{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,8,1]],"date-time":"2026-08-01T16:49:11Z","timestamp":1785602951545,"version":"3.56.0"},"reference-count":82,"publisher":"IEEE","license":[{"start":{"date-parts":[[2023,5,1]],"date-time":"2023-05-01T00:00:00Z","timestamp":1682899200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-009"},{"start":{"date-parts":[[2023,5,1]],"date-time":"2023-05-01T00:00:00Z","timestamp":1682899200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-001"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2023,5]]},"DOI":"10.1109\/sp46215.2023.10179422","type":"proceedings-article","created":{"date-parts":[[2023,7,21]],"date-time":"2023-07-21T17:18:15Z","timestamp":1689959895000},"page":"1926-1943","source":"Crossref","is-referenced-by-count":32,"title":["Private, Efficient, and Accurate: Protecting Models Trained by Multi-party Learning with Differential Privacy"],"prefix":"10.1109","author":[{"given":"Wenqiang","family":"Ruan","sequence":"first","affiliation":[{"name":"Fudan University,Laboratory of Data Analytics and Security"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Mingxin","family":"Xu","sequence":"additional","affiliation":[{"name":"Fudan University,Laboratory of Data Analytics and Security"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Wenjing","family":"Fang","sequence":"additional","affiliation":[{"name":"Ant Group"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Li","family":"Wang","sequence":"additional","affiliation":[{"name":"Ant Group"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Lei","family":"Wang","sequence":"additional","affiliation":[{"name":"Ant Group"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Weili","family":"Han","sequence":"additional","affiliation":[{"name":"Fudan University,Laboratory of Data Analytics and Security"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"263","reference":[{"key":"ref1","doi-asserted-by":"publisher","DOI":"10.1145\/2976749.2978318"},{"key":"ref2","doi-asserted-by":"publisher","DOI":"10.1109\/FOCS.2014.56"},{"key":"ref3","doi-asserted-by":"publisher","DOI":"10.1145\/62212.62213"},{"key":"ref4","first-page":"2147","article-title":"Secure multi-party computation of differentially private median","volume-title":"29th USENIX Security Symposium (USENIX Security 20)","author":"B\u00f6hler"},{"key":"ref5","article-title":"On the opportunities and risks of foundation models","author":"Bommasani","year":"2021"},{"key":"ref6","article-title":"Deep learning with gaussian differential privacy","volume-title":"Harvard Data Science Review","volume":"9","author":"Bu","year":"2020"},{"key":"ref7","doi-asserted-by":"publisher","DOI":"10.1145\/3460120.3484557"},{"key":"ref8","doi-asserted-by":"publisher","DOI":"10.29012\/jpc.784"},{"key":"ref9","doi-asserted-by":"publisher","DOI":"10.1109\/ICComm.2018.8484794"},{"key":"ref10","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-15317-4_13"},{"key":"ref11","article-title":"Private collaborative neural network learning","author":"Chase","year":"2017","journal-title":"Cryptology"},{"issue":"3","key":"ref12","article-title":"Differentially private empirical risk minimization","volume":"12","author":"Chaudhuri","year":"2011","journal-title":"Journal of Machine Learning Research"},{"key":"ref13","article-title":"Decision transformer: Reinforcement learning via sequence modeling","volume":"34","author":"Chen","year":"2021","journal-title":"Advances in neural information processing systems"},{"key":"ref14","first-page":"1597","article-title":"A simple framework for contrastive learning of visual representations","volume-title":"Proceedings of the 37th International Conference on Machine Learning, volume 119 of Proceedings of Machine Learning Research","author":"Chen"},{"key":"ref15","article-title":"Ca{pc} learning: Confidential and private collaborative learning","volume-title":"International Conference on Learning Representations","author":"Choquette-Choo"},{"key":"ref16","doi-asserted-by":"publisher","DOI":"10.1017\/CBO9781107337756"},{"key":"ref17","article-title":"Private machine learning in tensorflow using secure computation","author":"Dahl","year":"2018","journal-title":"CoRR"},{"key":"ref18","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2005.177"},{"key":"ref19","first-page":"2183","article-title":"Fantastic four: Honest-majority four-party secure computation with malicious security","volume-title":"30th USENIX Security Symposium (USENIX Security 21)","author":"Dalskov"},{"key":"ref20","first-page":"27","article-title":"Quality assessment of wikipedia articles without feature engineering","volume-title":"Proceedings of the 16th ACM\/IEEE-CS on Joint Conference on Digital Libraries","author":"Dang"},{"key":"ref21","author":"Devlin","year":"2018","journal-title":"BERT: pre-training of deep bidirectional transformers for language understanding"},{"key":"ref22","doi-asserted-by":"publisher","DOI":"10.1007\/11761679_29"},{"key":"ref23","doi-asserted-by":"publisher","DOI":"10.1561\/0400000042"},{"key":"ref24","doi-asserted-by":"publisher","DOI":"10.1145\/2810103.2813677"},{"key":"ref25","first-page":"218","article-title":"How to play any mental game or A completeness theorem for protocols with honest majority","volume-title":"Proceedings of the 19th Annual ACM Symposium on Theory of Computing","author":"Goldreich"},{"key":"ref26","volume-title":"Deep learning","author":"Goodfellow","year":"2016"},{"key":"ref27","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.90"},{"key":"ref28","doi-asserted-by":"publisher","DOI":"10.1145\/3133956.3134030"},{"key":"ref29","article-title":"Cheetah: Lean and fast secure Two-Party deep neural network inference","volume-title":"31st USENIX Security Symposium (USENIX Security 22)","author":"Huang"},{"key":"ref30","doi-asserted-by":"publisher","DOI":"10.1145\/3372297.3417269"},{"key":"ref31","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2019.00001"},{"key":"ref32","article-title":"Auditing differentially private machine learning: How private is private sgd?","volume-title":"Advances in Neural Information Processing Systems 33: Annual Conference on Neural Information Processing Systems 2020, NeurIPS 2020, December 6-12, 2020, virtual","author":"Jagielski"},{"key":"ref33","doi-asserted-by":"publisher","DOI":"10.1109\/SP46214.2022.9833644"},{"key":"ref34","doi-asserted-by":"publisher","DOI":"10.1145\/3319535.3363201"},{"key":"ref35","doi-asserted-by":"publisher","DOI":"10.1038\/s41586-021-03819-2"},{"key":"ref36","first-page":"5201","article-title":"The distributed discrete gaussian mechanism for federated learning with secure aggregation","volume-title":"International Conference on Machine Learning","author":"Kairouz"},{"key":"ref37","doi-asserted-by":"publisher","DOI":"10.1137\/090756090"},{"key":"ref38","article-title":"Crypten: Secure multi-party computation meets machine learning","author":"Knott","year":"2021","journal-title":"NeurIPS"},{"key":"ref39","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2013.102"},{"key":"ref40","article-title":"Learning multiple layers of features from tiny images","volume-title":"Technical Report 0","author":"Krizhevsky","year":"2009"},{"key":"ref41","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-24861-0_18"},{"key":"ref42","doi-asserted-by":"publisher","DOI":"10.1109\/5.726791"},{"key":"ref43","doi-asserted-by":"publisher","DOI":"10.1145\/3422337.3447836"},{"key":"ref44","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-57048-8_6"},{"key":"ref45","doi-asserted-by":"publisher","DOI":"10.1145\/3411501.3419427"},{"key":"ref46","doi-asserted-by":"publisher","DOI":"10.5555\/2002472.2002491"},{"key":"ref47","first-page":"1273","article-title":"Communication-efficient learning of deep networks from decentralized data","volume-title":"Artificial intelligence and statistics","author":"McMahan","year":"2017"},{"key":"ref48","doi-asserted-by":"publisher","DOI":"10.1145\/1559845.1559850"},{"key":"ref49","doi-asserted-by":"publisher","DOI":"10.1145\/2382196.2382264"},{"key":"ref50","doi-asserted-by":"publisher","DOI":"10.1109\/CSF.2017.11"},{"key":"ref51","doi-asserted-by":"publisher","DOI":"10.1145\/3243734.3243760"},{"key":"ref52","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.12"},{"key":"ref53","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2013.30"},{"key":"ref54","article-title":"Prediction poisoning: Towards defenses against dnn model stealing attacks","volume-title":"International Conference on Learning Representations","author":"Orekondy"},{"key":"ref55","article-title":"Semi-supervised knowledge transfer for deep learning from private training data","volume-title":"International Conference on Learning Representations","author":"Papernot"},{"key":"ref56","author":"Papernot","year":"2020","journal-title":"Making the shoe fit: Architectures, initializations, and tuning for learning with privacy"},{"key":"ref57","doi-asserted-by":"publisher","DOI":"10.1145\/2818000.2818027"},{"key":"ref58","article-title":"C5t5: Controllable generation of organic molecules with transformers","author":"Rothchild","year":"2021"},{"key":"ref59","doi-asserted-by":"publisher","DOI":"10.1145\/3318464.3380596"},{"key":"ref60","doi-asserted-by":"publisher","DOI":"10.1109\/MSEC.2021.3078218"},{"key":"ref61","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.41"},{"key":"ref62","article-title":"Very deep convolutional networks for large-scale image recognition","volume-title":"3rd International Conference on Learning Representations, ICLR 2015, San Diego, CA, USA, May 7-9, 2015, Conference Track Proceedings","author":"Simonyan"},{"key":"ref63","article-title":"Sok: Training machine learning models over multiple sources with privacy preservation","author":"Song","year":"2020"},{"key":"ref64","doi-asserted-by":"publisher","DOI":"10.1109\/GlobalSIP.2013.6736861"},{"key":"ref65","doi-asserted-by":"publisher","DOI":"10.1109\/SP40001.2021.00098"},{"key":"ref66","article-title":"Differentially private learning needs better features (or much more data)","volume-title":"International Conference on Learning Representations","author":"Tramer"},{"key":"ref67","doi-asserted-by":"publisher","DOI":"10.5555\/3241094.3241142"},{"key":"ref68","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-57959-7"},{"key":"ref69","doi-asserted-by":"publisher","DOI":"10.1145\/3418290"},{"key":"ref70","doi-asserted-by":"publisher","DOI":"10.2478\/popets-2021-0011"},{"key":"ref71","doi-asserted-by":"publisher","DOI":"10.1145\/3035918.3064047"},{"key":"ref72","doi-asserted-by":"publisher","DOI":"10.1109\/SP40000.2020.00088"},{"key":"ref73","doi-asserted-by":"publisher","DOI":"10.1109\/SP40001.2021.00034"},{"key":"ref74","doi-asserted-by":"publisher","DOI":"10.1145\/3298981"},{"key":"ref75","article-title":"Defending model inversion and membership inference attacks via prediction purification","author":"Yang","year":"2020"},{"key":"ref76","doi-asserted-by":"publisher","DOI":"10.1109\/SFCS.1982.38"},{"key":"ref77","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-12229-8_2"},{"key":"ref78","doi-asserted-by":"publisher","DOI":"10.1145\/3225058.3225069"},{"key":"ref79","article-title":"Opacus: User-friendly differential privacy library in pytorch","author":"Yousefpour","year":"2021","journal-title":"CoRR"},{"key":"ref80","doi-asserted-by":"publisher","DOI":"10.29012\/jpc.880"},{"key":"ref81","article-title":"Do not let privacy overbill utility: Gradient embedding perturbation for private learning","volume-title":"9th International Conference on Learning Representations, ICLR 2021","author":"Yu"},{"key":"ref82","doi-asserted-by":"publisher","DOI":"10.1109\/EuroSP51992.2021.00022"}],"event":{"name":"2023 IEEE Symposium on Security and Privacy (SP)","location":"San Francisco, CA, USA","start":{"date-parts":[[2023,5,21]]},"end":{"date-parts":[[2023,5,25]]}},"container-title":["2023 IEEE Symposium on Security and Privacy (SP)"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx7\/10179215\/10179280\/10179422.pdf?arnumber=10179422","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2024,7,20]],"date-time":"2024-07-20T05:14:33Z","timestamp":1721452473000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/10179422\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2023,5]]},"references-count":82,"URL":"https:\/\/doi.org\/10.1109\/sp46215.2023.10179422","relation":{},"subject":[],"published":{"date-parts":[[2023,5]]}}}