Privacy Auditing with Zero (0) Training Run
cs.CR
Submitted: 2026-05-14
Updated: 2026-09-10
License: http://creativecommons.org/licenses/by/4.0/
The gist: Privacy auditing provides empirical lower bounds on the differential privacy parameters of learning algorithms.
Terminology
Abstract
Privacy auditing provides empirical lower bounds on the differential privacy parameters of learning algorithms. Existing methods, however, require interventional access to the training pipeline, either to retrain models multiple times or to randomize data inclusion. This is often infeasible for large and opaque deployed systems such as foundation or language models. We introduce Zero-Run privacy auditing, a framework for auditing models post-hoc using two fixed datasets: examples known to be training-set members and examples known to be non-members. In this observational regime, membership is no longer randomized; instead, member and non-member data often differ in distribution, so membership inference scores may reflect a distribution shift rather than algorithmic leakage. Drawing on ideas from causal inference, we formalize this confounding effect and propose two complementary corrections that yield valid privacy audits. Our first approach models the combined effect of distribution shift and algorithmic leakage as an adaptive composition, producing conservative global corrections. Our second approach conditions on observed data and adjusts pointwise membership guesses, yielding sharper instance-dependent bounds. Experiments on synthetic data and large-scale image and text models show that Zero-Run auditing enables practical privacy evaluation when retraining or controlled data insertion is infeasible.
Sources
- The Hitchhiker's Guide to Efficient, End-to-End, and Tight DP Auditing
- Quantifying Memorization Across Neural Language Models
- Privacy in Theory, Bugs in Practice: Grey-Box Auditing of Differential Privacy Libraries
- Moshi: a speech-text foundation model for real-time dialogue
- An Image is Worth 16x16 Words: Transformers for Image Recognition at Scale
- Causal Evaluation of Membership Inference Attacks
- Gaussian DP for Reporting Differential Privacy Guarantees in Machine Learning
- TabPFN: A Transformer That Solves Small Tabular Classification Problems in a Second
- Mistral 7B
- Auditing $f$-Differential Privacy in One Run
- WILDS: A Benchmark of in-the-Wild Distribution Shifts
- SoK: Membership Inference Attacks on LLMs are Rushing Nowhere (and How to Fix It)
- Detecting Pretraining Data from Large Language Models
- VaultGemma: A Differentially Private Gemma Model
- LLaMA: Open and Efficient Foundation Language Models
- Debugging Differential Privacy: A Case Study for Privacy Auditing
Related papers
- SoK: AI-Augmented Binary Reversing
- Relaxed Sender Anonymity for CBDC Interbank Settlement: A Zero-Knowledge Approach on Permissioned EVM
- Calibration-Family Overfit: Why Trusted Sabotage Monitors Don't Transfer Across Lineages
- Efficient Fuzzy PSI under One-Sided Assumptions
- Sealing the Audit-Runtime Gap for LLM Skills
- Token Composition: A Graph Based on EVM Logs