Efficient Public Verification of Private ML via Regularization

Zoë Ruha Bell, Anvith Thudi, Olive Franzese, Nicolas Papernot, Shafi Goldwasser
Proceedings of the 43rd International Conference on Machine Learning, PMLR 306:7454-7468, 2026.

Abstract

Training with differential privacy (DP) guarantees dataset members that they cannot be identified by users of the released model. However, those data providers, and, in general, the public, lack methods to efficiently verify that models trained on their data satisfy DP guarantees. The amount of compute needed to verify DP guarantees for current algorithms scales with the amount of computation required to train the model. In this paper we design the first DP algorithm with near optimal privacy-utility trade-offs but whose DP guarantees can be verified cheaper than training. We focus on DP stochastic convex optimization (DP-SCO), where optimal privacy-utility trade-offs are known. Here we show we can obtain tight privacy-utility trade-offs by privately minimizing a series of regularized objectives and only using the standard DP composition bound. Crucially, this method can be verified with much less compute than training. This leads to the first known DP-SCO algorithm with near optimal privacy-utility whose DP verification scales better than training cost, significantly reducing verification costs on large datasets.

Cite this Paper


BibTeX
@InProceedings{pmlr-v306-bell26b, title = {Efficient Public Verification of Private {ML} via Regularization}, author = {Bell, Zo\"{e} Ruha and Thudi, Anvith and Franzese, Olive and Papernot, Nicolas and Goldwasser, Shafi}, booktitle = {Proceedings of the 43rd International Conference on Machine Learning}, pages = {7454--7468}, year = {2026}, editor = {Zhang, Tong and Dudik, Miroslav and Jaggi, Martin and Agarwal, Alekh and Li, Sharon and Schuurmans, Dale and Zhu, Jerry and Berkenkamp, Felix and Dong, Hanze and Bietti, Alberto}, volume = {306}, series = {Proceedings of Machine Learning Research}, month = {06--11 Jul}, publisher = {PMLR}, pdf = {https://raw.githubusercontent.com/mlresearch/v306/main/assets/bell26b/bell26b.pdf}, url = {https://proceedings.mlr.press/v306/bell26b.html}, abstract = {Training with differential privacy (DP) guarantees dataset members that they cannot be identified by users of the released model. However, those data providers, and, in general, the public, lack methods to efficiently verify that models trained on their data satisfy DP guarantees. The amount of compute needed to verify DP guarantees for current algorithms scales with the amount of computation required to train the model. In this paper we design the first DP algorithm with near optimal privacy-utility trade-offs but whose DP guarantees can be verified cheaper than training. We focus on DP stochastic convex optimization (DP-SCO), where optimal privacy-utility trade-offs are known. Here we show we can obtain tight privacy-utility trade-offs by privately minimizing a series of regularized objectives and only using the standard DP composition bound. Crucially, this method can be verified with much less compute than training. This leads to the first known DP-SCO algorithm with near optimal privacy-utility whose DP verification scales better than training cost, significantly reducing verification costs on large datasets.} }
Endnote
%0 Conference Paper %T Efficient Public Verification of Private ML via Regularization %A Zoë Ruha Bell %A Anvith Thudi %A Olive Franzese %A Nicolas Papernot %A Shafi Goldwasser %B Proceedings of the 43rd International Conference on Machine Learning %C Proceedings of Machine Learning Research %D 2026 %E Tong Zhang %E Miroslav Dudik %E Martin Jaggi %E Alekh Agarwal %E Sharon Li %E Dale Schuurmans %E Jerry Zhu %E Felix Berkenkamp %E Hanze Dong %E Alberto Bietti %F pmlr-v306-bell26b %I PMLR %P 7454--7468 %U https://proceedings.mlr.press/v306/bell26b.html %V 306 %X Training with differential privacy (DP) guarantees dataset members that they cannot be identified by users of the released model. However, those data providers, and, in general, the public, lack methods to efficiently verify that models trained on their data satisfy DP guarantees. The amount of compute needed to verify DP guarantees for current algorithms scales with the amount of computation required to train the model. In this paper we design the first DP algorithm with near optimal privacy-utility trade-offs but whose DP guarantees can be verified cheaper than training. We focus on DP stochastic convex optimization (DP-SCO), where optimal privacy-utility trade-offs are known. Here we show we can obtain tight privacy-utility trade-offs by privately minimizing a series of regularized objectives and only using the standard DP composition bound. Crucially, this method can be verified with much less compute than training. This leads to the first known DP-SCO algorithm with near optimal privacy-utility whose DP verification scales better than training cost, significantly reducing verification costs on large datasets.
APA
Bell, Z.R., Thudi, A., Franzese, O., Papernot, N. & Goldwasser, S.. (2026). Efficient Public Verification of Private ML via Regularization. Proceedings of the 43rd International Conference on Machine Learning, in Proceedings of Machine Learning Research 306:7454-7468 Available from https://proceedings.mlr.press/v306/bell26b.html.

Related Material