DP-Sniper: Black-Box Discovery of Differential Privacy Violations using Classifiers

DP-Sniper: Black-Box Discovery of Differential Privacy Violations using Classifiers
复制标题

DP-Sniper:使用分类器黑盒发现差异隐私侵犯

DOI:
--
复制
发表时间:
2021
期刊:
IEEE Symposium on Security and Privacy
影响因子:
--
通讯作者:
Martin T. Vechev
Martin T. Vechev
中科院分区:
--
文献类型:
--
作者:
Benjamin Bichsel;Samuel Steffen;Ilija Bogunovic;Martin T. Vechev

文献摘要

参考文献

被引文献

相似文献

我们提出了DP-Sniper,这是一种实用的黑盒方法,可以自动发现差分隐私的侵犯。DP-Sniper基于两个关键思想:(i)训练分类器以预测观察到的输出是否可能从两个可能的输入之一生成,以及(ii)将该分类器转换为对差分隐私的近似最优攻击。我们的实验评估表明,DP-狙击手获得了比最先进技术高12.4倍的保证,同时速度快15.5倍。此外,我们表明,DP-狙击手是有效的利用浮点漏洞天真地实现算法:它检测到,一个所谓的0.1-差分私人实施的拉普拉斯机制实际上并不满足甚至0.25-差分隐私。
We present DP-Sniper, a practical black-box method that automatically finds violations of differential privacy.DP-Sniper is based on two key ideas: (i) training a classifier to predict if an observed output was likely generated from one of two possible inputs, and (ii) transforming this classifier into an approximately optimal attack on differential privacy.Our experimental evaluation demonstrates that DP-Sniper obtains up to 12.4 times stronger guarantees than state-of-the-art, while being 15.5 times faster. Further, we show that DP-Sniper is effective in exploiting floating-point vulnerabilities of naively implemented algorithms: it detects that a supposedly 0.1-differentially private implementation of the Laplace mechanism actually does not satisfy even 0.25-differential privacy.
DOI: 10.1145/3158146
发表时间: 2018-01-01
影响因子: 1.8
作者:
Albarghouthi, Aws;Hsu, Justin
通讯作者: Hsu, Justin
有限计算机上的差异隐私
DOI: 10.29012/jpc.679
发表时间: 2019
影响因子: --
作者:
Balcer, Victor;Vadhan, Salil
通讯作者: Vadhan, Salil