arXiv Machine Learning

Differentially-Private Decision Trees and Provable Robustness to Data Poisoning

The paper introduces PrivaTree, a differentially‑private decision tree algorithm that uses private histograms to select splits while preserving a small privacy budget. PrivaTree supports mixed numerical and categorical data without leaking information about numerical features and achieves a superior privacy‑utility trade‑off compared to existing methods. Additionally, the authors provide theoretical bounds on the expected accuracy and success rates of backdoor attacks, showing that PrivaTree-trained trees are more robust against data poisoning than standard decision trees.

arXiv Machine Learning
Sep 23

Optimizing Canaries for Privacy Auditing with Metagradient Descent

The paper investigates black-box privacy auditing for differentially private learning algorithms, focusing on DP‑SGD. It introduces a method that optimizes the auditor’s canary set using metagradient descent, improving empirical lower bounds on privacy parameters compared to prior canary designs. The approach is shown to be DP‑SGD agnostic and efficient, with optimized canaries for small models remaining effective for larger DP‑SGD models.

By Matteo Boglioni, Terrance Liu, Andrew Ilyas, Zhiwei Steven Wu
arXiv Machine Learning
Jul 23

Differentially Private Neural Network Training Under the Hidden State Assumption

arXiv:2407. 08233v3 Announce Type: replace Abstract: Current differentially private learning paradigms face a severe utility bottleneck: DP-SGD degrades performance through noise accumulation over training steps, while aggregation-based approaches such as PATE suffer from data inefficiency due to disjoint data partitioning.

By Ding Chen, Haochen Luo, Xiaofei Wang, Chen Liu
arXiv Machine Learning
Jun 15

Let's Ask Gauss: Improved One-Run Privacy Auditing

arXiv:2606. 12733v2 Announce Type: replace Abstract: Privacy auditing provides an important safeguard by estimating the actual information leaked by a model, thus ensuring that theoretical privacy guarantees hold in practice.

By Adya Agrawal, Yu Wei, Jaspal Singh, Malik Magdon-Ismail, Vassilis Zikas