Score
Designs, builds, and integrates mechanisms and architectures that enforce differential privacy guarantees, including calibrated-noise algorithms, local-differential-privacy transformations, gradient clipping and noise in training, privacy-preserving aggregation and logging pipelines, and system- or hardware-level DP enforcement at scale. Analyzes and proves privacy-utility trade-offs and information-theoretic leakage, implements privacy-budget accounting, and evaluates privacy risk and compliance of data releases, models, and shared outputs.
This paper systematically surveys differential privacy (DP) auditing research, identifying three critical limitations in existing approaches: inefficiency, lack of end-to-end applicability, and loose (non-tight) guarantees. To address these, the authors propose the first unified evaluation framework encompassing all three dimensions—efficiency, end-to-end coverage, and tightness—by integrating threat models, attack paradigms, and evaluation functions. Grounded in a systematic literature review, formal modeling, and multidimensional comparative analysis, the study exposes fundamental blind spots and bottlenecks in prior work. Key contributions include: (1) the first cross-scenario DP auditing objective taxonomy; (2) a reusable, principled methodology for systematic DP audit evaluation; and (3) a standardized evaluation pipeline, a map of critical friction points, and actionable guidance for future research. Collectively, this work establishes foundational theoretical and practical support for advancing DP auditing toward rigorous, scalable, and deployable assurance.
The widespread use of personal data has intensified privacy leakage risks—particularly under strong re-identification attacks and mounting regulatory compliance pressures. Differential privacy (DP), a mathematically rigorous privacy-preserving paradigm, has emerged as a foundational mitigation strategy. This paper systematically surveys DP’s theoretical foundations, mainstream mechanisms—including Laplace/Gaussian noise injection, privacy budget allocation, and sensitive query perturbation—as well as its cutting-edge applications in privacy-preserving machine learning and synthetic data generation. It critically examines practical challenges: utility–privacy trade-offs, cross-domain adaptability, and user comprehension barriers. Building on this analysis, the paper proposes a practice-oriented framework centered on enhancing system transparency, interpretability, and usability. Designed for both researchers and practitioners, the framework bridges theoretical rigor with engineering feasibility, facilitating trustworthy DP deployment in high-stakes domains such as healthcare and cybersecurity.
Existing formal methods struggle to verify the privacy guarantees of modern differential privacy libraries that employ complex programming patterns such as higher-order functions, local state, and interactive algorithms. This work proposes a probabilistic higher-order separation logic that, for the first time, incorporates first-class support for privacy budgets within separation logic, treating them as composable resources to enable modular reasoning. Implemented in the Rocq proof assistant, the logic successfully verifies differential privacy programs featuring higher-order combinators, caching, and interactive mechanisms. Furthermore, the authors construct a formally verified library of mechanisms, including the online sparse vector technique and privacy filters inspired by OpenDP, thereby enabling end-to-end verification of client programs.
This work addresses the limitations of existing differential privacy (DP) auditing methods, which predominantly rely on batch sampling and are confined to $(\varepsilon, \delta)$-DP, thereby failing to comprehensively evaluate privacy guarantees under $f$-DP. To overcome this, we propose the first adaptive sequential auditing framework capable of full-spectrum privacy behavior detection for $f$-DP mechanisms without requiring a pre-specified sample size. Our approach operates in both white-box and black-box settings and constructs a sequential hypothesis test grounded in statistical significance theory, leveraging the trade-off function inherent to $f$-DP to identify privacy violations. Theoretical analysis and empirical evaluations demonstrate that our method significantly reduces sampling costs while maintaining statistical power, achieving substantial efficiency gains—particularly in high-overhead scenarios such as DP-SGD—by markedly decreasing the number of required samples.
This paper addresses privacy accounting for subsampling mechanisms—specifically Poisson and without-replacement sampling—in compositional settings under differential privacy (DP), identifying two prevalent misuses: (i) erroneously assuming the worst-case dataset for a single step suffices for adaptive composition analysis, and (ii) conflating the distinct privacy loss characteristics of the two sampling schemes. Method: We rigorously prove that privacy parameters for subsampled composition cannot be derived by naïvely composing single-step worst-case guarantees. Leveraging Rényi differential privacy and exact privacy loss distribution analysis, we develop a numerical accounting framework incorporating counterexample construction and tight theoretical bounds. Contribution/Results: We establish a decidable criterion for detecting and correcting such misuses, and demonstrate—under typical DP-SGD parameters—that ε values for Poisson and without-replacement sampling may differ by over an order of magnitude. Empirical evaluation confirms our framework prevents significant over- or under-estimation of privacy budgets, substantially improving the reliability of privacy guarantees.
This work addresses the risk that third-party applications in federated learning may misuse sensitive data despite claiming to implement differential privacy, forcing users to trust their correct execution. To eliminate this trust assumption, the authors propose DataGuard—a hardware-based privacy enforcement mechanism that embeds differential privacy compliance verification logic directly within systolic array accelerators. This design ensures that only computation results satisfying the prescribed privacy budget can leave the device, without relying on the integrity of third-party software. Evaluated via simulation across four accelerator architectures, DataGuard incurs less than 0.01% area overhead and under 0.3% performance degradation, demonstrating an efficient and practical approach to hardening privacy guarantees at the hardware level.
This work addresses the challenge of repeated leakage of sensitive information in privacy-sensitive streaming runtime monitoring, where temporal operations inherently amplify privacy risks. It presents the first approach to automatically integrate differential privacy into stream monitoring specifications by analyzing temporal dependencies and strategically injecting noise at critical points. To minimize aggregation error, the method incorporates a tree-based mechanism that jointly optimizes privacy guarantees and monitoring utility. The effectiveness of this approach is demonstrated in a public transportation usage monitoring case study, where it significantly preserves output accuracy while rigorously adhering to differential privacy constraints.
This work addresses the challenge of automating the design and verification of differentially private (DP) algorithms, which currently rely heavily on expert knowledge. To this end, the authors introduce DPrivBench, the first systematic benchmark for evaluating large language models’ (LLMs’) reasoning capabilities in DP. The benchmark encompasses diverse topics and difficulty levels while deliberately avoiding shortcut solutions based on pattern matching. Empirical evaluation using DPrivBench reveals that although current LLMs can handle classical DP mechanisms, they exhibit significant gaps when reasoning about more complex DP algorithms. By integrating automated reasoning, DP theory, and adversarial benchmark design, this study establishes a foundational framework for assessing and advancing automated DP verification.
This work addresses a critical discrepancy in the privacy analysis of existing DP-SGD implementations: due to gradient averaging, their actual mechanisms align more closely with the Expected Average Stochastic Gradient Mechanism (EASGM) or Average Stochastic Gradient Mechanism (ASGM) rather than the standard Stochastic Gradient Mechanism (SGM). Consequently, conventional SGM-based privacy analyses overstate the privacy guarantees. The paper is the first to explicitly distinguish between these gradient averaging strategies in DP-SGD and rigorously analyze their impact on privacy loss. It provides refined theoretical bounds and empirical privacy audits based on variants of the Subsampled Gaussian Mechanism—specifically EASGM and ASGM—and formally proves that their privacy guarantees are strictly weaker than those of SGM. Empirical evaluation across four widely used implementations reveals privacy leakage exceeding SGM assumptions, and the study establishes tight, corrected privacy bounds for the latest version of Opacus.