2026
Optimizing Canaries for Privacy Auditing with Metagradient Descent
ICLR 2026poster
In this work we study black-box privacy auditing, where the goal is to lower bound the privacy parameter of a differentially private learning algorithm using only the algorithm’s outputs (i.e., final trained model). For DP-SGD (the most successful method for training differentially private deep lear…