Debugging Differential Privacy: A Case Study for Privacy Auditing

Differential Privacy can provide provable privacy guarantees for training data in machine learning. However, the presence of proofs does not preclude the presence of errors. Inspired by recent advances in auditing which have been used for estimating lower bounds on differentially private algorithms, here we show that auditing can also be used to find flaws in (purportedly) differentially private schemes. In this case study, we audit a recent open source implementation of a differentially private deep learning algorithm and find, with 99.99999999% confidence, that the implementation does not satisfy the claimed differential privacy guarantee.

Paper

References (9)

09Tensorflow privacy issue #153: Incorrect comparison between privacy amplification by iteration and DP-SGD2020 · github.com/tensorflow/ privacy/issues

Similar papers

© 2026 NYSGPT2525 LLC