{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,6]],"date-time":"2026-05-06T23:14:35Z","timestamp":1778109275431,"version":"3.51.4"},"publisher-location":"Cham","reference-count":25,"publisher":"Springer Nature Switzerland","isbn-type":[{"value":"9783032160911","type":"print"},{"value":"9783032160928","type":"electronic"}],"license":[{"start":{"date-parts":[[2026,1,1]],"date-time":"2026-01-01T00:00:00Z","timestamp":1767225600000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2026,1,1]],"date-time":"2026-01-01T00:00:00Z","timestamp":1767225600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2026]]},"DOI":"10.1007\/978-3-032-16092-8_25","type":"book-chapter","created":{"date-parts":[[2026,5,6]],"date-time":"2026-05-06T22:50:47Z","timestamp":1778107847000},"page":"456-473","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":0,"title":["Adaptive Token-Weighted Differential Privacy for\u00a0LLMs: Not All Tokens Require Equal Protection"],"prefix":"10.1007","author":[{"given":"Manjiang","family":"Yu","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Priyanka","family":"Singh","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Xue","family":"Li","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Yang","family":"Cao","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2026,5,1]]},"reference":[{"key":"25_CR1","doi-asserted-by":"crossref","unstructured":"Abadi, M., et al.: Deep learning with differential privacy. In: Proceedings of the 2016 ACM SIGSAC Conference on Computer and Communications Security, pp. 308\u2013318 (2016)","DOI":"10.1145\/2976749.2978318"},{"key":"25_CR2","unstructured":"Biderman, S., et\u00a0al.: Pythia: a suite for analyzing large language models across training and scaling. In: International Conference on Machine Learning, pp. 2397\u20132430. PMLR (2023)"},{"key":"25_CR3","doi-asserted-by":"crossref","unstructured":"Black, S., et\u00a0al.: GPT-neox-20b: an open-source autoregressive language model. arXiv preprint arXiv:2204.06745 (2022)","DOI":"10.18653\/v1\/2022.bigscience-1.9"},{"key":"25_CR4","doi-asserted-by":"crossref","unstructured":"Brown, H., Lee, K., Mireshghallah, F., Shokri, R., Tram\u00e8r, F.: What does it mean for a language model to preserve privacy? In: Proceedings of the 2022 ACM Conference on Fairness, Accountability, and Transparency, pp. 2280\u20132292 (2022)","DOI":"10.1145\/3531146.3534642"},{"key":"25_CR5","doi-asserted-by":"crossref","unstructured":"Carlini, N., Ippolito, D., Jagielski, M., Lee, K., Tramer, F., Zhang, C.: Quantifying memorization across neural language models. arXiv preprint arXiv:2202.07646 (2022)","DOI":"10.52202\/075280-1708"},{"key":"25_CR6","unstructured":"Carlini, N., Liu, C., Erlingsson, \u00da., Kos, J., Song, D.: The secret sharer: evaluating and testing unintended memorization in neural networks. In: 28th USENIX Security Symposium (USENIX Security 2019), pp. 267\u2013284 (2019)"},{"key":"25_CR7","unstructured":"Carlini, N., et\u00a0al.: Extracting training data from large language models. In: 30th USENIX Security Symposium (USENIX Security 2021), pp. 2633\u20132650 (2021)"},{"key":"25_CR8","doi-asserted-by":"crossref","unstructured":"Chen, D., Chen, H., Yang, Y., Lin, A., Yu, Z.: Action-based conversations dataset: a corpus for building more in-depth task-oriented dialogue systems. arXiv preprint arXiv:2104.00783 (2021)","DOI":"10.18653\/v1\/2021.naacl-main.239"},{"key":"25_CR9","doi-asserted-by":"crossref","unstructured":"Dwork, C.: Differential privacy: a survey of results. In: International Conference on Theory and Applications of Models of Computation, pp. 1\u201319. Springer, Cham (2008)","DOI":"10.1007\/978-3-540-79228-4_1"},{"key":"25_CR10","doi-asserted-by":"crossref","unstructured":"Dwork, C., Roth, A., et\u00a0al.: The algorithmic foundations of differential privacy. Found. Trends\u00ae Theor. Comput. Sci. 9(3\u20134), 211\u2013407 (2014)","DOI":"10.1561\/0400000042"},{"key":"25_CR11","first-page":"27131","volume":"34","author":"B Ghazi","year":"2021","unstructured":"Ghazi, B., Golowich, N., Kumar, R., Manurangsi, P., Zhang, C.: Deep learning with label differential privacy. Adv. Neural. Inf. Process. Syst. 34, 27131\u201327145 (2021)","journal-title":"Adv. Neural. Inf. Process. Syst."},{"key":"25_CR12","unstructured":"Honnibal, M., Montani, I., Van\u00a0Landeghem, S., Boyd, A., et\u00a0al.: spacy: industrial-strength natural language processing in python (2020)"},{"key":"25_CR13","unstructured":"Li, X., Tramer, F., Liang, P., Hashimoto, T.: Large language models can be strong differentially private learners. arXiv preprint arXiv:2110.05679 (2021)"},{"key":"25_CR14","unstructured":"Merity, S., Xiong, C., Bradbury, J., Socher, R.: Pointer sentinel mixture models. arXiv preprint arXiv:1609.07843 (2016)"},{"key":"25_CR15","unstructured":"Nasr, M., et al.: Scalable extraction of training data from (production) language models. arXiv preprint arXiv:2311.17035 (2023)"},{"key":"25_CR16","unstructured":"Papernot, N., Abadi, M., Erlingsson, U., Goodfellow, I., Talwar, K.: Semi-supervised knowledge transfer for deep learning from private training data. arXiv preprint arXiv:1610.05755 (2016)"},{"key":"25_CR17","doi-asserted-by":"crossref","unstructured":"Shi, W., Cui, A., Li, E., Jia, R., Yu, Z.: Selective differential privacy for language modeling. arXiv preprint arXiv:2108.12944 (2021)","DOI":"10.18653\/v1\/2022.naacl-main.205"},{"key":"25_CR18","doi-asserted-by":"crossref","unstructured":"Shi, W., Shea, R., Chen, S., Zhang, C., Jia, R., Yu, Z.: Just fine-tune twice: Selective differential privacy for large language models. arXiv preprint arXiv:2204.07667 (2022)","DOI":"10.18653\/v1\/2022.emnlp-main.425"},{"key":"25_CR19","doi-asserted-by":"crossref","unstructured":"Shokri, R., Stronati, M., Song, C., Shmatikov, V.: Membership inference attacks against machine learning models. In: 2017 IEEE Symposium on Security and Privacy (SP), pp. 3\u201318. IEEE (2017)","DOI":"10.1109\/SP.2017.41"},{"key":"25_CR20","unstructured":"Touvron, H., et\u00a0al.: Llama: open and efficient foundation language models. arXiv preprint arXiv:2302.13971 (2023)"},{"key":"25_CR21","unstructured":"Tramer, F., Boneh, D.: Differentially private learning needs better features (or much more data). arXiv preprint arXiv:2011.11660 (2020)"},{"key":"25_CR22","unstructured":"Vaswani, A., et al.: Attention is all you need. In: Advances in Neural Information Processing Systems, vol. 30 (2017)"},{"key":"25_CR23","doi-asserted-by":"publisher","DOI":"10.1016\/j.ins.2024.121000","volume":"678","author":"T Wang","year":"2024","unstructured":"Wang, T., Zhai, L., Yang, T., Luo, Z., Liu, S.: Selective privacy-preserving framework for large language models fine-tuning. Inf. Sci. 678, 121000 (2024)","journal-title":"Inf. Sci."},{"key":"25_CR24","doi-asserted-by":"crossref","unstructured":"Wu, X., Gong, L., Xiong, D.: Adaptive differential privacy for language model training. In: Proceedings of the First Workshop on Federated Learning for Natural Language Processing (FL4NLP 2022), pp. 21\u201326 (2022)","DOI":"10.18653\/v1\/2022.fl4nlp-1.3"},{"key":"25_CR25","unstructured":"Yu, D., et\u00a0al.: Differentially private fine-tuning of language models. arXiv preprint arXiv:2110.06500 (2021)"}],"container-title":["Lecture Notes in Computer Science","Computer Security. ESORICS 2025 International Workshops"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-032-16092-8_25","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,5,6]],"date-time":"2026-05-06T22:50:51Z","timestamp":1778107851000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-3-032-16092-8_25"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026]]},"ISBN":["9783032160911","9783032160928"],"references-count":25,"URL":"https:\/\/doi.org\/10.1007\/978-3-032-16092-8_25","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"value":"0302-9743","type":"print"},{"value":"1611-3349","type":"electronic"}],"subject":[],"published":{"date-parts":[[2026]]},"assertion":[{"value":"1 May 2026","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"ESORICS","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"European Symposium on Research in Computer Security","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Toulouse","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"France","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2025","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"22 September 2025","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"26 September 2025","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"30","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"esorics2025","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"https:\/\/www.esorics2025.org\/","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}}]}}