Auditing Private Prediction
Developed novel techniques to audit the Renyi DP satisfied by a mechanism. Used the framework to elicit empirical privacy guarantees for a variety of private prediction algorithms like PATE, CaPC, PromptPATE and Private kNN across varying levels of adversary access and observation models.
Better White-Box Membership Inference Attacks
Working on developing better membership inference attacks with white-box access to mechanism outputs.