NeurIPS 2020

Auditing Differentially Private Machine Learning: How Private is Private SGD?

Meta Review

All three reviewers support acceptance of this paper. They agree that providing lower bounds on the privacy guarantees of DP-SGD is an important problem and that the paper makes significant headway on this problem. I therefore recommend accept. It would be worthwhile to incorporate changes to the camera ready version of the paper clarifying some of Reviewer 1's questions.