A protocol-aware empirical audit is introduced in which the server commits to a single shared candidate bank and replaces roughly 1% of its entries with probes derived from a known, non-private canary, to quantify the gap between formal worst-case privacy and leakage achievable through protocol-valid candidate-bank manipulation.
Abstract
Private Evolution (PE) generates high-fidelity synthetic data in federated settings without exposing users'raw data. It aggregates clipped user votes over a shared candidate bank into a differentially private histogram, with noise calibrated to the worst-case user contribution. However, it is unclear whether an adversary can realize this worst-case privacy loss while following the PE protocol. We introduce a protocol-aware empirical audit in which the server commits to a single shared candidate bank and replaces roughly 1% of its entries with probes derived from a known, non-private canary. We evaluate eight attacks, including an unchanged-bank baseline, exact copies, plausible paraphrases, and high-entropy synthetic nonces. Experiments on Yelp and Sentiment140 show that natural-text attacks remain substantially below the theoretical DP bound, while nonce-based attacks yield considerably stronger bounds and come closest to the mechanism's privacy ceiling. These results quantify the gap between formal worst-case privacy and leakage achievable through protocol-valid candidate-bank manipulation.
Synthetic data releases are increasingly proposed in the literature as a means of sharing realistic data replicas in lieu of sensitive private datasets. Even when the worst-case privacy leakage of such releases is bounded by means of differential privacy (DP), in practice a residual risk remains. Membership inference a...
Yi-Dan Sun, Viktor Schlegel, Srinivasan Nandakumar et al.· 0 citations
Conformal Privacy Auditing is introduced, a distribution-free calibration framework that provides a statistical certificate of re-identification risk for each released document against LLM-empowered adversaries and enables audits of open-source models and proprietary API models in a unified framework.
Shuo Huang, G. Haffari, Xing-Liang Yuan et al.· 0 citations
A lightweight defense framework that generically augments optimization methods in the ML pipeline to have significantly-improved empirical privacy on standard benchmarks is given, and it is shown that the framework comes at no theoretical privacy cost when augmenting DP-SGD, unlike previously-proposed defenses against...
Saloni Modi, Srivi Balaji, Yu-Song Zhu et al.· 0 citations
CoVeil is proposed, a defense mechanism which dynamically optimizes transmitted signals to suppress leakage during decoding time while preserving the collaborative quality, and consistently improves the privacy-utility trade-off over existing baselines by reducing data leakage.
Ke-Jia Zhang, Tianyuan Zou, Zi-Xuan Gu et al.· 0 citations
This paper revisits the continuous noise sampling protocols and makes several improvements in both security and efficiency and turns to discrete sampling at the granularity of individual biased bits to address the security and efficiency issues together.
A systems-security case study of a two-node split-LLM training system whose privacy evaluation passed while leaving an observable channel untested, but the system is not thereby safe: five classes of attack, including those accumulating observations across training steps, were never measured.
G. Politis, E. Pappas· 1 citation
Related blog posts
MIT News · Artificial Intelligence· news.mit.eduSep 29, 2026
Professor Sherry Turkle’s new book, “Artificial Intimacy,” offers a withering critique of chatbots and the antisocial dynamics she believes they encourage.