🤖 AI Summary
This study addresses the challenge that existing differential privacy (DP) auditing methods struggle to detect residual harms in AI systems when developers strategically respond to audit protocols. The authors model privacy auditing as a Stackelberg game, wherein the auditor first commits to a query strategy and privacy budget allocation, and the developer subsequently optimizes mitigation measures in response. To capture the limitations of conventional DP audits, they introduce the welfare-weighted undetected gap metric $B_w$ and demonstrate that optimal auditing requires balancing four key factors. They develop a strategy-aware privacy budget allocation method via bilevel optimization, reformulated into a single-level problem using KKT conditions, and solved by a supergradient-projected gradient algorithm (SPAD). Theoretical analysis and experiments show that, under realistic conditions such as heterogeneous detectability, their approach significantly outperforms baseline strategies like uniform or harm-proportional budget allocations.
📝 Abstract
Regulatory audits of AI systems increasingly rely on differential privacy (DP) to protect training data and model internals. We study audit design when the audited developer can strategically respond to the privacy-constrained audit interface. We formalize privacy-constrained auditing as a bilevel Stackelberg game, in which an auditor commits to a query policy and DP budget allocation across harm dimensions, and a strategic developer reallocates mitigation efforts in response. We introduce the welfare-weighted under-detection gap $B_w$, the welfare-weighted true residual harm the audit fails to detect at the developer's strategic best response, and prove that naive DP auditing (uniform or harm-proportional allocation) induces a strictly larger $B_w$ than any non-strategic mitigation baseline whenever effective detectability is heterogeneous, the welfare weights are not comonotone with detectability, and the developer's optimum is interior. We characterize the optimal auditor allocation as a four-factor balance of welfare weight, audit miss-probability, detectability elasticity, and mitigation-cost curvature, and provide a single-level reformulation of the bilevel problem via the developer's KKT system. We propose Strategic Private Audit Design (SPAD), a projected-gradient algorithm with hypergradients computed through the developer's best response.