Cet évènement est passé.
Privacy Auditing of DP-SGD in the Hidden State Threat Model

Quand

2 décembre 2024    
14 h 00 min

Room 02.124 Building 5
St Priest Campus, Montpellier, 34000

Machine Learning in Montpellier, Theory & Practice

In this talk, we introduce privacy auditing and explore the privacy guarantees of machine learning models trained with Differentially Private Stochastic Gradient Descent (DP-SGD), focusing on the hidden state threat model, in which an adversary only has access to the final training model. We employ simple adversaries for privacy auditing models in the hidden state, outperforming previous methods. We show that if a user contributes to each DP-SGD step, releasing only the final model does not amplify privacy, compared to the standard case where all intermediary models are released. The problem is more complex when the crafted gradient is not inserted at every step: our auditing lower bound matches the privacy upper bound only for an adversarially-chosen loss landscape and a sufficiently large batch size. This suggests that existing privacy upper bounds can be improved in certain regimes

Map /Briefcase/RF-Inria_logo_signat.png" target="_blank" rel="noopener">Online

Carte non disponible