acceptodds
Under review as a conference paper at ICLR 2027

Attested but Unaccounted: DP-SGD Privacy Accounting as a Precondition of Every Step

Abstract

Confidential training offers one attestation report as evidence for two claims: that data stays inside an attested virtual machine, and that the released model satisfies (ε, δ)-differential privacy. The report supports only the first, because it measures code, whereas ε depends on how many steps touched the data and which composition state accounted for them. We propose DP-Attest, which makes privacy accounting a precondition of every DP-SGD step: an attested accountant charges and seals each step against an external register before minting the token that a separate data plane requires to serve that step's batch. We measure the gap across seven accounting surfaces in six widely used packages, in real DP-SGD training and with membership audits; prove that the durable accounting state dominates the cost of every released output; and show that a fresh-once registration, which refuses every repeated sample context, makes the accountant enforce the schedule our privacy corollary assumes. No surface compares a loaded composition state with the one it holds, so DP-SGD that checkpoints, crashes and resumes touches 800 steps while accounting for 600, and at a fixed published ε, rewinding the accountant buys up to 54 accuracy points. DP-Attest shows no invariant violations across 235,298 enumerated interleavings of crashes, rollbacks and replays, and its gate removes the rewinding gain for a measured 0.21% of a 29.36 ms step in a CPU prototype. Binding ε to the steps a trainer ran turns a privacy claim from an assertion into an accounting any verifier can recompute.

Then back it, or bet against it.

Related papers

Open the market on this paper to see 7 more related papers.