{"about":{"site":"https://codewithpapers.app","non_affiliation":"Code with Papers and Syntology are not affiliated with, endorsed by, or sponsored by Papers with Code, Meta, or the pwc-archive mirror.","licence":"CC BY-SA 4.0","licence_url":"https://creativecommons.org/licenses/by-sa/4.0/legalcode","attribution":"https://codewithpapers.app/attribution","modified":"archive material modified by Syntology; see the attribution page"},"url":"/paper/one-shot-empirical-privacy-estimation-for","title":"One-shot Empirical Privacy Estimation for Federated Learning","arxiv_id":"2302.03098","date":"2023-02-06","proceeding":null,"authors":["Galen Andrew","Peter Kairouz","Sewoong Oh","Alina Oprea","H. Brendan McMahan","Vinith M. Suriyakumar"],"abstract":"Privacy estimation techniques for differentially private (DP) algorithms are useful for comparing against analytical bounds, or to empirically measure privacy loss in settings where known analytical bounds are not tight. However, existing privacy auditing techniques usually make strong assumptions on the adversary (e.g., knowledge of intermediate model iterates or the training data distribution), are tailored to specific tasks, model architectures, or DP algorithm, and/or require retraining the model many times (typically on the order of thousands). These shortcomings make deploying such techniques at scale difficult in practice, especially in federated settings where model training can take days or weeks. In this work, we present a novel \"one-shot\" approach that can systematically address these challenges, allowing efficient auditing or estimation of the privacy loss of a model during the same, single training run used to fit model parameters, and without requiring any a priori knowledge about the model architecture, task, or DP training algorithm. We show that our method provides provably correct estimates for the privacy loss under the Gaussian mechanism, and we demonstrate its performance on well-established FL benchmark datasets under several adversarial threat models.","url_abs":"https://arxiv.org/abs/2302.03098v5","url_pdf":"https://arxiv.org/pdf/2302.03098v5.pdf","source":{"archive":"pwc-archive (Hugging Face), CC BY-SA 4.0","snapshot":"2025-07-28","licence_url":"https://creativecommons.org/licenses/by-sa/4.0/legalcode","row_kind":"abstracts"},"code_links":[{"paper_slug":"one-shot-empirical-privacy-estimation-for","repo_url":"https://github.com/google-research/federated","is_official":1,"mentioned_in_paper":1,"mentioned_in_github":0,"framework":"tf","reach":null}],"tasks":[{"task_slug":"federated-learning","task_name":"Federated Learning"}],"methods":[],"datasets_introduced":[],"methods_introduced":[],"results":[],"syntology":{"atlas_url":"https://app.syntology.ai/?focus=2302.03098","mcp":{"get_harvested_code_for_paper":{"arxiv_id":"2302.03098"}},"developers":"https://syntology.ai/developers","read_at":"2026-09-24T18:15:14+00:00","read_at_is":"when the build read Syntology's graph, not when any sample ran","claim":"Per-sample execution status on synthesized fixtures; not a correctness claim about the paper. Samples come from repositories linked to the paper, official or community; repo_kind says which.","repos":[{"provenance":"external:paperswithcode_snapshot_2025-07-28","url":"https://github.com/google-research/federated","reach":null}],"summary":{"ran_honours":2,"ran_fixture":1},"by_repo_kind":{"official":{"samples":3,"ran":3,"repositories":1}},"repo_kind_vocabulary":{"official":"The archive marks this repository official for the paper","named_in_paper":"The archive records that the paper mentions this repository; it is not marked official","listed":"In the archive's code links for this paper, not marked official and not recorded as mentioned in the paper","found_in_text":"Syntology found this repository in the paper's own text; whether it is the authors' implementation is not asserted","community":"Not in the archive's code links for this paper; a community repository Syntology harvested"},"n_pointer_only_for_licence":0,"samples":[{"code_sha256_prefix":"b0df1d866e09d983","entry":"_epsilon_lower_bound","repo":"google-research/federated","repo_kind":"official","path":"one_shot_epe/empirical_privacy_estimation_lib.py","file_url":"https://github.com/google-research/federated/blob/HEAD/one_shot_epe/empirical_privacy_estimation_lib.py","link_basis":"first_harvest_node","language":"python","status":"ran_honours","verification_level":1,"contract_check":"HONOURS","metamorphic_tier":"well_formed","behaviour_fingerprint":true,"licence":"Apache-2.0","inline_ok":true,"mcp_get_code":{"code_sha256":"b0df1d866e09d983"}},{"code_sha256_prefix":"923c36a0ae072ef4","entry":"_jeffreys_high","repo":"google-research/federated","repo_kind":"official","path":"one_shot_epe/empirical_privacy_estimation_lib.py","file_url":"https://github.com/google-research/federated/blob/HEAD/one_shot_epe/empirical_privacy_estimation_lib.py","link_basis":"first_harvest_node","language":"python","status":"ran_honours","verification_level":1,"contract_check":"HONOURS","metamorphic_tier":"well_formed","behaviour_fingerprint":true,"licence":"Apache-2.0","inline_ok":true,"mcp_get_code":{"code_sha256":"923c36a0ae072ef4"}},{"code_sha256_prefix":"b1d2a132602deaa6","entry":"optimal_epsilon_lower_bound","repo":"google-research/federated","repo_kind":"official","path":"one_shot_epe/empirical_privacy_estimation_lib.py","file_url":"https://github.com/google-research/federated/blob/HEAD/one_shot_epe/empirical_privacy_estimation_lib.py","link_basis":"first_harvest_node","language":"python","status":"ran_fixture","verification_level":1,"contract_check":"RAISES","metamorphic_tier":"well_formed","behaviour_fingerprint":true,"licence":"Apache-2.0","inline_ok":true,"mcp_get_code":{"code_sha256":"b1d2a132602deaa6"}}]},"arxiv_metadata":null,"syntology_extracted_results":null}