arXiv · 2606.12733
Let's Ask Gauss: Improved One-Run Privacy Auditing
Abstract
Privacy auditing provides an important safeguard by estimating the actual information leaked by a model, thus ensuring that theoretical privacy guarantees hold in practice. We study empirical privacy auditing for differentially private (DP) machine learning, focusing on efficient one-run methods for mechanisms such as DP-SGD. Prior one-run approaches threshold training examples or "canaries" into binary membership guesses, which discards useful information. We show that, in the white-box DP-SGD setting, canary-aligned signals naturally form a sequence of random variables whose normalized sum is asymptotically Gaussian. Leveraging this distributional perspective, we develop a DP-auditing framework that leads to tighter privacy lower bounds from a single training run.
Explore related subjects
Keep this discovery
Adya Agrawal, Yu Wei, Jaspal Singh, Malik Magdon-Ismail, Vassilis Zikas. 2026-06-10. Let's Ask Gauss: Improved One-Run Privacy Auditing. https://arxiv.org/abs/2606.12733
Cite the original work for its findings. Save a collection to share your selection of sources.