{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,6]],"date-time":"2026-05-06T13:07:42Z","timestamp":1778072862759,"version":"3.51.4"},"publisher-location":"New York, NY, USA","reference-count":32,"publisher":"ACM","license":[{"start":{"date-parts":[[2020,10,30]],"date-time":"2020-10-30T00:00:00Z","timestamp":1604016000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2020,10,30]]},"DOI":"10.1145\/3372297.3417880","type":"proceedings-article","created":{"date-parts":[[2020,11,2]],"date-time":"2020-11-02T18:27:04Z","timestamp":1604341624000},"page":"363-375","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":51,"title":["Analyzing Information Leakage of Updates to Natural Language Models"],"prefix":"10.1145","author":[{"given":"Santiago","family":"Zanella-B\u00e9guelin","sequence":"first","affiliation":[{"name":"Microsoft, Cambridge, United Kingdom"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Lukas","family":"Wutschitz","sequence":"additional","affiliation":[{"name":"Microsoft, Cambridge, United Kingdom"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Shruti","family":"Tople","sequence":"additional","affiliation":[{"name":"Microsoft, Cambridge, United Kingdom"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Victor","family":"R\u00fchle","sequence":"additional","affiliation":[{"name":"Microsoft, Cambridge, United Kingdom"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Andrew","family":"Paverd","sequence":"additional","affiliation":[{"name":"Microsoft, Cambridge, United Kingdom"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Olga","family":"Ohrimenko","sequence":"additional","affiliation":[{"name":"University of Melbourne, Melbourne, VIC, Australia"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Boris","family":"K\u00f6pf","sequence":"additional","affiliation":[{"name":"Microsoft, Cambridge, United Kingdom"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Marc","family":"Brockschmidt","sequence":"additional","affiliation":[{"name":"Microsoft, Cambridge, United Kingdom"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2020,11,2]]},"reference":[{"key":"e_1_3_2_2_1_1","volume-title":"Deep Learning with Differential Privacy. In 23rd ACM SIGSAC Conference on Computer and Communications Security, CCS","author":"Abadi Martin","year":"2016"},{"key":"e_1_3_2_2_2_1","unstructured":"Galen Andrew Steve Chien and Nicolas Papernot. 2020. TensorFlow Privacy. https:\/\/github.com\/tensorflow\/privacy.  Galen Andrew Steve Chien and Nicolas Papernot. 2020. TensorFlow Privacy. https:\/\/github.com\/tensorflow\/privacy."},{"key":"e_1_3_2_2_3_1","unstructured":"Arm. 2020. TrustZone Technology. https:\/\/developer.arm.com\/ip-products\/security-ip\/trustzone  Arm. 2020. TrustZone Technology. https:\/\/developer.arm.com\/ip-products\/security-ip\/trustzone"},{"key":"e_1_3_2_2_4_1","volume-title":"Private Empirical Risk Minimization: Efficient Algorithms and Tight Error Bounds. In 55th IEEE Annual Symposium on Foundations of Computer Science, FOCS","author":"Bassily Raef","year":"2014"},{"key":"e_1_3_2_2_5_1","volume-title":"Machine Unlearning. In 42nd IEEE Symposium on Security and Privacy, S&P","author":"Bourtoule Lucas","year":"2021"},{"key":"e_1_3_2_2_6_1","volume-title":"The Secret Sharer: Evaluating and Testing Unintended Memorization in Neural Networks. In 28th USENIX Security Symposium. USENIX Association, 267--284","author":"Carlini Nicholas","year":"2019"},{"key":"e_1_3_2_2_7_1","volume-title":"Leakage-Abuse Attacks Against Searchable Encryption. In 22nd ACM SIGSAC Conference on Computer and Communications Security, CCS","author":"Cash David","year":"2015"},{"key":"e_1_3_2_2_8_1","volume-title":"When Machine Unlearning Jeopardizes Privacy. arxiv","author":"Chen Min","year":"2005"},{"key":"e_1_3_2_2_9_1","volume-title":"BERT: Pre-training of Deep Bidirectional Transformers for Language Understanding. In 2019 Conference of the North American","author":"Devlin Jacob","year":"2019"},{"key":"e_1_3_2_2_10_1","volume-title":"ICS","author":"Dwork Cynthia","year":"2010"},{"key":"e_1_3_2_2_11_1","first-page":"3","article-title":"The Algorithmic Foundations of Differential Privacy","volume":"9","author":"Dwork Cynthia","year":"2014","journal-title":"Foundations and Trends in Theoretical Computer Science"},{"key":"e_1_3_2_2_12_1","doi-asserted-by":"publisher","DOI":"10.1145\/2810103.2813677"},{"key":"e_1_3_2_2_13_1","volume-title":"Privacy in Pharmacogenetics: An End-to-End Case Study of Personalized Warfarin Dosing. In 23rd USENIX Security Symposium. USENIX Association, 17--32","author":"Fredrikson Matthew","year":"2014"},{"key":"e_1_3_2_2_14_1","volume-title":"Advances in Neural Information Processing Systems 32, NeurIPS","author":"Ginart Antonio","year":"2019"},{"key":"e_1_3_2_2_15_1","volume-title":"Eternal Sunshine of the Spotless Net: Selective Forgetting in Deep Networks. In IEEE\/CVF Conference on Computer Vision and Pattern Recognition, CVPR","author":"Golatkar Aditya","year":"2020"},{"key":"e_1_3_2_2_16_1","volume-title":"37th International Conference on Machine Learning, ICML","author":"Guo Chuan","year":"2020"},{"key":"e_1_3_2_2_17_1","doi-asserted-by":"publisher","DOI":"10.1162\/neco.1997.9.8.1735"},{"key":"e_1_3_2_2_18_1","unstructured":"Intel. 2020. Software Guard Extensions (SGX). https:\/\/software.intel.com\/en-us\/sgx  Intel. 2020. Software Guard Extensions (SGX). https:\/\/software.intel.com\/en-us\/sgx"},{"key":"e_1_3_2_2_19_1","doi-asserted-by":"publisher","DOI":"10.1016\/B978-1-55860-377-6.50048-7"},{"key":"e_1_3_2_2_20_1","doi-asserted-by":"publisher","DOI":"10.5555\/972470.972475"},{"key":"e_1_3_2_2_21_1","volume-title":"Learning Differentially Private Recurrent Language Models. In 6th International Conference on Learning Representations, ICLR","author":"McMahan H. Brendan","year":"2018"},{"key":"e_1_3_2_2_22_1","volume-title":"Pointer Sentinel Mixture Models. In 5th International Conference on Learning Representations, ICLR","author":"Merity Stephen","year":"2017"},{"key":"e_1_3_2_2_24_1","volume-title":"2019 a. Updates-Leak: Data Set Inference and Reconstruction Attacks in Online Learning. arxiv","author":"Salem Ahmed","year":"1904"},{"key":"e_1_3_2_2_25_1","volume-title":"ML-Leaks: Model and Data Independent Membership Inference Attacks and Defenses on Machine Learning Models. In 26th Annual Network and Distributed System Security Symposium, NDSS","author":"Salem Ahmed","year":"2019"},{"key":"e_1_3_2_2_26_1","volume-title":"Membership Inference Attacks Against Machine Learning Models. In 38th IEEE Symposium on Security and Privacy, S&P","author":"Shokri Reza","year":"2017"},{"key":"e_1_3_2_2_27_1","doi-asserted-by":"publisher","DOI":"10.1145\/3292500.3330885"},{"key":"e_1_3_2_2_28_1","volume-title":"Stochastic Gradient Descent with Differentially Private Updates. In 1st IEEE Global Conference on Signal and Information Processing, GlobalSIP","author":"Song S.","year":"2013"},{"key":"e_1_3_2_2_29_1","unstructured":"European Union. 2016. Regulation (EU) 2016\/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data and repealing Directive 95\/46\/EC (General Data Protection Regulation).  European Union. 2016. Regulation (EU) 2016\/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data and repealing Directive 95\/46\/EC (General Data Protection Regulation)."},{"key":"e_1_3_2_2_30_1","volume-title":"NIPS","author":"Vaswani Ashish","year":"2017"},{"key":"e_1_3_2_2_31_1","volume-title":"Diverse Beam Search for Improved Description of Complex Scenes. In 32nd AAAI Conference on Artificial Intelligence, AAAI","author":"Vijayakumar Ashwin K.","year":"2018"},{"key":"e_1_3_2_2_32_1","doi-asserted-by":"publisher","DOI":"10.1109\/CSF.2018.00027"},{"key":"e_1_3_2_2_33_1","unstructured":"Wojciech Zaremba Ilya Sutskever and Oriol Vinyals. 2014. Recurrent Neural Network Regularization. arxiv: 1409.2329 [cs.NE]  Wojciech Zaremba Ilya Sutskever and Oriol Vinyals. 2014. Recurrent Neural Network Regularization. arxiv: 1409.2329 [cs.NE]"}],"event":{"name":"CCS '20: 2020 ACM SIGSAC Conference on Computer and Communications Security","location":"Virtual Event USA","acronym":"CCS '20","sponsor":["SIGSAC ACM Special Interest Group on Security, Audit, and Control"]},"container-title":["Proceedings of the 2020 ACM SIGSAC Conference on Computer and Communications Security"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3372297.3417880","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3372297.3417880","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,17]],"date-time":"2025-06-17T22:01:31Z","timestamp":1750197691000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3372297.3417880"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2020,10,30]]},"references-count":32,"alternative-id":["10.1145\/3372297.3417880","10.1145\/3372297"],"URL":"https:\/\/doi.org\/10.1145\/3372297.3417880","relation":{},"subject":[],"published":{"date-parts":[[2020,10,30]]},"assertion":[{"value":"2020-11-02","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}