利用高斯分布特性,单次训练就能更精准评估差分隐私模型泄露风险。
Let's Ask Gauss: Improved One-Run Privacy Auditing

- 将密钥信号视为随机变量序列,用高斯分布建模其归一化和
- 单次训练即可获得比现有方法更紧的隐私下界
- 适合关注隐私泄露实测结果的研究者和开发者
隐私审计通过估算模型实际泄露的信息,为差分隐私(DP)机器学习提供重要保障。本文研究针对差分隐私机器学习的实证隐私审计,聚焦于如DP-SGD等机制的高效单次运行方法。先前的单次方法将训练样本或“密钥”阈值化为二元成员身份猜测,导致信息丢失。我们证明,在白盒DP-SGD设置中,密钥对齐信号自然形成一组随机变量,其归一化和渐近服从高斯分布。基于这一分布视角,我们提出一个新型DP审计框架,仅需一次训练即可获得更紧的隐私下界。
原文摘要 · Abstract (English)
Privacy auditing provides an important safeguard by estimating the actual information leaked by a model, thus ensuring that theoretical privacy guarantees hold in practice. We study empirical privacy auditing for differentially private (DP) machine learning, focusing on efficient one-run methods for mechanisms such as DP-SGD. Prior one-run approaches threshold training examples or "canaries" into binary membership guesses, which discards useful information. We show that, in the white-box DP-SGD setting, canary-aligned signals naturally form a sequence of random variables whose normalized sum is asymptotically Gaussian. Leveraging this distributional perspective, we develop a DP-auditing framework that leads to tighter privacy lower bounds from a single training run.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。