ResearchResearch paperEfficiency & Inference · Training & Scaling1 source · Oct 7, 2026

Closed-Form Noise Calibration Against Membership Inference for Random-Allocation DP-SGD

DP-SGD protects training data by adding Gaussian noise to clipped gradients.

Key points

  • We study DP-SGD with random allocation, where each epoch uses every record once, at a randomly chosen step.
  • For this setting we give a one-line formula that bounds the accuracy of every membership inference attack (MIA) on the trained model.
  • With $M$ steps per epoch, $E$ epochs and noise multiplier $σ$, and with membership and non-membership equally likely a priori, the attack accuracy is at most $\frac12+\frac14\sqrt{(1+(e^{1/σ^2}-1)/M)^E-1}$.
  • In training, the resulting $σ$ outperforms the formula and matches a published accountant in test accuracy.

Sources (1)

Extractive summary: sentences quoted from the sources.

Related