We address the problem of empirical privacy auditing for differentially private stochas- tic gradient descent (DP-SGD) under the hidden state threat model, where adversaries only observe the final ...