English

Auditing Differential Privacy in the Black-Box Setting

Methodology 2025-04-14 v2 Cryptography and Security Machine Learning

Abstract

This paper introduces a novel theoretical framework for auditing differential privacy (DP) in a black-box setting. Leveraging the concept of ff-differential privacy, we explicitly define type I and type II errors and propose an auditing mechanism based on conformal inference. Our approach robustly controls the type I error rate under minimal assumptions. Furthermore, we establish a fundamental impossibility result, demonstrating the inherent difficulty of simultaneously controlling both type I and type II errors without additional assumptions. Nevertheless, under a monotone likelihood ratio (MLR) assumption, our auditing mechanism effectively controls both errors. We also extend our method to construct valid confidence bands for the trade-off function in the finite-sample regime.

Keywords

Cite

@article{arxiv.2503.12045,
  title  = {Auditing Differential Privacy in the Black-Box Setting},
  author = {Kaining Shi and Cong Ma},
  journal= {arXiv preprint arXiv:2503.12045},
  year   = {2025}
}

Comments

work in progress, comments are welcomed

R2 v1 2026-06-28T22:21:46.385Z