarithmic factors, our sample-complexity guarantees are information-theoretically optimal, thereby establishing the first optimal guarantees for auditing RDP via DV estimators. Empirically, we instantiate our framework for auditing DP-SGD in a fully black-box setting. Across MNIST and CIFAR-10, and over a wide range of privacy regimes, our auditors produce a strong overall improvement on empirical RDP lower bounds compared to prior state-of-the-art black-box methods especially at small and moderate Rényi orders where accurate auditing is most challenging.

差分隐私审计瑞尼散度隐私验证

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。