
MB
Murat Bilgehan Ertan, Marten van Dijk
· 1 min read
ResearcharXiv cs.LG
Closed-Form Noise Calibration Against Membership Inference for Random-Allocation DP-SGD
arXiv:2610.09651v1 Announce Type: new
Abstract: DP-SGD protects training data by adding Gaussian noise to clipped gradients. The amount of noise is usually chosen by running a numerical privacy accountant inside a search. We study DP-SGD with random allocation, where each epoch uses every record once, at a randomly chosen step. For this setting we give a one-line formula that bounds the accuracy of every membership inference attack (MIA) on the trained model. With $M$ steps per epoch, $E$ epochs and noise multiplier $\sigma$, and with membership and non-membership equally likely a priori, the attack accuracy is at most $\frac12+\frac14\sqrt{(1+(e^{1/\sigma^2}-1)/M)^E-1}$. The formula comes from the chi-square divergence between a Gaussian distribution and a Gaussian mixture that dominates random allocation. It is interpretable and gives $\sigma$ in about a microsecond. Where applicable, our formula needs at most about half the noise of the state-of-the-art closed-form bound. To measure how close the bound is, we also derive an exact expression for the attack accuracy of these two distributions and evaluate it numerically. Calibrating to this exact expression requires $13.0\%$ to $20.2\%$ less noise than the formula in our main experiments, and since it is exact, no accountant that knows only $M$, $E$ and $\sigma$ can certify a smaller $\sigma$. In training, the resulting $\sigma$ outperforms the formula and matches a published accountant in test accuracy. It is found in seconds and certified in minutes, whereas every search we ran with that accountant took longer or returned at least $0.62\%$ more noise. We show that MIAs on the trained models stay below the bound.
Original source
This story was published by arXiv cs.LG and written by Murat Bilgehan Ertan, Marten van Dijk. SyncAI.news shows a preview; the complete article is on the publisher's site.
Read the full story on arxiv.org


