Privacy leakage from utility-oriented sparse attacks
Characterize whether sparse malicious deviations specifically designed to maximize privacy leakage can cause additional membership leakage beyond that observed for the utility-oriented forged-gradient attacks evaluated in the paper.
References
These results do not rule out sparse attacks designed to maximize privacy leakage: Theorem~\ref{thm:privacy_incomplete_training} characterizes a substantially worse case in which malicious iterations repeatedly expose one target user, whereas the attacks evaluated here use broad training signals.
— Towards TEE-Certified DP: Verifiable Differentially Private Training on Legacy GPUs
(2609.20532 - Ge et al., 17 Sep 2026) in Section 4.2, “Analysis of Sparse Malicious Deviations,” subsection “Utility Analysis”