{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,4]],"date-time":"2026-05-04T13:09:04Z","timestamp":1777900144108,"version":"3.51.4"},"publisher-location":"Cham","reference-count":31,"publisher":"Springer Nature Switzerland","isbn-type":[{"value":"9783032060952","type":"print"},{"value":"9783032060969","type":"electronic"}],"license":[{"start":{"date-parts":[[2025,9,27]],"date-time":"2025-09-27T00:00:00Z","timestamp":1758931200000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2025,9,27]],"date-time":"2025-09-27T00:00:00Z","timestamp":1758931200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2026]]},"DOI":"10.1007\/978-3-032-06096-9_23","type":"book-chapter","created":{"date-parts":[[2025,9,26]],"date-time":"2025-09-26T09:54:41Z","timestamp":1758880481000},"page":"397-414","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":0,"title":["MCMC for\u00a0Bayesian Estimation of\u00a0Differential Privacy from\u00a0Membership Inference Attacks"],"prefix":"10.1007","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-8029-6520","authenticated-orcid":false,"given":"Ceren","family":"Y\u0131ld\u0131r\u0131m","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-8678-5467","authenticated-orcid":false,"given":"Kamer","family":"Kaya","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-7980-8990","authenticated-orcid":false,"given":"Sinan","family":"Y\u0131ld\u0131r\u0131m","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-4869-5556","authenticated-orcid":false,"given":"Erkay","family":"Sava\u015f","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2025,9,27]]},"reference":[{"key":"23_CR1","unstructured":"Abadi, M., et al.: TensorFlow: large-scale machine learning on heterogeneous systems (2015). https:\/\/www.tensorflow.org\/, software available from tensorflow.org"},{"key":"23_CR2","unstructured":"Andrew, G., Kairouz, P., Oh, S., Oprea, A., McMahan, H.B., Suriyakumar, V.M.: One-shot empirical privacy estimation for federated learning. In: 12th International Conference on Learning Representation (2024)"},{"key":"23_CR3","unstructured":"Andrieu, C., Y\u0131ld\u0131r\u0131m, S., Doucet, A., Chopin, N.: Metropolis-hastings with averaged acceptance ratios (2020). https:\/\/arxiv.org\/abs\/2101.01253"},{"key":"23_CR4","unstructured":"Balle, B., Barthe, G., Gaboardi, M.: Privacy amplification by subsampling: tight analyses via couplings and divergences. In: Proceedings of the 32nd International Conference on Neural Information Processing Systems, NIPS 2018, , pp. 6280\u20136290. Curran Associates Inc., Red Hook (2018)"},{"key":"23_CR5","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"635","DOI":"10.1007\/978-3-662-53641-4_24","volume-title":"Theory of Cryptography","author":"M Bun","year":"2016","unstructured":"Bun, M., Steinke, T.: Concentrated differential privacy: simplifications, extensions, and lower bounds. In: Hirt, M., Smith, A. (eds.) TCC 2016. LNCS, vol. 9985, pp. 635\u2013658. Springer, Heidelberg (2016). https:\/\/doi.org\/10.1007\/978-3-662-53641-4_24"},{"key":"23_CR6","doi-asserted-by":"crossref","unstructured":"Carlini, N., Chien, S., Nasr, M., Song, S., Terzis, A., Tram\u00e8r, F.: Membership inference attacks from first principles. In: 2022 IEEE Symposium on Security and Privacy (SP), pp. 1897\u20131914 (2022)","DOI":"10.1109\/SP46214.2022.9833649"},{"key":"23_CR7","unstructured":"Chollet, F., et\u00a0al.: Keras (2015). https:\/\/keras.io"},{"issue":"6","key":"23_CR8","doi-asserted-by":"publisher","first-page":"141","DOI":"10.1109\/MSP.2012.2211477","volume":"29","author":"L Deng","year":"2012","unstructured":"Deng, L.: The MNIST database of handwritten digit images for machine learning research. IEEE Signal Process. Mag. 29(6), 141\u2013142 (2012)","journal-title":"IEEE Signal Process. Mag."},{"key":"23_CR9","doi-asserted-by":"crossref","unstructured":"Dong, J., Roth, A., Su, W.J.: Gaussian differential privacy. J. Roy. Stat. Society Ser. B: Stat. Methodol. 84(1), 3\u201337 (2022)","DOI":"10.1111\/rssb.12454"},{"key":"23_CR10","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1007\/11787006_1","volume-title":"Automata, Languages and Programming","author":"C Dwork","year":"2006","unstructured":"Dwork, C.: Differential privacy. In: Bugliesi, M., Preneel, B., Sassone, V., Wegener, I. (eds.) ICALP 2006. LNCS, vol. 4052, pp. 1\u201312. Springer, Heidelberg (2006). https:\/\/doi.org\/10.1007\/11787006_1"},{"key":"23_CR11","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"265","DOI":"10.1007\/11681878_14","volume-title":"Theory of Cryptography","author":"C Dwork","year":"2006","unstructured":"Dwork, C., McSherry, F., Nissim, K., Smith, A.: Calibrating noise to sensitivity in private data analysis. In: Halevi, S., Rabin, T. (eds.) TCC 2006. LNCS, vol. 3876, pp. 265\u2013284. Springer, Heidelberg (2006). https:\/\/doi.org\/10.1007\/11681878_14"},{"key":"23_CR12","doi-asserted-by":"crossref","unstructured":"Dwork, C., Roth, A.: The algorithmic foundations of differential privacy. Found. Trends\u00ae Theor. Comput. Sci. 9(3\u20134), 211\u2013407 (2014)","DOI":"10.1561\/0400000042"},{"key":"23_CR13","unstructured":"Hyland, S.L., Tople, S.: An empirical study on the intrinsic privacy of SGD (2022). https:\/\/arxiv.org\/abs\/1912.02919"},{"key":"23_CR14","unstructured":"Jagielski, M., Ullman, J., Oprea, A.: Auditing differentially private machine learning: how private is private SGD? In: Proceedings of the 34th International Conference on Neural Information Processing Systems, NIPS 2020. Curran Associates Inc., Red Hook (2020)"},{"key":"23_CR15","unstructured":"Kairouz, P., Oh, S., Viswanath, P.: The composition theorem for differential privacy. In: Bach, F., Blei, D. (eds.) Proceedings of the 32nd International Conference on Machine Learning. Proceedings of Machine Learning Research, vol.\u00a037, pp. 1376\u20131385. PMLR, Lille (2015)"},{"issue":"6","key":"23_CR16","doi-asserted-by":"publisher","first-page":"4037","DOI":"10.1109\/TIT.2017.2685505","volume":"63","author":"P Kairouz","year":"2017","unstructured":"Kairouz, P., Oh, S., Viswanath, P.: The composition theorem for differential privacy. IEEE Trans. Inf. Theor. 63(6), 4037\u20134049 (2017)","journal-title":"IEEE Trans. Inf. Theor."},{"issue":"1","key":"23_CR17","doi-asserted-by":"publisher","first-page":"69","DOI":"10.2307\/2529589","volume":"34","author":"LL Kupper","year":"1978","unstructured":"Kupper, L.L., Haseman, J.K.: The use of a correlated binomial model for the analysis of certain toxicological experiments. Biometrics 34(1), 69\u201376 (1978)","journal-title":"Biometrics"},{"key":"23_CR18","unstructured":"Leemann, T., Pawelczyk, M., Kasneci, G.: Gaussian membership inference privacy. In: Thirty-seventh Conference on Neural Information Processing Systems (2023)"},{"key":"23_CR19","unstructured":"Lu, F., et al.: A general framework for auditing differentially private machine learning. In: Oh, A.H., Agarwal, A., Belgrave, D., Cho, K. (eds.) Advances in Neural Information Processing Systems (2022)"},{"key":"23_CR20","unstructured":"Maddock, S., Sablayrolles, A., Stock, P.: CANIFE: crafting canaries for empirical privacy measurement in federated learning. In: ICLR (2023)"},{"key":"23_CR21","doi-asserted-by":"publisher","unstructured":"Mironov, I.: R\u00e9nyi differential privacy . In: 2017 IEEE 30th Computer Security Foundations Symposium (CSF), pp. 263\u2013275. IEEE Computer Society, Los Alamitos (2017). https:\/\/doi.org\/10.1109\/CSF.2017.11","DOI":"10.1109\/CSF.2017.11"},{"key":"23_CR22","unstructured":"Nasr, M., et al.: Tight auditing of differentially private machine learning. In: Proceedings of the 32nd USENIX Conference on Security Symposium, SEC 2023. USENIX, USA (2023)"},{"key":"23_CR23","doi-asserted-by":"crossref","unstructured":"Nasr, M., Songi, S., Thakurta, A., Papernot, N., Carlin, N.: Adversary instantiation: lower bounds for differentially private machine learning. In: 2021 IEEE Symposium on security and privacy (SP), pp. 866\u2013882. IEEE (2021)","DOI":"10.1109\/SP40001.2021.00069"},{"key":"23_CR24","unstructured":"Nasr, M., et al.: The last iterate advantage: empirical auditing and principled heuristic analysis of differentially private SGD. In: The 13th International Conference on Learning Representation (2025)"},{"key":"23_CR25","doi-asserted-by":"crossref","unstructured":"Pillutla, K., Andrew, G., Kairouz, P., McMahan, H.B., Oprea, A., Oh, S.: Unleashing the power of randomization in auditing differentially private ml. In: Proceedings of the 37th International Conference on Neural Information Processing Systems, NIPS 2023. Curran Associates Inc., Red Hook (2023)","DOI":"10.52202\/075280-2890"},{"key":"23_CR26","unstructured":"Sablayrolles, A., Douze, M., Schmid, C., Ollivier, Y., J\u00e9gou, H.: White-box vs black-box: bayes optimal strategies for membership inference. In: International Conference on Machine Learning (2019)"},{"key":"23_CR27","doi-asserted-by":"publisher","unstructured":"Shokri, R., Stronati, M., Song, C., Shmatikov, V.: Membership inference attacks against machine learning models. In: 2017 IEEE Symposium on Security and Privacy (SP), pp. 3\u201318. IEEE Computer Society, Los Alamitos (2017). https:\/\/doi.org\/10.1109\/SP.2017.41","DOI":"10.1109\/SP.2017.41"},{"key":"23_CR28","unstructured":"Steinke, T., Nasr, M., Jagielski, M.: Privacy auditing with one (1) training run. In: Thirty-seventh Conference on Neural Information Processing Systems (2023)"},{"key":"23_CR29","doi-asserted-by":"publisher","unstructured":"Ye, J., Maddi, A., Murakonda, S.K., Bindschaedler, V., Shokri, R.: Enhanced membership inference attacks against machine learning models. In: Proceedings of the 2022 ACM SIGSAC Conference on Computer and Communication Security, CCS 2022, pp. 3093\u20133106. ACM, New York (2022). https:\/\/doi.org\/10.1145\/3548606.3560675","DOI":"10.1145\/3548606.3560675"},{"key":"23_CR30","doi-asserted-by":"publisher","unstructured":"Yeom, S., Giacomelli, I., Fredrikson, M., Jha, S.: Privacy risk in machine learning: analyzing the connection to overfitting . In: 2018 IEEE 31st Computer Security Foundations Symposium (CSF), pp. 268\u2013282. IEEE Computer Society, Los Alamitos (2018). https:\/\/doi.org\/10.1109\/CSF.2018.00027","DOI":"10.1109\/CSF.2018.00027"},{"key":"23_CR31","unstructured":"Zanella-Beguelin, S., et\u00a0al.: Bayesian estimation of differential privacy. In: Proceedings of the 40th International Conference on Machine Learning, vol.\u00a0202, pp. 40624\u201340636. PMLR (2023)"}],"container-title":["Lecture Notes in Computer Science","Machine Learning and Knowledge Discovery in Databases. Research Track"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-032-06096-9_23","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,5,1]],"date-time":"2026-05-01T10:24:51Z","timestamp":1777631091000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-3-032-06096-9_23"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,9,27]]},"ISBN":["9783032060952","9783032060969"],"references-count":31,"URL":"https:\/\/doi.org\/10.1007\/978-3-032-06096-9_23","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"value":"0302-9743","type":"print"},{"value":"1611-3349","type":"electronic"}],"subject":[],"published":{"date-parts":[[2025,9,27]]},"assertion":[{"value":"27 September 2025","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"The authors have no competing interests to declare that are relevant to the content of this article.","order":1,"name":"Ethics","group":{"name":"EthicsHeading","label":"Disclosure of Interests"}},{"value":"ECML PKDD","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Joint European Conference on Machine Learning and Knowledge Discovery in Databases","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Porto","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Portugal","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2025","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"15 September 2025","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"19 September 2025","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"ecml2025","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"https:\/\/ecmlpkdd.org\/2025\/","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}}]}}