{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,2]],"date-time":"2026-06-02T22:32:57Z","timestamp":1780439577784,"version":"3.54.1"},"publisher-location":"New York, NY, USA","reference-count":58,"publisher":"ACM","license":[{"start":{"date-parts":[[2016,10,24]],"date-time":"2016-10-24T00:00:00Z","timestamp":1477267200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by-nc-nd\/4.0\/"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2016,10,24]]},"DOI":"10.1145\/2976749.2978318","type":"proceedings-article","created":{"date-parts":[[2016,10,25]],"date-time":"2016-10-25T12:46:35Z","timestamp":1477399595000},"page":"308-318","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":4377,"title":["Deep Learning with Differential Privacy"],"prefix":"10.1145","author":[{"given":"Martin","family":"Abadi","sequence":"first","affiliation":[{"name":"Google, Mountain View, CA, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Andy","family":"Chu","sequence":"additional","affiliation":[{"name":"Google, Mountain View, CA, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Ian","family":"Goodfellow","sequence":"additional","affiliation":[{"name":"Open AI, San Francisco, CA, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"H. Brendan","family":"McMahan","sequence":"additional","affiliation":[{"name":"Google, Mountain View, CA, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Ilya","family":"Mironov","sequence":"additional","affiliation":[{"name":"Google, Mountain View, CA, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Kunal","family":"Talwar","sequence":"additional","affiliation":[{"name":"Google, Mountain View, CA, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Li","family":"Zhang","sequence":"additional","affiliation":[{"name":"Google, Mountain View, CA, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2016,10,24]]},"reference":[{"key":"e_1_3_2_1_1_1","unstructured":"CIFAR-10 and CIFAR-100 datasets. www.cs.toronto.edu\/~kriz\/cifar.html.  CIFAR-10 and CIFAR-100 datasets. www.cs.toronto.edu\/~kriz\/cifar.html."},{"key":"e_1_3_2_1_2_1","unstructured":"TensorFlow convolutional neural networks tutorial. www.tensor ow.org\/tutorials\/deepcnn.  TensorFlow convolutional neural networks tutorial. www.tensor ow.org\/tutorials\/deepcnn."},{"key":"e_1_3_2_1_3_1","volume-title":"Large-scale machine learning on heterogeneous systems","year":"2015","unstructured":"TensorFlow : Large-scale machine learning on heterogeneous systems , 2015 . Software available from tensorflow.org. TensorFlow: Large-scale machine learning on heterogeneous systems, 2015. Software available from tensorflow.org."},{"key":"e_1_3_2_1_4_1","doi-asserted-by":"publisher","DOI":"10.1145\/2976749.2978318"},{"key":"e_1_3_2_1_5_1","first-page":"901","volume-title":"VLDB","author":"Aggarwal C. C.","year":"2005","unstructured":"C. C. Aggarwal . On k-anonymity and the curse of dimensionality . In VLDB , pages 901 -- 909 , 2005 . C. C. Aggarwal. On k-anonymity and the curse of dimensionality. In VLDB, pages 901--909, 2005."},{"key":"e_1_3_2_1_6_1","doi-asserted-by":"publisher","DOI":"10.1145\/342009.335438"},{"key":"e_1_3_2_1_7_1","doi-asserted-by":"publisher","DOI":"10.1145\/2897518.2897566"},{"key":"e_1_3_2_1_8_1","doi-asserted-by":"publisher","DOI":"10.1109\/FOCS.2014.56"},{"key":"e_1_3_2_1_9_1","doi-asserted-by":"publisher","DOI":"10.1007\/s10994-013-5404-1"},{"key":"e_1_3_2_1_10_1","doi-asserted-by":"publisher","DOI":"10.1145\/1401890.1401904"},{"key":"e_1_3_2_1_11_1","volume-title":"Concentrated di erential privacy: Simpli cations, extensions, and lower bounds. CoRR, abs\/1605.02065","author":"Bun M.","year":"2016","unstructured":"M. Bun and T. Steinke . Concentrated di erential privacy: Simpli cations, extensions, and lower bounds. CoRR, abs\/1605.02065 , 2016 . M. Bun and T. Steinke. Concentrated di erential privacy: Simpli cations, extensions, and lower bounds. CoRR, abs\/1605.02065, 2016."},{"key":"e_1_3_2_1_12_1","doi-asserted-by":"publisher","DOI":"10.5555\/1953048.2021036"},{"key":"e_1_3_2_1_13_1","volume-title":"NIPS Workshop, number EPFL-CONF-192376","author":"Collobert R.","year":"2011","unstructured":"R. Collobert , K. Kavukcuoglu , and C. Farabet . Torch7: A Matlab-like environment for machine learning. In BigLearn , NIPS Workshop, number EPFL-CONF-192376 , 2011 . R. Collobert, K. Kavukcuoglu, and C. Farabet. Torch7: A Matlab-like environment for machine learning. In BigLearn, NIPS Workshop, number EPFL-CONF-192376, 2011."},{"key":"e_1_3_2_1_14_1","doi-asserted-by":"publisher","DOI":"10.1109\/FG.2011.5771385"},{"key":"e_1_3_2_1_15_1","doi-asserted-by":"publisher","DOI":"10.1038\/nature16961"},{"key":"e_1_3_2_1_16_1","volume-title":"Toward deeper understanding of neural networks: The power of initialization and a dual view on expressivity. CoRR, abs\/1602.05897","author":"Daniely A.","year":"2016","unstructured":"A. Daniely , R. Frostig , and Y. Singer . Toward deeper understanding of neural networks: The power of initialization and a dual view on expressivity. CoRR, abs\/1602.05897 , 2016 . A. Daniely, R. Frostig, and Y. Singer. Toward deeper understanding of neural networks: The power of initialization and a dual view on expressivity. CoRR, abs\/1602.05897, 2016."},{"key":"e_1_3_2_1_17_1","doi-asserted-by":"publisher","DOI":"10.5555\/1953048.2021068"},{"key":"e_1_3_2_1_18_1","doi-asserted-by":"publisher","DOI":"10.1145\/1866739.1866758"},{"key":"e_1_3_2_1_19_1","doi-asserted-by":"publisher","DOI":"10.1007\/11761679_29"},{"key":"e_1_3_2_1_20_1","doi-asserted-by":"publisher","DOI":"10.1145\/1536414.1536466"},{"key":"e_1_3_2_1_21_1","doi-asserted-by":"publisher","DOI":"10.1007\/11681878_14"},{"key":"e_1_3_2_1_22_1","doi-asserted-by":"publisher","DOI":"10.1561\/0400000042"},{"key":"e_1_3_2_1_23_1","volume-title":"Concentrated differential privacy. CoRR, abs\/1603.01887","author":"Dwork C.","year":"2016","unstructured":"C. Dwork and G. N. Rothblum . Concentrated differential privacy. CoRR, abs\/1603.01887 , 2016 . C. Dwork and G. N. Rothblum. Concentrated differential privacy. CoRR, abs\/1603.01887, 2016."},{"key":"e_1_3_2_1_24_1","doi-asserted-by":"publisher","DOI":"10.1109\/FOCS.2010.12"},{"key":"e_1_3_2_1_25_1","doi-asserted-by":"publisher","DOI":"10.1145\/2591796.2591883"},{"key":"e_1_3_2_1_26_1","doi-asserted-by":"publisher","DOI":"10.1145\/2810103.2813677"},{"key":"e_1_3_2_1_27_1","volume-title":"Efficient per-example gradient computations. CoRR, abs\/1510.01799v2","author":"Goodfellow I.","year":"2015","unstructured":"I. Goodfellow . Efficient per-example gradient computations. CoRR, abs\/1510.01799v2 , 2015 . I. Goodfellow. Efficient per-example gradient computations. CoRR, abs\/1510.01799v2, 2015."},{"key":"e_1_3_2_1_28_1","volume-title":"Fractional max-pooling. CoRR, abs\/1412.6071","author":"Graham B.","year":"2014","unstructured":"B. Graham . Fractional max-pooling. CoRR, abs\/1412.6071 , 2014 . B. Graham. Fractional max-pooling. CoRR, abs\/1412.6071, 2014."},{"key":"e_1_3_2_1_29_1","doi-asserted-by":"publisher","DOI":"10.5555\/1873601.1873691"},{"key":"e_1_3_2_1_30_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2015.123"},{"key":"e_1_3_2_1_31_1","doi-asserted-by":"publisher","DOI":"10.1002\/(SICI)1097-024X(199606)26:6%3C635::AID-SPE26%3E3.0.CO;2-P"},{"key":"e_1_3_2_1_32_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2009.5459469"},{"key":"e_1_3_2_1_33_1","first-page":"315","volume-title":"NIPS","author":"Johnson R.","year":"2013","unstructured":"R. Johnson and T. Zhang . Accelerating stochastic gradient descent using predictive variance reduction . In NIPS , pages 315 -- 323 , 2013 . R. Johnson and T. Zhang. Accelerating stochastic gradient descent using predictive variance reduction. In NIPS, pages 315--323, 2013."},{"key":"e_1_3_2_1_34_1","first-page":"1376","volume-title":"ICML","author":"Kairouz P.","year":"2015","unstructured":"P. Kairouz , S. Oh , and P. Viswanath . The composition theorem for di erential privacy . In ICML , pages 1376 -- 1385 . ACM, 2015 . P. Kairouz, S. Oh, and P. Viswanath. The composition theorem for di erential privacy. In ICML, pages 1376--1385. ACM, 2015."},{"key":"e_1_3_2_1_35_1","doi-asserted-by":"publisher","DOI":"10.1137\/090756090"},{"key":"e_1_3_2_1_36_1","first-page":"25.1","volume-title":"COLT","author":"Kifer D.","year":"2012","unstructured":"D. Kifer , A. D. Smith , and A. Thakurta . Private convex optimization for empirical risk minimization with applications to high-dimensional regression . In COLT , pages 25.1 -- 25.40 , 2012 . D. Kifer, A. D. Smith, and A. Thakurta. Private convex optimization for empirical risk minimization with applications to high-dimensional regression. In COLT, pages 25.1--25.40, 2012."},{"key":"e_1_3_2_1_37_1","first-page":"1097","volume-title":"NIPS","author":"Krizhevsky A.","year":"2012","unstructured":"A. Krizhevsky , I. Sutskever , and G. E. Hinton . ImageNet classification with deep convolutional neural networks . In NIPS , pages 1097 -- 1105 , 2012 . A. Krizhevsky, I. Sutskever, and G. E. Hinton. ImageNet classification with deep convolutional neural networks. In NIPS, pages 1097--1105, 2012."},{"key":"e_1_3_2_1_38_1","doi-asserted-by":"publisher","DOI":"10.1109\/5.726791"},{"key":"e_1_3_2_1_39_1","doi-asserted-by":"publisher","DOI":"10.5555\/646765.704129"},{"key":"e_1_3_2_1_40_1","volume-title":"ICLR","author":"Maddison C. J.","year":"2015","unstructured":"C. J. Maddison , A. Huang , I. Sutskever , and D. Silver . Move evaluation in Go using deep convolutional neural networks . In ICLR , 2015 . C. J. Maddison, A. Huang, I. Sutskever, and D. Silver. Move evaluation in Go using deep convolutional neural networks. In ICLR, 2015."},{"key":"e_1_3_2_1_41_1","doi-asserted-by":"publisher","DOI":"10.1145\/1557019.1557090"},{"key":"e_1_3_2_1_42_1","doi-asserted-by":"publisher","DOI":"10.1145\/1559845.1559850"},{"key":"e_1_3_2_1_43_1","volume-title":"Efficient estimation of word representations in vector space. CoRR, abs\/1301.3781","author":"Mikolov T.","year":"2013","unstructured":"T. Mikolov , K. Chen , G. Corrado , and J. Dean . Efficient estimation of word representations in vector space. CoRR, abs\/1301.3781 , 2013 . T. Mikolov, K. Chen, G. Corrado, and J. Dean. Efficient estimation of word representations in vector space. CoRR, abs\/1301.3781, 2013."},{"key":"e_1_3_2_1_44_1","volume-title":"Renyi differential privacy. Private communication","author":"Mironov I.","year":"2016","unstructured":"I. Mironov . Renyi differential privacy. Private communication , 2016 . I. Mironov. Renyi differential privacy. Private communication, 2016."},{"key":"e_1_3_2_1_45_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-1-4419-8853-9"},{"key":"e_1_3_2_1_46_1","doi-asserted-by":"publisher","DOI":"10.3115\/v1\/D14-1162"},{"key":"e_1_3_2_1_47_1","first-page":"1309","volume-title":"AAAI","author":"Phan N.","year":"2016","unstructured":"N. Phan , Y. Wang , X. Wu , and D. Dou . Di erential privacy preservation for deep auto-encoders: an application of human behavior prediction . In AAAI , pages 1309 -- 1316 , 2016 . N. Phan, Y. Wang, X. Wu, and D. Dou. Di erential privacy preservation for deep auto-encoders: an application of human behavior prediction. In AAAI, pages 1309--1316, 2016."},{"key":"e_1_3_2_1_48_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPRW.2011.5981788"},{"key":"e_1_3_2_1_49_1","volume-title":"Privacy odometers and lters: Pay-as-you-go composition. CoRR, abs\/1605.08294","author":"Rogers R. M.","year":"2016","unstructured":"R. M. Rogers , A. Roth , J. Ullman , and S. P. Vadhan . Privacy odometers and lters: Pay-as-you-go composition. CoRR, abs\/1605.08294 , 2016 . R. M. Rogers, A. Roth, J. Ullman, and S. P. Vadhan. Privacy odometers and lters: Pay-as-you-go composition. CoRR, abs\/1605.08294, 2016."},{"key":"e_1_3_2_1_50_1","doi-asserted-by":"publisher","DOI":"10.1038\/323533a0"},{"key":"e_1_3_2_1_51_1","first-page":"1089","volume-title":"ICML","author":"Saxe A.","year":"2011","unstructured":"A. Saxe , P. W. Koh , Z. Chen , M. Bhand , B. Suresh , and A. Ng . On random weights and unsupervised feature learning . In ICML , pages 1089 -- 1096 . ACM, 2011 . A. Saxe, P. W. Koh, Z. Chen, M. Bhand, B. Suresh, and A. Ng. On random weights and unsupervised feature learning. In ICML, pages 1089--1096. ACM, 2011."},{"key":"e_1_3_2_1_52_1","doi-asserted-by":"publisher","DOI":"10.1145\/2810103.2813687"},{"key":"e_1_3_2_1_53_1","doi-asserted-by":"publisher","DOI":"10.1109\/GlobalSIP.2013.6736861"},{"key":"e_1_3_2_1_54_1","doi-asserted-by":"publisher","DOI":"10.1142\/S0218488502001648"},{"key":"e_1_3_2_1_55_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2015.7298594"},{"key":"e_1_3_2_1_56_1","volume-title":"Large scale kernel learning using block coordinate descent. CoRR, abs\/1602.05310","author":"Tu S.","year":"2016","unstructured":"S. Tu , R. Roelofs , S. Venkataraman , and B. Recht . Large scale kernel learning using block coordinate descent. CoRR, abs\/1602.05310 , 2016 . S. Tu, R. Roelofs, S. Venkataraman, and B. Recht. Large scale kernel learning using block coordinate descent. CoRR, abs\/1602.05310, 2016."},{"key":"e_1_3_2_1_57_1","first-page":"2773","volume-title":"NIPS","author":"Vinyals O.","year":"2015","unstructured":"O. Vinyals , L. Kaiser , T. Koo , S. Petrov , I. Sutskever , and G. E. Hinton . Grammar as a foreign language . In NIPS , pages 2773 -- 2781 , 2015 . O. Vinyals, L. Kaiser, T. Koo, S. Petrov, I. Sutskever, and G. E. Hinton. Grammar as a foreign language. In NIPS, pages 2773--2781, 2015."},{"key":"e_1_3_2_1_58_1","volume-title":"Di erentially private stochastic gradient descent for in-RDBMS analytics. CoRR, abs\/1606.04722","author":"Wu X.","year":"2016","unstructured":"X. Wu , A. Kumar , K. Chaudhuri , S. Jha , and J. F. Naughton . Di erentially private stochastic gradient descent for in-RDBMS analytics. CoRR, abs\/1606.04722 , 2016 . X. Wu, A. Kumar, K. Chaudhuri, S. Jha, and J. F. Naughton. Di erentially private stochastic gradient descent for in-RDBMS analytics. CoRR, abs\/1606.04722, 2016."}],"event":{"name":"CCS'16: 2016 ACM SIGSAC Conference on Computer and Communications Security","location":"Vienna Austria","acronym":"CCS'16","sponsor":["SIGSAC ACM Special Interest Group on Security, Audit, and Control"]},"container-title":["Proceedings of the 2016 ACM SIGSAC Conference on Computer and Communications Security"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/2976749.2978318","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/2976749.2978318","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,18]],"date-time":"2025-06-18T04:56:17Z","timestamp":1750222577000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/2976749.2978318"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2016,10,24]]},"references-count":58,"alternative-id":["10.1145\/2976749.2978318","10.1145\/2976749"],"URL":"https:\/\/doi.org\/10.1145\/2976749.2978318","relation":{},"subject":[],"published":{"date-parts":[[2016,10,24]]},"assertion":[{"value":"2016-10-24","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}