Auditing Differential Privacy in the Black-Box Setting
–arXiv.org Artificial Intelligence
This paper introduces a novel theoretical framework for auditing differential privacy (DP) in a black-box setting. Leveraging the concept of $f$-differential privacy, we explicitly define type I and type II errors and propose an auditing mechanism based on conformal inference. Our approach robustly controls the type I error rate under minimal assumptions. Furthermore, we establish a fundamental impossibility result, demonstrating the inherent difficulty of simultaneously controlling both type I and type II errors without additional assumptions. Nevertheless, under a monotone likelihood ratio (MLR) assumption, our auditing mechanism effectively controls both errors. We also extend our method to construct valid confidence bands for the trade-off function in the finite-sample regime.
arXiv.org Artificial Intelligence
Mar-15-2025
- Country:
- North America > United States
- New York > New York County
- New York City (0.04)
- Illinois > Cook County
- Chicago (0.04)
- California > Orange County
- Anaheim (0.04)
- New York > New York County
- North America > United States
- Genre:
- Research Report (0.84)
- Industry:
- Information Technology > Security & Privacy (1.00)
- Government (0.94)
- Transportation > Air (0.62)
- Technology: