We gratefully acknowledge support from
the Simons Foundation and member institutions.
Full-text links:

Download:

Current browse context:

cs.LG

Change to browse by:

References & Citations

DBLP - CS Bibliography

Bookmark

(what is this?)
CiteULike logo BibSonomy logo Mendeley logo del.icio.us logo Digg logo Reddit logo

Computer Science > Machine Learning

Title: One-shot Empirical Privacy Estimation for Federated Learning

Abstract: Privacy estimation techniques for differentially private (DP) algorithms are useful for comparing against analytical bounds, or to empirically measure privacy loss in settings where known analytical bounds are not tight. However, existing privacy auditing techniques usually make strong assumptions on the adversary (e.g., knowledge of intermediate model iterates or the training data distribution), are tailored to specific tasks, model architectures, or DP algorithm, and/or require retraining the model many times (typically on the order of thousands). These shortcomings make deploying such techniques at scale difficult in practice, especially in federated settings where model training can take days or weeks. In this work, we present a novel "one-shot" approach that can systematically address these challenges, allowing efficient auditing or estimation of the privacy loss of a model during the same, single training run used to fit model parameters, and without requiring any a priori knowledge about the model architecture, task, or DP training algorithm. We show that our method provides provably correct estimates for the privacy loss under the Gaussian mechanism, and we demonstrate its performance on well-established FL benchmark datasets under several adversarial threat models.
Comments: Final revision, oral presentation at ICLR 2024
Subjects: Machine Learning (cs.LG); Cryptography and Security (cs.CR)
Cite as: arXiv:2302.03098 [cs.LG]
  (or arXiv:2302.03098v5 [cs.LG] for this version)

Submission history

From: Galen Andrew [view email]
[v1] Mon, 6 Feb 2023 19:58:28 GMT (145kb,D)
[v2] Wed, 8 Feb 2023 16:46:21 GMT (145kb,D)
[v3] Mon, 22 May 2023 22:57:05 GMT (223kb,D)
[v4] Wed, 18 Oct 2023 23:32:56 GMT (307kb,D)
[v5] Thu, 18 Apr 2024 17:14:37 GMT (340kb,D)

Link back to: arXiv, form interface, contact.