Tag
The paper proposes a lightweight defense framework to enhance the empirical privacy of DP-SGD without theoretical privacy cost, validated through extensive audits across models, datasets, and threat models.