DP-Sniper: Black-Box Discovery of Differential Privacy Violations using Classifiers
DP-Sniper: Black-Box Discovery of Differential Privacy Violations using Classifiers
复制标题
DP-Sniper:使用分类器黑盒发现差异隐私侵犯
DOI:
--
复制
发表时间:
2021
期刊:
影响因子:
--
通讯作者:
Martin T. Vechev
中科院分区:
文献类型:
--
作者:
Benjamin Bichsel;Samuel Steffen;Ilija Bogunovic;Martin T. Vechev
We present DP-Sniper, a practical black-box method that automatically finds violations of differential privacy.DP-Sniper is based on two key ideas: (i) training a classifier to predict if an observed output was likely generated from one of two possible inputs, and (ii) transforming this classifier into an approximately optimal attack on differential privacy.Our experimental evaluation demonstrates that DP-Sniper obtains up to 12.4 times stronger guarantees than state-of-the-art, while being 15.5 times faster. Further, we show that DP-Sniper is effective in exploiting floating-point vulnerabilities of naively implemented algorithms: it detects that a supposedly 0.1-differentially private implementation of the Laplace mechanism actually does not satisfy even 0.25-differential privacy.
影响因子:
1.8
作者:
Albarghouthi, Aws;Hsu, Justin
通讯作者:
Hsu, Justin
影响因子:
--
作者:
Balcer, Victor;Vadhan, Salil
通讯作者:
Vadhan, Salil