Skip to content

Canaries in the Bank: Auditing User-Level Privacy in Private Evolution

Sep 2026 · 0 citations · 20 references
Computer Science

TL;DR

A protocol-aware empirical audit is introduced in which the server commits to a single shared candidate bank and replaces roughly 1% of its entries with probes derived from a known, non-private canary, to quantify the gap between formal worst-case privacy and leakage achievable through protocol-valid candidate-bank manipulation.

Abstract

Private Evolution (PE) generates high-fidelity synthetic data in federated settings without exposing users'raw data. It aggregates clipped user votes over a shared candidate bank into a differentially private histogram, with noise calibrated to the worst-case user contribution. However, it is unclear whether an adversary can realize this worst-case privacy loss while following the PE protocol. We introduce a protocol-aware empirical audit in which the server commits to a single shared candidate bank and replaces roughly 1% of its entries with probes derived from a known, non-private canary. We evaluate eight attacks, including an unchanged-bank baseline, exact copies, plausible paraphrases, and high-entropy synthetic nonces. Experiments on Yelp and Sentiment140 show that natural-text attacks remain substantially below the theoretical DP bound, while nonce-based attacks yield considerably stronger bounds and come closest to the mechanism's privacy ceiling. These results quantify the gap between formal worst-case privacy and leakage achievable through protocol-valid candidate-bank manipulation.

View source

Similar papers

#artificial intelligence Preprint Sep 2026

Subgroup Membership Inference Audits of Differentially Private Synthetic Text

Synthetic data releases are increasingly proposed in the literature as a means of sharing realistic data replicas in lieu of sensitive private datasets. Even when the worst-case privacy leakage of such releases is bounded by means of differential privacy (DP), in practice a residual risk remains. Membership inference a...

Yi-Dan Sun, Viktor Schlegel, Srinivasan Nandakumar et al. · 0 citations
#natural language process... Preprint Sep 2026

Conformal Privacy Auditing: Calibrated Re-identification Attacks with Statistical Guarantees

Conformal Privacy Auditing is introduced, a distribution-free calibration framework that provides a statistical certificate of re-identification risk for each released document against LLM-empowered adversaries and enables audits of open-source models and proprietary API models in a unified framework.

Shuo Huang, G. Haffari, Xing-Liang Yuan et al. · 0 citations
#machine learning Preprint Aug 2026

Revisiting the Provable-Auditable Privacy Gap of DP-SGD

A lightweight defense framework that generically augments optimization methods in the ML pipeline to have significantly-improved empirical privacy on standard benchmarks is given, and it is shown that the framework comes at no theoretical privacy cost when augmenting DP-SGD, unlike previously-proposed defenses against...

Saloni Modi, Srivi Balaji, Yu-Song Zhu et al. · 0 citations
#artificial intelligence Preprint Aug 2026

Auditing and Mitigating Privacy Leakage in Cloud-Edge Collaborative Decoding

CoVeil is proposed, a defense mechanism which dynamically optimizes transmitted signals to suppress leakage during decoding time while preserving the collaborative quality, and consistently improves the privacy-utility trade-off over existing baselines by reducing data leakage.

Ke-Jia Zhang, Tianyuan Zou, Zi-Xuan Gu et al. · 0 citations
Preprint Aug 2026

Revisiting Continuous Noise Sampling for Multi-Party Differential Privacy

This paper revisits the continuous noise sampling protocols and makes several improvements in both security and efficiency and turns to discrete sampling at the granularity of individual biased bits to address the security and efficiency issues together.

Yu-Cheng Fu, Tianhao Wang · 1 citation
#machine learning Preprint Sep 2026

Privacy Failure in Split-LLM Training, The Returned Gradient Nullifies the Decoys

A systems-security case study of a two-node split-LLM training system whose privacy evaluation passed while leaving an observable channel untested, but the system is not thereby safe: five classes of attack, including those accumulating observations across training steps, were never measured.

G. Politis, E. Pappas · 1 citation

Related blog posts

MIT News · Artificial Intelligence Sep 29, 2026

Who we become when we talk to machines

Professor Sherry Turkle’s new book, “Artificial Intimacy,” offers a withering critique of chatbots and the antisocial dynamics she believes they encourage.

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.