cs.LGSep 29, 2026

A Sharp Transition in Data Reconstruction under Differential Privacy

Authors: Max Cairney-Leeming, Simone Bombari, Marco Mondelli

Organizations: Institute of Science and Technology Austria

Abstract

Data reconstruction attacks have empirically been successful in recovering training samples from learned models, raising privacy concerns and motivating defenses with guarantees that remain valid against future threats. While differential privacy (DP) provides formal protection, choosing the privacy budget remains a challenge: small budgets severely reduce utility, but it is hard to quantify how large the budget can be without allowing accurate reconstruction. In this work, we study informed attackers who aim to reconstruct a single dd-dimensional training sample from a ρρ-zero-concentrated DP model, knowing all other training data. Our main contribution is to establish a sharp transition at ρ≍dρ\asymp d for data reconstruction: on the one hand, we derive entropy-based lower bounds for any private mechanism and any attack, characterizing a set of target priors for which reconstruction is information-theoretically impossible for ρ≪dρ\ll d; on the other hand, we analyze a simple attack on private linear regression with output perturbation, showing that reconstruction is practically feasible for ρ≫dρ\gg d. Remarkably, the transition moves to ρ≍sρ\asymp s for data lying in an ss-dimensional subspace, demonstrating that the privacy budget guaranteeing adequate protection must be assessed in terms of the effective dimension of the data. We validate our findings via experiments on synthetic data and natural images (CIFAR-10, ImageNet).

Explore similar work

CardsList
  1. Efficient Techniques for Data Reconstruction, with Finite-Width Recovery Guarantees

    May 7, 2026Edward Tansley, Roy Makhlouf, Estelle Massart +1SubspaceInfinities

  2. Reducing information dependency does not cause training data privacy. Adversarially non-robust features do

    Jul 14, 2026Rasmus Torp, Shailen K. Smith, Adam BreuerPrivacyTraining Data

  3. SoK: Reconstruction Attacks on Synthetic Tabular Data (Insights from Winning the NIST CRC)

    Jun 6, 2026Steven Golob, Sikha Pentyala, Martine De CockSynthetic Tabular DataMembership Inference Attacks