Privacy leakage from utility-oriented sparse attacks

Characterize whether sparse malicious deviations specifically designed to maximize privacy leakage can cause additional membership leakage beyond that observed for the utility-oriented forged-gradient attacks evaluated in the paper.

Background

The paper analyzes sparse deviations in DP-SGD by studying forged-gradient attacks that steer training toward non-private checkpoints. For the evaluated attack strategies and budgets, the experiments report limited utility improvement and no measurable additional membership leakage relative to honest DP baselines.

The authors explicitly caution that these empirical results do not cover sparse attacks optimized primarily for privacy leakage. The unresolved issue is therefore whether an adversary can exploit a small number of deviations to increase membership leakage substantially, even when utility-oriented sparse attacks appear ineffective. The paper’s worst-case privacy theorem allows for substantially greater privacy loss under highly targeted, data-dependent deviations, but does not resolve the behavior of practical sparse attacks designed for that objective.

References

These results do not rule out sparse attacks designed to maximize privacy leakage: Theorem~\ref{thm:privacy_incomplete_training} characterizes a substantially worse case in which malicious iterations repeatedly expose one target user, whereas the attacks evaluated here use broad training signals.

Towards TEE-Certified DP: Verifiable Differentially Private Training on Legacy GPUs  (2609.20532 - Ge et al., 17 Sep 2026) in Section 4.2, “Analysis of Sparse Malicious Deviations,” subsection “Utility Analysis”