{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,8,28]],"date-time":"2026-08-28T11:04:48Z","timestamp":1787915088158,"version":"build-2784847793"},"reference-count":181,"publisher":"Association for Computing Machinery (ACM)","issue":"2","license":[{"start":{"date-parts":[[2021,3,5]],"date-time":"2021-03-05T00:00:00Z","timestamp":1614902400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"DOI":"10.13039\/501100000923","name":"Australian Research Council","doi-asserted-by":"publisher","award":["LP180101150"],"award-info":[{"award-number":["LP180101150"]}],"id":[{"id":"10.13039\/501100000923","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["ACM Comput. Surv."],"published-print":{"date-parts":[[2022,3,31]]},"abstract":"<jats:p>The newly emerged machine learning (e.g., deep learning) methods have become a strong driving force to revolutionize a wide range of industries, such as smart healthcare, financial technology, and surveillance systems. Meanwhile, privacy has emerged as a big concern in this machine learning-based artificial intelligence era. It is important to note that the problem of privacy preservation in the context of machine learning is quite different from that in traditional data privacy protection, as machine learning can act as both friend and foe. Currently, the work on the preservation of privacy and machine learning are still in an infancy stage, as most existing solutions only focus on privacy problems during the machine learning process. Therefore, a comprehensive study on the privacy preservation problems and machine learning is required. This article surveys the state of the art in privacy issues and solutions for machine learning. The survey covers three categories of interactions between privacy and machine learning: (i) private machine learning, (ii) machine learning-aided privacy protection, and (iii) machine learning-based privacy attack and corresponding protection schemes. The current research progress in each category is reviewed and the key challenges are identified. Finally, based on our in-depth analysis of the area of privacy and machine learning, we point out future research directions in this field.<\/jats:p>","DOI":"10.1145\/3436755","type":"journal-article","created":{"date-parts":[[2021,3,6]],"date-time":"2021-03-06T04:09:57Z","timestamp":1615003797000},"page":"1-36","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":427,"title":["When Machine Learning Meets Privacy"],"prefix":"10.1145","volume":"54","author":[{"given":"Bo","family":"Liu","sequence":"first","affiliation":[{"name":"University of Technology Sydney, Broadway, Ultimo NSW, Australia"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Ming","family":"Ding","sequence":"additional","affiliation":[{"name":"Data61, CSIRO, Eveleigh NSW, Australia"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Sina","family":"Shaham","sequence":"additional","affiliation":[{"name":"The University of Sydney, Camperdown NSW, Australia"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Wenny","family":"Rahayu","sequence":"additional","affiliation":[{"name":"La Trobe University, Bundoora VIC, Australia"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Farhad","family":"Farokhi","sequence":"additional","affiliation":[{"name":"The University of Melbourne, Parkville VIC, Australia"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Zihuai","family":"Lin","sequence":"additional","affiliation":[{"name":"The University of Sydney, Camperdown NSW, Australia"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2021,3,5]]},"reference":[{"key":"e_1_2_1_1_1","doi-asserted-by":"publisher","DOI":"10.1109\/CSF.2017.10"},{"key":"e_1_2_1_2_1","doi-asserted-by":"publisher","DOI":"10.1145\/2976749.2978318"},{"key":"e_1_2_1_3_1","volume-title":"Privacy and human behavior in the age of information. Science 347, 6221","author":"Acquisti Alessandro","year":"2015","unstructured":"Alessandro Acquisti , Laura Brandimarte , and George Loewenstein . 2015. Privacy and human behavior in the age of information. Science 347, 6221 ( 2015 ), 509--514. DOI:https:\/\/doi.org\/10.1126\/science.aaa1465 10.1126\/science.aaa1465 Alessandro Acquisti, Laura Brandimarte, and George Loewenstein. 2015. Privacy and human behavior in the age of information. Science 347, 6221 (2015), 509--514. DOI:https:\/\/doi.org\/10.1126\/science.aaa1465"},{"key":"e_1_2_1_4_1","doi-asserted-by":"publisher","DOI":"10.1109\/TKDE.2018.2855136"},{"key":"e_1_2_1_5_1","doi-asserted-by":"publisher","DOI":"10.5555\/1083592.1083696"},{"key":"e_1_2_1_6_1","volume-title":"International Conference on Database Theory. Springer, 246--258","author":"Aggarwal Gagan","year":"2005","unstructured":"Gagan Aggarwal , Tom\u00e1s Feder , Krishnaram Kenthapadi , Rajeev Motwani , Rina Panigrahy , Dilys Thomas , and An Zhu . 2005 . Anonymizing tables . In International Conference on Database Theory. Springer, 246--258 . Gagan Aggarwal, Tom\u00e1s Feder, Krishnaram Kenthapadi, Rajeev Motwani, Rina Panigrahy, Dilys Thomas, and An Zhu. 2005. Anonymizing tables. In International Conference on Database Theory. Springer, 246--258."},{"key":"e_1_2_1_7_1","doi-asserted-by":"publisher","DOI":"10.1145\/342009.335438"},{"key":"e_1_2_1_8_1","doi-asserted-by":"publisher","DOI":"10.1504\/IJSN.2015.071829"},{"key":"e_1_2_1_9_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICSE.2015.61"},{"key":"e_1_2_1_10_1","volume-title":"Pattern Recognition and Machine Learning (Information Science and Statistics)","author":"Bishop Christopher M.","unstructured":"Christopher M. Bishop . 2006. Pattern Recognition and Machine Learning (Information Science and Statistics) . Springer-Verlag , Secaucus, NJ . Christopher M. Bishop. 2006. Pattern Recognition and Machine Learning (Information Science and Statistics). Springer-Verlag, Secaucus, NJ."},{"key":"e_1_2_1_11_1","doi-asserted-by":"publisher","DOI":"10.21437\/Interspeech.2017-1420"},{"key":"e_1_2_1_12_1","doi-asserted-by":"publisher","DOI":"10.1145\/3133956.3133982"},{"key":"e_1_2_1_13_1","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2015.23241"},{"key":"e_1_2_1_14_1","volume-title":"Proceedings of the 20th International Conference on Artificial Intelligence and Statistics (AISTATS\u201917)","author":"McMahan H. Brendan","year":"2017","unstructured":"H. Brendan McMahan , Eider Moore , Daniel Ramage , Seth Hampson , and Blaise Ag\u00fcera y Arcas . 2017 . Communication-efficient learning of deep networks from decentralized data . In Proceedings of the 20th International Conference on Artificial Intelligence and Statistics (AISTATS\u201917) . H. Brendan McMahan, Eider Moore, Daniel Ramage, Seth Hampson, and Blaise Ag\u00fcera y Arcas. 2017. Communication-efficient learning of deep networks from decentralized data. In Proceedings of the 20th International Conference on Artificial Intelligence and Statistics (AISTATS\u201917)."},{"key":"e_1_2_1_15_1","doi-asserted-by":"publisher","DOI":"10.1145\/1315245.1315307"},{"key":"e_1_2_1_16_1","doi-asserted-by":"publisher","DOI":"10.1145\/1315245.1315306"},{"key":"e_1_2_1_17_1","volume-title":"Public perceptions of privacy and security","author":"Pew Research Center","year":"2014","unstructured":"Pew Research Center . 2014. Public perceptions of privacy and security . Pew Research Center ( 2014 ). Retrieved from http:\/\/www.pewinternet.org\/2014\/11\/12\/public-privacy-perceptions\/. Pew Research Center. 2014. Public perceptions of privacy and security. Pew Research Center (2014). Retrieved from http:\/\/www.pewinternet.org\/2014\/11\/12\/public-privacy-perceptions\/."},{"key":"e_1_2_1_18_1","volume-title":"Sarwate","author":"Chaudhuri Kamalika","year":"2011","unstructured":"Kamalika Chaudhuri , Claire Monteleoni , and Anand D . Sarwate . 2011 . Differentially private empirical risk minimization. J. Mach. Learn. Res. 12 (Mar .2011), 1069--1109. Kamalika Chaudhuri, Claire Monteleoni, and Anand D. Sarwate. 2011. Differentially private empirical risk minimization. J. Mach. Learn. Res. 12 (Mar.2011), 1069--1109."},{"key":"e_1_2_1_19_1","doi-asserted-by":"publisher","DOI":"10.1145\/3128572.3140448"},{"key":"e_1_2_1_20_1","doi-asserted-by":"publisher","DOI":"10.1145\/1871437.1871535"},{"key":"e_1_2_1_21_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICIP.2018.8451239"},{"key":"e_1_2_1_22_1","doi-asserted-by":"publisher","DOI":"10.1145\/2020408.2020579"},{"key":"e_1_2_1_23_1","volume-title":"Proceedings of the Machine Learning for Healthcare Conference","author":"Choi Edward","year":"2017","unstructured":"Edward Choi , Siddharth Biswal , Bradley Malin , Jon Duke , Walter F. Stewart , and Jimeng Sun . 2017 . Generating multi-label discrete patient records using generative adversarial networks . Proceedings of the Machine Learning for Healthcare Conference (2017). Retrieved from http:\/\/proceedings.mlr.press\/v68\/choi17a.html http:\/\/arxiv.org\/abs\/1703.06490. Edward Choi, Siddharth Biswal, Bradley Malin, Jon Duke, Walter F. Stewart, and Jimeng Sun. 2017. Generating multi-label discrete patient records using generative adversarial networks. Proceedings of the Machine Learning for Healthcare Conference (2017). Retrieved from http:\/\/proceedings.mlr.press\/v68\/choi17a.html http:\/\/arxiv.org\/abs\/1703.06490."},{"key":"e_1_2_1_24_1","doi-asserted-by":"publisher","DOI":"10.1109\/STAST.2011.6059256"},{"key":"e_1_2_1_25_1","volume-title":"Proceedings of the ACM Conference on Computer and Communications Security (CCS\u201912)","author":"Costante Elisa","year":"2012","unstructured":"Elisa Costante , Yuanhao Sun , Milan Petkovic , and Jerry Den Hartog . 2012 . A machine learning solution to assess privacy policy completeness (short paper) . In Proceedings of the ACM Conference on Computer and Communications Security (CCS\u201912) . 91--96. DOI:https:\/\/doi.org\/10.1145\/2381966.2381979 10.1145\/2381966.2381979 Elisa Costante, Yuanhao Sun, Milan Petkovic, and Jerry Den Hartog. 2012. A machine learning solution to assess privacy policy completeness (short paper). In Proceedings of the ACM Conference on Computer and Communications Security (CCS\u201912). 91--96. DOI:https:\/\/doi.org\/10.1145\/2381966.2381979"},{"key":"e_1_2_1_26_1","doi-asserted-by":"publisher","DOI":"10.1109\/MPRV.2018.03367733"},{"key":"e_1_2_1_27_1","volume-title":"Proceedings of the Conference on Advances in Neural Information Processing Systems (NIPS\u201915)","author":"Denton Emily","year":"2015","unstructured":"Emily Denton , Soumith Chintala , Arthur Szlam , and Rob Fergus . 2015 . Deep generative image models using a laplacian pyramid of adversarial networks . In Proceedings of the Conference on Advances in Neural Information Processing Systems (NIPS\u201915) . 1486--1494. Emily Denton, Soumith Chintala, Arthur Szlam, and Rob Fergus. 2015. Deep generative image models using a laplacian pyramid of adversarial networks. In Proceedings of the Conference on Advances in Neural Information Processing Systems (NIPS\u201915). 1486--1494."},{"key":"e_1_2_1_28_1","unstructured":"Hadi M. Dolatabadi Sarah Erfani and Christopher Leckie. 2020. AdvFlow: Inconspicuous black-box adversarial attacks using normalizing flows. Retrieved from https:\/\/arXiv:2007.07435.  Hadi M. Dolatabadi Sarah Erfani and Christopher Leckie. 2020. AdvFlow: Inconspicuous black-box adversarial attacks using normalizing flows. Retrieved from https:\/\/arXiv:2007.07435."},{"key":"e_1_2_1_29_1","volume-title":"Proceedings of the 33rd International Conference on Machine Learning (ICML\u201916)","volume":"1","author":"Dowlin Nathan","year":"2016","unstructured":"Nathan Dowlin , Ran Gilad-Bachrach , Kim Laine , Kristin Lauter , Michael Naehrig , and John Wernsing . 2016 . Cryptonets: Applying neural networks to encrypted data with high throughput and accuracy . In Proceedings of the 33rd International Conference on Machine Learning (ICML\u201916) , Vol. 1 . 342--351. Nathan Dowlin, Ran Gilad-Bachrach, Kim Laine, Kristin Lauter, Michael Naehrig, and John Wernsing. 2016. Cryptonets: Applying neural networks to encrypted data with high throughput and accuracy. In Proceedings of the 33rd International Conference on Machine Learning (ICML\u201916), Vol. 1. 342--351."},{"key":"e_1_2_1_30_1","series-title":"SIAM Proceedings Series. 222--233. DOI:https:\/\/doi.org\/10.1137\/1.9781611972740.21","volume-title":"Privacy-preserving multivariate statistical analysis: Linear regression and classification","author":"Du Wenliang","unstructured":"Wenliang Du , Yunghsiang S. Han , and Shigang Chen . 2004. Privacy-preserving multivariate statistical analysis: Linear regression and classification . In SIAM Proceedings Series. 222--233. DOI:https:\/\/doi.org\/10.1137\/1.9781611972740.21 10.1137\/1.9781611972740.21 Wenliang Du, Yunghsiang S. Han, and Shigang Chen. 2004. Privacy-preserving multivariate statistical analysis: Linear regression and classification. In SIAM Proceedings Series. 222--233. DOI:https:\/\/doi.org\/10.1137\/1.9781611972740.21"},{"key":"e_1_2_1_31_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-540-79228-4_1"},{"key":"e_1_2_1_32_1","doi-asserted-by":"publisher","DOI":"10.1007\/11681878_14"},{"key":"e_1_2_1_33_1","first-page":"3","article-title":"The algorithmic foundations of differential privacy.Found","volume":"9","author":"Dwork Cynthia","year":"2014","unstructured":"Cynthia Dwork , Aaron Roth , et\u00a0al. 2014 . The algorithmic foundations of differential privacy.Found . Trends Theoret. Comput. Sci. 9 , 3 - 4 (2014), 211--407. Cynthia Dwork, Aaron Roth, et\u00a0al. 2014. The algorithmic foundations of differential privacy.Found. Trends Theoret. Comput. Sci. 9, 3-4 (2014), 211--407.","journal-title":"Trends Theoret. Comput. Sci."},{"key":"e_1_2_1_34_1","volume-title":"Proceedings of the Machine Learning for Healthcare Conference.","author":"Dwork C.","unstructured":"C. Dwork and V. Feldman Theory . 2018. Privacy-preserving prediction . In Proceedings of the Machine Learning for Healthcare Conference. Retrieved from http:\/\/proceedings.mlr.press\/v75\/dwork18a.html. C. Dwork and V. Feldman Theory. 2018. Privacy-preserving prediction. In Proceedings of the Machine Learning for Healthcare Conference. Retrieved from http:\/\/proceedings.mlr.press\/v75\/dwork18a.html."},{"key":"e_1_2_1_35_1","volume-title":"Proceedings of the Conference on Advances in Neural Information Processing Systems (NIPS\u201918)","author":"Elsayed Gamaleldin F","year":"2018","unstructured":"Gamaleldin F Elsayed , Nicolas Papernot , Shreya Shankar , Alexey Kurakin , Brian Cheung , Ian Goodfellow , and Jascha Sohl-Dickstein . 2018 . Adversarial examples that fool both computer vision and time-limited humans . In Proceedings of the Conference on Advances in Neural Information Processing Systems (NIPS\u201918) . 3910--3920. Gamaleldin F Elsayed, Nicolas Papernot, Shreya Shankar, Alexey Kurakin, Brian Cheung, Ian Goodfellow, and Jascha Sohl-Dickstein. 2018. Adversarial examples that fool both computer vision and time-limited humans. In Proceedings of the Conference on Advances in Neural Information Processing Systems (NIPS\u201918). 3910--3920."},{"key":"e_1_2_1_36_1","volume-title":"Proceedings of International Conference on Machine Learning (ICML\u201915)","author":"Fawzi Alhussein","year":"2015","unstructured":"Alhussein Fawzi , Omar Fawzi , and Pascal Frossard . 2015 . Fundamental limits on adversarial robustness . Proceedings of International Conference on Machine Learning (ICML\u201915) . 1--7. Alhussein Fawzi, Omar Fawzi, and Pascal Frossard. 2015. Fundamental limits on adversarial robustness. Proceedings of International Conference on Machine Learning (ICML\u201915). 1--7."},{"key":"e_1_2_1_37_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.chb.2014.11.083"},{"key":"e_1_2_1_38_1","doi-asserted-by":"publisher","DOI":"10.1145\/2810103.2813677"},{"key":"e_1_2_1_39_1","volume-title":"Proceedings of the 23rd USENIX Security Symposium (USENIX\u201914)","author":"Fredrikson Matthew","year":"2014","unstructured":"Matthew Fredrikson , Eric Lantz , Somesh Jha , Simon Lin , David Page , and Thomas Ristenpart . 2014 . Privacy in pharmacogenetics: An end-to-end case study of personalized warfarin dosing . In Proceedings of the 23rd USENIX Security Symposium (USENIX\u201914) . 17--32. Matthew Fredrikson, Eric Lantz, Somesh Jha, Simon Lin, David Page, and Thomas Ristenpart. 2014. Privacy in pharmacogenetics: An end-to-end case study of personalized warfarin dosing. In Proceedings of the 23rd USENIX Security Symposium (USENIX\u201914). 17--32."},{"key":"e_1_2_1_40_1","doi-asserted-by":"publisher","DOI":"10.1007\/s11257-016-9177-7"},{"key":"e_1_2_1_41_1","first-page":"19","volume-title":"Proceedings of the 57th Annual Meeting of the Association for Computational Linguistics (ACL\u201920)","author":"Friedrich Max","year":"2020","unstructured":"Max Friedrich , Arne K\u00f6hn , Gregor Wiedemann , and Chris Biemann . 2020 . Adversarial learning of privacy-preserving text representations for de-identification of medical records . In Proceedings of the 57th Annual Meeting of the Association for Computational Linguistics (ACL\u201920) . 5829--5839. DOI:https:\/\/doi.org\/10.18653\/v1\/p 19 - 1584 10.18653\/v1 Max Friedrich, Arne K\u00f6hn, Gregor Wiedemann, and Chris Biemann. 2020. Adversarial learning of privacy-preserving text representations for de-identification of medical records. In Proceedings of the 57th Annual Meeting of the Association for Computational Linguistics (ACL\u201920). 5829--5839. DOI:https:\/\/doi.org\/10.18653\/v1\/p19-1584"},{"key":"e_1_2_1_42_1","doi-asserted-by":"publisher","DOI":"10.1109\/INFOCOM.2019.8737510"},{"key":"e_1_2_1_43_1","doi-asserted-by":"publisher","DOI":"10.1109\/CSCloud.2016.52"},{"key":"e_1_2_1_44_1","unstructured":"Ian Goodfellow. 2018. Defense against the dark arts: An overview of adversarial example security research and future research directions. Retrieved from http:\/\/arxiv.org\/abs\/1806.04169.  Ian Goodfellow. 2018. Defense against the dark arts: An overview of adversarial example security research and future research directions. Retrieved from http:\/\/arxiv.org\/abs\/1806.04169."},{"key":"e_1_2_1_45_1","volume-title":"Proceedings of the Conference on Advances in Neural Information Processing Systems (NIPS\u201914)","volume":"3","author":"Goodfellow Ian J.","year":"2014","unstructured":"Ian J. Goodfellow , Jean Pouget-Abadie , Mehdi Mirza , Bing Xu , David Warde-Farley , Sherjil Ozair , Aaron Courville , and Yoshua Bengio . 2014 . Generative adversarial nets . In Proceedings of the Conference on Advances in Neural Information Processing Systems (NIPS\u201914) , Vol. 3 . 2672--2680. Ian J. Goodfellow, Jean Pouget-Abadie, Mehdi Mirza, Bing Xu, David Warde-Farley, Sherjil Ozair, Aaron Courville, and Yoshua Bengio. 2014. Generative adversarial nets. In Proceedings of the Conference on Advances in Neural Information Processing Systems (NIPS\u201914), Vol. 3. 2672--2680."},{"key":"e_1_2_1_46_1","doi-asserted-by":"publisher","DOI":"10.1145\/2568225.2568276"},{"key":"e_1_2_1_47_1","volume-title":"Proceedings of the International Conference on Information Security and Cryptology (ICISC\u201912)","author":"Graepel Thore","year":"2012","unstructured":"Thore Graepel , Kristin Lauter , and Michael Naehrig . 2012 . ML confidential: Machine learning on encrypted data . In Proceedings of the International Conference on Information Security and Cryptology (ICISC\u201912) . 1--21. Thore Graepel, Kristin Lauter, and Michael Naehrig. 2012. ML confidential: Machine learning on encrypted data. In Proceedings of the International Conference on Information Security and Cryptology (ICISC\u201912). 1--21."},{"key":"e_1_2_1_48_1","volume-title":"Proceedings of the 32nd International Conference on Machine Learning (ICML\u201915)","volume":"2","author":"Gregor Karol","year":"2015","unstructured":"Karol Gregor , Ivo Danihelka , Alex Graves , Danilo Jimenez Rezende , and Daan Wierstra . 2015 . DRAW: A recurrent neural network for image generation . In Proceedings of the 32nd International Conference on Machine Learning (ICML\u201915) , Vol. 2 . 1462--1471. Karol Gregor, Ivo Danihelka, Alex Graves, Danilo Jimenez Rezende, and Daan Wierstra. 2015. DRAW: A recurrent neural network for image generation. In Proceedings of the 32nd International Conference on Machine Learning (ICML\u201915), Vol. 2. 1462--1471."},{"key":"e_1_2_1_49_1","volume-title":"Badnets: Identifying vulnerabilities in the machine learning model supply chain.","author":"Gu Tianyu","year":"2017","unstructured":"Tianyu Gu , Brendan Dolan-Gavitt , and Siddharth Garg . 2017 . Badnets: Identifying vulnerabilities in the machine learning model supply chain. Retrieved from https:\/\/arXiv:1708.06733. Tianyu Gu, Brendan Dolan-Gavitt, and Siddharth Garg. 2017. Badnets: Identifying vulnerabilities in the machine learning model supply chain. Retrieved from https:\/\/arXiv:1708.06733."},{"key":"e_1_2_1_50_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICCCN.2016.7568598"},{"key":"e_1_2_1_51_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP40000.2020.00097"},{"key":"e_1_2_1_52_1","doi-asserted-by":"publisher","DOI":"10.2478\/popets-2019-0008"},{"key":"e_1_2_1_53_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.ijinfomgt.2016.08.002"},{"key":"e_1_2_1_54_1","volume-title":"Proceedings of the Conference on Privacy Enhancing Technologies (PETS\u201919)","author":"Hesamifard Ehsan","unstructured":"Ehsan Hesamifard , Hassan Takabi , Mehdi Ghasemi , and Rebecca N. Wright . 2018. Privacy-preserving machine learning as a service . In Proceedings of the Conference on Privacy Enhancing Technologies (PETS\u201919) . 123--142. Ehsan Hesamifard, Hassan Takabi, Mehdi Ghasemi, and Rebecca N. Wright. 2018. Privacy-preserving machine learning as a service. In Proceedings of the Conference on Privacy Enhancing Technologies (PETS\u201919). 123--142."},{"key":"e_1_2_1_55_1","doi-asserted-by":"publisher","DOI":"10.1145\/3133956.3134012"},{"key":"e_1_2_1_56_1","volume-title":"Proceedings of the Design Automation Conference (DAC\u201918)","volume":"1377","author":"Hua Weizhe","year":"1959","unstructured":"Weizhe Hua , Zhiru Zhang , and G. Edward Suh . 2018. Reverse engineering convolutional neural networks through side-channel information leaks . In Proceedings of the Design Automation Conference (DAC\u201918) , Vol. Part F 1377 . 1--6. DOI:https:\/\/doi.org\/10.1145\/3 1959 70.3196105 10.1145\/3195970.3196105 Weizhe Hua, Zhiru Zhang, and G. Edward Suh. 2018. Reverse engineering convolutional neural networks through side-channel information leaks. In Proceedings of the Design Automation Conference (DAC\u201918), Vol. Part F1377. 1--6. DOI:https:\/\/doi.org\/10.1145\/3195970.3196105"},{"key":"e_1_2_1_57_1","doi-asserted-by":"publisher","DOI":"10.24963\/ijcai.2019\/353"},{"key":"e_1_2_1_58_1","doi-asserted-by":"publisher","DOI":"10.4236\/jis.2013.42012"},{"key":"e_1_2_1_59_1","volume-title":"Proceedings of IEEE International Conference on Acoustics, Speech and Signal Processing (ICASSP\u201918)","author":"Imtia Hafiz","year":"2018","unstructured":"Hafiz Imtia and Anand D. Sarwate . 2018. Improved algorithms for differentially private orthogonal tensor decomposition . In Proceedings of IEEE International Conference on Acoustics, Speech and Signal Processing (ICASSP\u201918) . IEEE, 2201--2205. DOI:https:\/\/doi.org\/10.1109\/ICASSP. 2018 .8461303 10.1109\/ICASSP.2018.8461303 Hafiz Imtia and Anand D. Sarwate. 2018. Improved algorithms for differentially private orthogonal tensor decomposition. In Proceedings of IEEE International Conference on Acoustics, Speech and Signal Processing (ICASSP\u201918). IEEE, 2201--2205. DOI:https:\/\/doi.org\/10.1109\/ICASSP.2018.8461303"},{"key":"e_1_2_1_60_1","doi-asserted-by":"publisher","DOI":"10.1109\/JSTSP.2018.2877842"},{"key":"e_1_2_1_61_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2019.00001"},{"key":"e_1_2_1_62_1","volume-title":"Proceedings of the ACM International Conference on Knowledge Discovery and Data Mining (KDD\u201905)","author":"Jagannathan Geetha","year":"1870","unstructured":"Geetha Jagannathan and Rebecca N. Wright . 2005. Privacy-preserving distributed k-means clustering over arbitrarily partitioned data . In Proceedings of the ACM International Conference on Knowledge Discovery and Data Mining (KDD\u201905) . 593--599. DOI:https:\/\/doi.org\/10.1145\/108 1870 .1081942 10.1145\/1081870.1081942 Geetha Jagannathan and Rebecca N. Wright. 2005. Privacy-preserving distributed k-means clustering over arbitrarily partitioned data. In Proceedings of the ACM International Conference on Knowledge Discovery and Data Mining (KDD\u201905). 593--599. DOI:https:\/\/doi.org\/10.1145\/1081870.1081942"},{"key":"e_1_2_1_63_1","volume-title":"Proceedings of the International Conference on Pattern Recognition (ICPR\u201910)","author":"Jahanbekam Amirhossein","year":"2010","unstructured":"Amirhossein Jahanbekam , Christian Bauckhage , and Christian Thurau . 2010 . Age recognition in the wild . In Proceedings of the International Conference on Pattern Recognition (ICPR\u201910) . 392--395. DOI:https:\/\/doi.org\/10.1109\/ICPR.2010.104 10.1109\/ICPR.2010.104 Amirhossein Jahanbekam, Christian Bauckhage, and Christian Thurau. 2010. Age recognition in the wild. In Proceedings of the International Conference on Pattern Recognition (ICPR\u201910). 392--395. DOI:https:\/\/doi.org\/10.1109\/ICPR.2010.104"},{"key":"e_1_2_1_64_1","unstructured":"Zhanglong Ji Zachary C. Lipton and Charles Elkan. 2014. Differential privacy and machine learning: A survey and review. Retrieved from http:\/\/arxiv.org\/abs\/1412.7584.  Zhanglong Ji Zachary C. Lipton and Charles Elkan. 2014. Differential privacy and machine learning: A survey and review. Retrieved from http:\/\/arxiv.org\/abs\/1412.7584."},{"key":"e_1_2_1_65_1","volume-title":"Proceedings of the 27th USENIX Security Symposium (USENIX\u201918)","author":"Jia Jinyuan","year":"2018","unstructured":"Jinyuan Jia and Neil Zhenqiang Gong . 2018 . AttriGuard: A practical defense against attribute inference attacks via adversarial machine learning . In Proceedings of the 27th USENIX Security Symposium (USENIX\u201918) . 513--529. Jinyuan Jia and Neil Zhenqiang Gong. 2018. AttriGuard: A practical defense against attribute inference attacks via adversarial machine learning. In Proceedings of the 27th USENIX Security Symposium (USENIX\u201918). 513--529."},{"key":"e_1_2_1_66_1","doi-asserted-by":"publisher","DOI":"10.1109\/TPDS.2018.2809624"},{"key":"e_1_2_1_67_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2015.440"},{"key":"e_1_2_1_68_1","unstructured":"Peter Kairouz H. Brendan McMahan Brendan Avent Aur\u00e9lien Bellet Mehdi Bennis Arjun Nitin Bhagoji Keith Bonawitz Zachary Charles Graham Cormode Rachel Cummings Rafael G. L. D\u2019Oliveira Salim El Rouayheb David Evans Josh Gardner Zachary Garrett Adri\u00e0 Gasc\u00f3n Badih Ghazi Phillip B. Gibbons Marco Gruteser Zaid Harchaoui Chaoyang He Lie He Zhouyuan Huo Ben Hutchinson Justin Hsu Martin Jaggi Tara Javidi Gauri Joshi Mikhail Khodak Jakub Kone\u010dn\u00fd Aleksandra Korolova Farinaz Koushanfar Sanmi Koyejo Tancr\u00e8de Lepoint Yang Liu Prateek Mittal Mehryar Mohri Richard Nock Ayfer \u00d6zg\u00fcr Rasmus Pagh Mariana Raykova Hang Qi Daniel Ramage Ramesh Raskar Dawn Song Weikang Song Sebastian U. Stich Ziteng Sun Ananda Theertha Suresh Florian Tram\u00e8r Praneeth Vepakomma Jianyu Wang Li Xiong Zheng Xu Qiang Yang Felix X. Yu Han Yu and Sen Zhao. 2019. Advances and open problems in federated learning. Retrieved from http:\/\/arxiv.org\/abs\/1912.04977.  Peter Kairouz H. Brendan McMahan Brendan Avent Aur\u00e9lien Bellet Mehdi Bennis Arjun Nitin Bhagoji Keith Bonawitz Zachary Charles Graham Cormode Rachel Cummings Rafael G. L. D\u2019Oliveira Salim El Rouayheb David Evans Josh Gardner Zachary Garrett Adri\u00e0 Gasc\u00f3n Badih Ghazi Phillip B. Gibbons Marco Gruteser Zaid Harchaoui Chaoyang He Lie He Zhouyuan Huo Ben Hutchinson Justin Hsu Martin Jaggi Tara Javidi Gauri Joshi Mikhail Khodak Jakub Kone\u010dn\u00fd Aleksandra Korolova Farinaz Koushanfar Sanmi Koyejo Tancr\u00e8de Lepoint Yang Liu Prateek Mittal Mehryar Mohri Richard Nock Ayfer \u00d6zg\u00fcr Rasmus Pagh Mariana Raykova Hang Qi Daniel Ramage Ramesh Raskar Dawn Song Weikang Song Sebastian U. Stich Ziteng Sun Ananda Theertha Suresh Florian Tram\u00e8r Praneeth Vepakomma Jianyu Wang Li Xiong Zheng Xu Qiang Yang Felix X. Yu Han Yu and Sen Zhao. 2019. Advances and open problems in federated learning. Retrieved from http:\/\/arxiv.org\/abs\/1912.04977."},{"key":"e_1_2_1_69_1","volume-title":"Ananda Theertha Suresh, and Dave Bacon","author":"Kone\u010dn\u00fd Jakub","year":"2016","unstructured":"Jakub Kone\u010dn\u00fd , H. Brendan McMahan , Felix X. Yu , Peter Richt\u00e1rik , Ananda Theertha Suresh, and Dave Bacon . 2016 . Federated learning: Strategies for improving communication efficiency. Retrieved from http:\/\/arxiv.org\/abs\/1610.05492. Jakub Kone\u010dn\u00fd, H. Brendan McMahan, Felix X. Yu, Peter Richt\u00e1rik, Ananda Theertha Suresh, and Dave Bacon. 2016. Federated learning: Strategies for improving communication efficiency. Retrieved from http:\/\/arxiv.org\/abs\/1610.05492."},{"key":"e_1_2_1_70_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-540-72037-9_8"},{"key":"e_1_2_1_71_1","unstructured":"Vaibhav Kulkarni Natasa Tagasovska Thibault Vatter and Benoit Garbinato. 2018. Generative models for simulating mobility trajectories. Retrieved from http:\/\/arxiv.org\/abs\/1811.12801.  Vaibhav Kulkarni Natasa Tagasovska Thibault Vatter and Benoit Garbinato. 2018. Generative models for simulating mobility trajectories. Retrieved from http:\/\/arxiv.org\/abs\/1811.12801."},{"key":"e_1_2_1_72_1","volume-title":"Proceedings of the International Conference on Learning Representations (ICLR\u201919)","author":"Kurakin Alexey","year":"2019","unstructured":"Alexey Kurakin , Ian J. Goodfellow , and Samy Bengio . 2019 . Adversarial machine learning at scale . In Proceedings of the International Conference on Learning Representations (ICLR\u201919) . Alexey Kurakin, Ian J. Goodfellow, and Samy Bengio. 2019. Adversarial machine learning at scale. In Proceedings of the International Conference on Learning Representations (ICLR\u201919)."},{"key":"e_1_2_1_73_1","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/D18-1387"},{"key":"e_1_2_1_74_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2019.00044"},{"key":"e_1_2_1_75_1","doi-asserted-by":"publisher","DOI":"10.1109\/PERCOM.2017.7917874"},{"key":"e_1_2_1_76_1","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2016.2604383"},{"key":"e_1_2_1_77_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.future.2017.02.006"},{"key":"e_1_2_1_78_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPRW.2019.00013"},{"key":"e_1_2_1_79_1","volume-title":"Proceedings of the International Conference on Machine Learning (ICML\u201919)","author":"Li Yandong","year":"2019","unstructured":"Yandong Li , Lijun Li , Liqiang Wang , Tong Zhang , and Boqing Gong . 2019 . NATTACK: Learning the distributions of adversarial examples for an improved black-box attack on deep neural networks . In Proceedings of the International Conference on Machine Learning (ICML\u201919) . 3866--3876. Yandong Li, Lijun Li, Liqiang Wang, Tong Zhang, and Boqing Gong. 2019. NATTACK: Learning the distributions of adversarial examples for an improved black-box attack on deep neural networks. In Proceedings of the International Conference on Machine Learning (ICML\u201919). 3866--3876."},{"key":"e_1_2_1_80_1","volume-title":"Concurrency Computation","author":"Liu Bo","unstructured":"Bo Liu , Ming Ding , Tianqing Zhu , Yong Xiang , and Wanlei Zhou . 2019. Adversaries or allies? Privacy and deep learning in big data era . In Concurrency Computation , Vol. 31 . Wiley Online Library , e5102. DOI:https:\/\/doi.org\/10.1002\/cpe.5102 10.1002\/cpe.5102 Bo Liu, Ming Ding, Tianqing Zhu, Yong Xiang, and Wanlei Zhou. 2019. Adversaries or allies? Privacy and deep learning in big data era. In Concurrency Computation, Vol. 31. Wiley Online Library, e5102. DOI:https:\/\/doi.org\/10.1002\/cpe.5102"},{"key":"e_1_2_1_81_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-72359-4_43"},{"key":"e_1_2_1_82_1","doi-asserted-by":"publisher","DOI":"10.1109\/TVT.2016.2531185"},{"key":"e_1_2_1_83_1","volume-title":"Proceedings of IEEE International Conference on Computer Communications (INFOCOM\u201914)","author":"Liu Hao","year":"2014","unstructured":"Hao Liu , Yaoxue Zhang , Yuezhi Zhou , Di Zhang , Xiaoming Fu , and K. K. Ramakrishnan . 2014. Mining checkins from location-sharing services for client-independent IP geolocation . In Proceedings of IEEE International Conference on Computer Communications (INFOCOM\u201914) . 619--627. DOI:https:\/\/doi.org\/10.1109\/INFOCOM. 2014 .6847987 10.1109\/INFOCOM.2014.6847987 Hao Liu, Yaoxue Zhang, Yuezhi Zhou, Di Zhang, Xiaoming Fu, and K. K. Ramakrishnan. 2014. Mining checkins from location-sharing services for client-independent IP geolocation. In Proceedings of IEEE International Conference on Computer Communications (INFOCOM\u201914). 619--627. DOI:https:\/\/doi.org\/10.1109\/INFOCOM.2014.6847987"},{"key":"e_1_2_1_84_1","unstructured":"Kin Sum Liu Bo Li and Jie Gao. 2018. Generative model: Membership attack generalization and diversity. CoRR abs\/1805.09898.  Kin Sum Liu Bo Li and Jie Gao. 2018. Generative model: Membership attack generalization and diversity. CoRR abs\/1805.09898."},{"key":"e_1_2_1_85_1","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2018.2805680"},{"key":"e_1_2_1_86_1","volume-title":"Proceedings of the Location Privacy and Security Workshop. 1--7.","author":"Liu Xi","year":"2018","unstructured":"Xi Liu , Hanzhou Chen , and Clio Andris . 2018 . trajGANs: Using generative adversarial networks for geo-privacy protection of trajectory data (Vision paper) . In Proceedings of the Location Privacy and Security Workshop. 1--7. Xi Liu, Hanzhou Chen, and Clio Andris. 2018. trajGANs: Using generative adversarial networks for geo-privacy protection of trajectory data (Vision paper). In Proceedings of the Location Privacy and Security Workshop. 1--7."},{"key":"e_1_2_1_87_1","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2018.23291"},{"key":"e_1_2_1_88_1","volume-title":"Protecting privacy in shared photos via adversarial examples based stealth. Secur. Commun. Netw. 2017","author":"Liu Yujia","year":"2017","unstructured":"Yujia Liu , Weiming Zhang , and Nenghai Yu. 2017. Protecting privacy in shared photos via adversarial examples based stealth. Secur. Commun. Netw. 2017 ( 2017 ). DOI:https:\/\/doi.org\/10.1155\/2017\/1897438 10.1155\/2017 Yujia Liu, Weiming Zhang, and Nenghai Yu. 2017. Protecting privacy in shared photos via adversarial examples based stealth. Secur. Commun. Netw. 2017 (2017). DOI:https:\/\/doi.org\/10.1155\/2017\/1897438"},{"key":"e_1_2_1_89_1","unstructured":"Yunhui Long Vincent Bindschaedler Lei Wang Diyue Bu Xiaofeng Wang Haixu Tang Carl A. Gunter and Kai Chen. 2018. Understanding membership inferences on well-generalized learning models. Retrieved from http:\/\/arxiv.org\/abs\/1802.04889.  Yunhui Long Vincent Bindschaedler Lei Wang Diyue Bu Xiaofeng Wang Haixu Tang Carl A. Gunter and Kai Chen. 2018. Understanding membership inferences on well-generalized learning models. Retrieved from http:\/\/arxiv.org\/abs\/1802.04889."},{"key":"e_1_2_1_90_1","doi-asserted-by":"publisher","DOI":"10.1145\/1081870.1081950"},{"key":"e_1_2_1_91_1","doi-asserted-by":"publisher","DOI":"10.1145\/2528548"},{"key":"e_1_2_1_92_1","doi-asserted-by":"publisher","DOI":"10.1504\/IJKWI.2016.078712"},{"key":"e_1_2_1_93_1","doi-asserted-by":"publisher","DOI":"10.1037\/0022-3514.83.6.1456"},{"key":"e_1_2_1_94_1","first-page":"091118","article-title":"Federated learning of deep networks using model averaging","volume":"92","author":"McMahan H. Brendan","year":"2016","unstructured":"H. Brendan McMahan , Eider Moore , Daniel Ramage , Seth Hampson , and Blaise Ag\u00fcera y Arcas . 2016 . Federated learning of deep networks using model averaging . Arxiv 92 , 9 (2016), 091118 . DOI:https:\/\/doi.org\/10.1063\/1.2841713 10.1063\/1.2841713 H. Brendan McMahan, Eider Moore, Daniel Ramage, Seth Hampson, and Blaise Ag\u00fcera y Arcas. 2016. Federated learning of deep networks using model averaging. Arxiv 92, 9 (2016), 091118. DOI:https:\/\/doi.org\/10.1063\/1.2841713","journal-title":"Arxiv"},{"key":"e_1_2_1_95_1","volume-title":"Proceedings of the 6th International Conference on Learning Representations (ICLR\u201918)","volume":"45","author":"McMahan H. Brendan","year":"2018","unstructured":"H. Brendan McMahan , Daniel Ramage , Kunal Talwar , and Li Zhang . 2018 . Learning differentially private recurrent language models without lossing accuracy . In Proceedings of the 6th International Conference on Learning Representations (ICLR\u201918) , Vol. 45 . 39--44. DOI:https:\/\/doi.org\/10.1145\/585597.585599 10.1145\/585597.585599 H. Brendan McMahan, Daniel Ramage, Kunal Talwar, and Li Zhang. 2018. Learning differentially private recurrent language models without lossing accuracy. In Proceedings of the 6th International Conference on Learning Representations (ICLR\u201918), Vol. 45. 39--44. DOI:https:\/\/doi.org\/10.1145\/585597.585599"},{"key":"e_1_2_1_96_1","unstructured":"Richard McPherson Reza Shokri and Vitaly Shmatikov. 2016. Defeating image obfuscation with deep learning. Retrieved from https:\/\/arXiv:1609.00408.  Richard McPherson Reza Shokri and Vitaly Shmatikov. 2016. Defeating image obfuscation with deep learning. Retrieved from https:\/\/arXiv:1609.00408."},{"key":"e_1_2_1_97_1","doi-asserted-by":"publisher","DOI":"10.1109\/PAC.2017.15"},{"key":"e_1_2_1_98_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2019.00029"},{"key":"e_1_2_1_99_1","doi-asserted-by":"publisher","DOI":"10.1145\/2660267.2687258"},{"key":"e_1_2_1_100_1","doi-asserted-by":"publisher","DOI":"10.1109\/CSF.2017.11"},{"key":"e_1_2_1_101_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.12"},{"key":"e_1_2_1_102_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2017.17"},{"key":"e_1_2_1_103_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.282"},{"key":"e_1_2_1_104_1","unstructured":"Arvind Narayanan and Vitaly Shmatikov. 2006. How to break anonymity of the Netflix prize dataset. Retrieved from http:\/\/arxiv.org\/abs\/cs\/0610105.  Arvind Narayanan and Vitaly Shmatikov. 2006. How to break anonymity of the Netflix prize dataset. Retrieved from http:\/\/arxiv.org\/abs\/cs\/0610105."},{"key":"e_1_2_1_105_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2019.00065"},{"key":"e_1_2_1_106_1","unstructured":"Seth Neel Aaron Roth Giuseppe Vietri and Zhiwei Steven Wu. 2019. Oracle efficient private non-convex optimization. Retrieved from http:\/\/arxiv.org\/abs\/1909.01783.  Seth Neel Aaron Roth Giuseppe Vietri and Zhiwei Steven Wu. 2019. Oracle efficient private non-convex optimization. Retrieved from http:\/\/arxiv.org\/abs\/1909.01783."},{"key":"e_1_2_1_107_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2013.30"},{"key":"e_1_2_1_108_1","unstructured":"Ruair\u00ed Nugent. 2018. Assesing completeness of solvency and financial condition reports through the use of machine learning and text classification. (2018).  Ruair\u00ed Nugent. 2018. Assesing completeness of solvency and financial condition reports through the use of machine learning and text classification. (2018)."},{"key":"e_1_2_1_109_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-46487-9_2"},{"key":"e_1_2_1_110_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2017.165"},{"key":"e_1_2_1_111_1","volume-title":"Explainable AI: Interpreting, Explaining and Visualizing Deep Learning","author":"Oh Seong Joon","unstructured":"Seong Joon Oh , Bernt Schiele , and Mario Fritz . 2019. Towards reverse-engineering black-box neural networks . In Explainable AI: Interpreting, Explaining and Visualizing Deep Learning . Springer , 121--144. Seong Joon Oh, Bernt Schiele, and Mario Fritz. 2019. Towards reverse-engineering black-box neural networks. In Explainable AI: Interpreting, Explaining and Visualizing Deep Learning. Springer, 121--144."},{"key":"e_1_2_1_112_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.25"},{"key":"e_1_2_1_113_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2018.00883"},{"key":"e_1_2_1_114_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2017.398"},{"key":"e_1_2_1_115_1","doi-asserted-by":"publisher","DOI":"10.24963\/ijcai.2018\/530"},{"key":"e_1_2_1_116_1","volume-title":"Proceedings of the 5th International Conference on Learning Representations (ICLR\u201919)","author":"Papernot Nicolas","year":"2019","unstructured":"Nicolas Papernot , Ian Goodfellow , Mart\u00edn Abadi , Kunal Talwar , and \u00dalfar Erlingsson . 2019 . Semi-supervised knowledge transfer for deep learning from private training data . In Proceedings of the 5th International Conference on Learning Representations (ICLR\u201919) . Nicolas Papernot, Ian Goodfellow, Mart\u00edn Abadi, Kunal Talwar, and \u00dalfar Erlingsson. 2019. Semi-supervised knowledge transfer for deep learning from private training data. In Proceedings of the 5th International Conference on Learning Representations (ICLR\u201919)."},{"key":"e_1_2_1_117_1","unstructured":"Nicolas Papernot Patrick McDaniel and Ian Goodfellow. 2016. Transferability in machine learning: From phenomena to black-box attacks using adversarial samples. Retrieved from http:\/\/arxiv.org\/abs\/1605.07277.  Nicolas Papernot Patrick McDaniel and Ian Goodfellow. 2016. Transferability in machine learning: From phenomena to black-box attacks using adversarial samples. Retrieved from http:\/\/arxiv.org\/abs\/1605.07277."},{"key":"e_1_2_1_118_1","doi-asserted-by":"publisher","DOI":"10.1145\/3052973.3053009"},{"key":"e_1_2_1_119_1","doi-asserted-by":"publisher","DOI":"10.1109\/EuroSP.2016.36"},{"key":"e_1_2_1_120_1","doi-asserted-by":"publisher","DOI":"10.14778\/3231751.3231757"},{"key":"e_1_2_1_121_1","volume-title":"Proceedings of the Conference on Advances in Neural Information Processing Systems (NIPS\u201910)","author":"Pathak Manas A.","year":"2010","unstructured":"Manas A. Pathak , Shantanu Rane , and Bhiksha Raj . 2010 . Multiparty differential privacy via aggregation of locally trained classifiers . In Proceedings of the Conference on Advances in Neural Information Processing Systems (NIPS\u201910) . 1876--1884. Manas A. Pathak, Shantanu Rane, and Bhiksha Raj. 2010. Multiparty differential privacy via aggregation of locally trained classifiers. In Proceedings of the Conference on Advances in Neural Information Processing Systems (NIPS\u201910). 1876--1884."},{"key":"e_1_2_1_122_1","doi-asserted-by":"publisher","DOI":"10.1109\/CloudCom.2010.66"},{"key":"e_1_2_1_123_1","volume-title":"Proceedings of the 37th International Conference on Machine Learning (PMLR\u201920)","volume":"6","author":"Phan NhatHai","year":"2020","unstructured":"NhatHai Phan , My T. Thai , Han Hu , Ruoming Jin , Tong Sun , and Dejing Dou . 2020 . Scalable differential privacy with certified robustness in adversarial learning . In Proceedings of the 37th International Conference on Machine Learning (PMLR\u201920) , Vol. 6 . Retrieved from http:\/\/arxiv.org\/abs\/ 1903.09822. NhatHai Phan, My T. Thai, Han Hu, Ruoming Jin, Tong Sun, and Dejing Dou. 2020. Scalable differential privacy with certified robustness in adversarial learning. In Proceedings of the 37th International Conference on Machine Learning (PMLR\u201920), Vol. 6. Retrieved from http:\/\/arxiv.org\/abs\/1903.09822."},{"key":"e_1_2_1_124_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICDM.2017.48"},{"key":"e_1_2_1_125_1","volume-title":"Proceedings of International Joint Conference on Artificial Intelligence (IJCAI\u201919)","author":"Phan Nhat Hai","year":"2019","unstructured":"Nhat Hai Phan , Minh N. Vu , Yang Liu , Ruoming Jin , Dejing Dou , Xintao Wu , and My T. Thai . 2019. Heterogeneous Gaussian mechanism: Preserving differential privacy in deep learning with provable robustness . In Proceedings of International Joint Conference on Artificial Intelligence (IJCAI\u201919) . 4753--4759. DOI:https:\/\/doi.org\/10.24963\/ijcai. 2019 \/660arxiv:1906.01444 10.24963\/ijcai.2019 Nhat Hai Phan, Minh N. Vu, Yang Liu, Ruoming Jin, Dejing Dou, Xintao Wu, and My T. Thai. 2019. Heterogeneous Gaussian mechanism: Preserving differential privacy in deep learning with provable robustness. In Proceedings of International Joint Conference on Artificial Intelligence (IJCAI\u201919). 4753--4759. DOI:https:\/\/doi.org\/10.24963\/ijcai.2019\/660arxiv:1906.01444"},{"key":"e_1_2_1_126_1","doi-asserted-by":"publisher","DOI":"10.5555\/3196160.3196245"},{"key":"e_1_2_1_127_1","doi-asserted-by":"publisher","DOI":"10.1145\/772862.772865"},{"key":"e_1_2_1_128_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2018.00465"},{"key":"e_1_2_1_129_1","unstructured":"Shadi Rahimian Tribhuvanesh Orekondy and Mario Fritz. 2020. Sampling attacks: Amplification of membership inference attacks by repeated queries. Retrieved from http:\/\/arxiv.org\/abs\/2009.00395.  Shadi Rahimian Tribhuvanesh Orekondy and Mario Fritz. 2020. Sampling attacks: Amplification of membership inference attacks by repeated queries. Retrieved from http:\/\/arxiv.org\/abs\/2009.00395."},{"key":"e_1_2_1_130_1","doi-asserted-by":"publisher","DOI":"10.1145\/2660267.2660305"},{"key":"e_1_2_1_131_1","volume-title":"Proceedings of the IEEE Computer Society Conference on Computer Vision and Pattern Recognition Workshops (CVPW\u201916)","author":"Rozsa Andras","year":"2016","unstructured":"Andras Rozsa , Ethan M. Rudd , and Terrance E. Boult . 2016. Adversarial diversity and hard positive generation . In Proceedings of the IEEE Computer Society Conference on Computer Vision and Pattern Recognition Workshops (CVPW\u201916) . 410--417. DOI:https:\/\/doi.org\/10.1109\/CVPRW. 2016 .58 10.1109\/CVPRW.2016.58 Andras Rozsa, Ethan M. Rudd, and Terrance E. Boult. 2016. Adversarial diversity and hard positive generation. In Proceedings of the IEEE Computer Society Conference on Computer Vision and Pattern Recognition Workshops (CVPW\u201916). 410--417. DOI:https:\/\/doi.org\/10.1109\/CVPRW.2016.58"},{"key":"e_1_2_1_132_1","first-page":"65","article-title":"Learning in a Large Function Space","volume":"1","author":"Rubinstein Benjamin I. P.","year":"2012","unstructured":"Benjamin I. P. Rubinstein , Peter L. Bartlett , Ling Huang , and Nina Taft . 2012 . Learning in a Large Function Space : Privacy-Preserving Mechanisms for SVM Learning. Technical Report 1. 65 -- 100 . Retrieved from http:\/\/repository.cmu.edu\/jpc. Benjamin I. P. Rubinstein, Peter L. Bartlett, Ling Huang, and Nina Taft. 2012. Learning in a Large Function Space: Privacy-Preserving Mechanisms for SVM Learning. Technical Report 1. 65--100. Retrieved from http:\/\/repository.cmu.edu\/jpc.","journal-title":"Privacy-Preserving Mechanisms for SVM Learning. Technical Report"},{"key":"e_1_2_1_133_1","unstructured":"Ahmed Salem Rui Wen Michael Backes Shiqing Ma and Yang Zhang. 2020. Dynamic backdoor attacks against machine learning models. Retrieved from http:\/\/arxiv.org\/abs\/2003.03675.  Ahmed Salem Rui Wen Michael Backes Shiqing Ma and Yang Zhang. 2020. Dynamic backdoor attacks against machine learning models. Retrieved from http:\/\/arxiv.org\/abs\/2003.03675."},{"key":"e_1_2_1_134_1","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2019.23119"},{"key":"e_1_2_1_135_1","volume-title":"Proceedings of the ACM SIGKDD International Conference on Knowledge Discovery and Data Mining (KDD\u201904)","author":"Sanil Ashish P.","unstructured":"Ashish P. Sanil , Alan F. Karr , Xiaodong Lin , and Jerome P. Reiter . 2004. Privacy preserving regression modelling via distributed computation . In Proceedings of the ACM SIGKDD International Conference on Knowledge Discovery and Data Mining (KDD\u201904) . 677--682. DOI:https:\/\/doi.org\/10.1145\/1014052.1014139 10.1145\/1014052.1014139 Ashish P. Sanil, Alan F. Karr, Xiaodong Lin, and Jerome P. Reiter. 2004. Privacy preserving regression modelling via distributed computation. In Proceedings of the ACM SIGKDD International Conference on Knowledge Discovery and Data Mining (KDD\u201904). 677--682. DOI:https:\/\/doi.org\/10.1145\/1014052.1014139"},{"key":"e_1_2_1_136_1","first-page":"1","article-title":"Secure linear regression on vertically partitioned datasets","volume":"2016","author":"Schoppmann Phillipp","year":"2016","unstructured":"Phillipp Schoppmann , Borja Balle , Jack Doerner , Samee Zahur , and David Evans . 2016 . Secure linear regression on vertically partitioned datasets . IACR Cryptol. Eprint Arch. 2016 (2016), 1 -- 27 . Phillipp Schoppmann, Borja Balle, Jack Doerner, Samee Zahur, and David Evans. 2016. Secure linear regression on vertically partitioned datasets. IACR Cryptol. Eprint Arch. 2016 (2016), 1--27.","journal-title":"IACR Cryptol. Eprint Arch."},{"key":"e_1_2_1_137_1","doi-asserted-by":"publisher","DOI":"10.1145\/505282.505283"},{"key":"e_1_2_1_138_1","volume-title":"Proceedings of the ACM Conference on Computer and Communications Security (CCS\u201916)","author":"Sharif Mahmood","unstructured":"Mahmood Sharif , Sruti Bhagavatula , Lujo Bauer , and Michael K. Reiter . 2016. Accessorize to a crime: Real and stealthy attacks on state-of-the-art face recognition . In Proceedings of the ACM Conference on Computer and Communications Security (CCS\u201916) . 1528--1540. DOI:https:\/\/doi.org\/10.1145\/2976749.2978392 10.1145\/2976749.2978392 Mahmood Sharif, Sruti Bhagavatula, Lujo Bauer, and Michael K. Reiter. 2016. Accessorize to a crime: Real and stealthy attacks on state-of-the-art face recognition. In Proceedings of the ACM Conference on Computer and Communications Security (CCS\u201916). 1528--1540. DOI:https:\/\/doi.org\/10.1145\/2976749.2978392"},{"key":"e_1_2_1_139_1","doi-asserted-by":"publisher","DOI":"10.1109\/REW.2017.77"},{"key":"e_1_2_1_140_1","volume-title":"Proceedings of the ACM Conference on Computer and Communications Security (CCS\u201915)","author":"Shokri Reza","year":"2015","unstructured":"Reza Shokri and Vitaly Shmatikov . 2015 . Privacy-preserving deep learning . In Proceedings of the ACM Conference on Computer and Communications Security (CCS\u201915) . 1310--1321. Reza Shokri and Vitaly Shmatikov. 2015. Privacy-preserving deep learning. In Proceedings of the ACM Conference on Computer and Communications Security (CCS\u201915). 1310--1321."},{"key":"e_1_2_1_141_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.41"},{"key":"e_1_2_1_142_1","first-page":"266","article-title":"Hiding in the mobile crowd: Location privacy through collaboration","volume":"3","author":"Shokri Reza","year":"2014","unstructured":"Reza Shokri , George Theodorakopoulos , Panos Papadimitratos , Ehsan Kazemi , and Jean Pierre Hubaux . 2014 . Hiding in the mobile crowd: Location privacy through collaboration . IEEE Trans. Dependable Secure Comput. 3 (2014), 266 -- 279 . DOI:https:\/\/doi.org\/10.1109\/TDSC.2013.57 10.1109\/TDSC.2013.57 Reza Shokri, George Theodorakopoulos, Panos Papadimitratos, Ehsan Kazemi, and Jean Pierre Hubaux. 2014. Hiding in the mobile crowd: Location privacy through collaboration. IEEE Trans. Dependable Secure Comput.3 (2014), 266--279. DOI:https:\/\/doi.org\/10.1109\/TDSC.2013.57","journal-title":"IEEE Trans. Dependable Secure Comput."},{"key":"e_1_2_1_143_1","volume-title":"Proceedings of the IEEE International Conference on Data Mining (ICDM\u201907)","author":"Slavkovic Aleksandra B.","year":"2007","unstructured":"Aleksandra B. Slavkovic , Yuval Nardi , and Matthew M. Tibbits . 2007. Secure logistic regression of horizontally and vertically partitioned distributed databases . In Proceedings of the IEEE International Conference on Data Mining (ICDM\u201907) . 723--728. DOI:https:\/\/doi.org\/10.1109\/ICDMW. 2007 .114 10.1109\/ICDMW.2007.114 Aleksandra B. Slavkovic, Yuval Nardi, and Matthew M. Tibbits. 2007. Secure logistic regression of horizontally and vertically partitioned distributed databases. In Proceedings of the IEEE International Conference on Data Mining (ICDM\u201907). 723--728. DOI:https:\/\/doi.org\/10.1109\/ICDMW.2007.114"},{"key":"e_1_2_1_144_1","doi-asserted-by":"publisher","DOI":"10.1145\/3133956.3134077"},{"key":"e_1_2_1_145_1","volume-title":"Proceedings of the Conference on Advances in Neural Information Processing Systems (NIPS\u201918)","author":"Song Guocong","year":"2018","unstructured":"Guocong Song and Wei Chai . 2018 . Collaborative learning for deep neural networks . In Proceedings of the Conference on Advances in Neural Information Processing Systems (NIPS\u201918) . 1832--1841. Guocong Song and Wei Chai. 2018. Collaborative learning for deep neural networks. In Proceedings of the Conference on Advances in Neural Information Processing Systems (NIPS\u201918). 1832--1841."},{"key":"e_1_2_1_146_1","volume-title":"Proceedings of the IEEE Global Conference on Signal and Information Processing (GlobalSIP\u201913)","author":"Song Shuang","year":"2013","unstructured":"Shuang Song , Kamalika Chaudhuri , and Anand D. Sarwate . 2013. Stochastic gradient descent with differentially private updates . In Proceedings of the IEEE Global Conference on Signal and Information Processing (GlobalSIP\u201913) . 245--248. DOI:https:\/\/doi.org\/10.1109\/GlobalSIP. 2013 .6736861 10.1109\/GlobalSIP.2013.6736861 Shuang Song, Kamalika Chaudhuri, and Anand D. Sarwate. 2013. Stochastic gradient descent with differentially private updates. In Proceedings of the IEEE Global Conference on Signal and Information Processing (GlobalSIP\u201913). 245--248. DOI:https:\/\/doi.org\/10.1109\/GlobalSIP.2013.6736861"},{"key":"e_1_2_1_147_1","doi-asserted-by":"publisher","DOI":"10.1145\/2983644"},{"key":"e_1_2_1_148_1","doi-asserted-by":"publisher","DOI":"10.1145\/2631775.2631803"},{"key":"e_1_2_1_149_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2018.00530"},{"key":"e_1_2_1_150_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2017.54"},{"key":"e_1_2_1_151_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.neucom.2018.03.030"},{"key":"e_1_2_1_152_1","volume-title":"Proceedings of the International Conference on Learning Representations (ICLR\u201914)","author":"Szegedy Christian","year":"2014","unstructured":"Christian Szegedy , Wojciech Zaremba , Ilya Sutskever , Joan Bruna , Dumitru Erhan , Ian Goodfellow , and Rob Fergus . 2014 . Intriguing properties of neural networks . In Proceedings of the International Conference on Learning Representations (ICLR\u201914) . Christian Szegedy, Wojciech Zaremba, Ilya Sutskever, Joan Bruna, Dumitru Erhan, Ian Goodfellow, and Rob Fergus. 2014. Intriguing properties of neural networks. In Proceedings of the International Conference on Learning Representations (ICLR\u201914)."},{"key":"e_1_2_1_153_1","doi-asserted-by":"publisher","DOI":"10.1145\/3184558.3186969"},{"key":"e_1_2_1_154_1","volume-title":"Facebook privacy breach. Financial Times","author":"Times Financial","year":"2020","unstructured":"Financial Times . 2020. Facebook privacy breach. Financial Times ( 2020 ), 11--12. Retrieved from https:\/\/www.ft.com\/content\/87184c40-2cfe-11e8-9b4b-bc4b9f08f381. Financial Times. 2020. Facebook privacy breach. Financial Times (2020), 11--12. Retrieved from https:\/\/www.ft.com\/content\/87184c40-2cfe-11e8-9b4b-bc4b9f08f381."},{"key":"e_1_2_1_155_1","doi-asserted-by":"publisher","DOI":"10.5555\/3241094.3241142"},{"key":"e_1_2_1_156_1","volume-title":"Proceedings of the CEUR Workshop","volume":"2335","author":"Triastcyn Aleksei","year":"2019","unstructured":"Aleksei Triastcyn and Boi Faltings . 2019 . Generating artificial data for private deep learning . In Proceedings of the CEUR Workshop , Vol. 2335 . 33--40. Aleksei Triastcyn and Boi Faltings. 2019. Generating artificial data for private deep learning. In Proceedings of the CEUR Workshop, Vol. 2335. 33--40."},{"key":"e_1_2_1_157_1","doi-asserted-by":"publisher","DOI":"10.1007\/s00778-006-0041-y"},{"key":"e_1_2_1_158_1","unstructured":"Aaron van den Oord Sander Dieleman Heiga Zen Karen Simonyan Oriol Vinyals Alex Graves Nal Kalchbrenner Andrew Senior and Koray Kavukcuoglu. 2016. WaveNet: A generative model for raw audio. Retrieved from http:\/\/arxiv.org\/abs\/1609.03499.  Aaron van den Oord Sander Dieleman Heiga Zen Karen Simonyan Oriol Vinyals Alex Graves Nal Kalchbrenner Andrew Senior and Koray Kavukcuoglu. 2016. WaveNet: A generative model for raw audio. Retrieved from http:\/\/arxiv.org\/abs\/1609.03499."},{"key":"e_1_2_1_159_1","unstructured":"Praneeth Vepakomma Otkrist Gupta Tristan Swedish and Ramesh Raskar. 2018. Split learning for health: Distributed deep learning without sharing raw patient data. Retrieved from http:\/\/arxiv.org\/abs\/1812.00564.  Praneeth Vepakomma Otkrist Gupta Tristan Swedish and Ramesh Raskar. 2018. Split learning for health: Distributed deep learning without sharing raw patient data. Retrieved from http:\/\/arxiv.org\/abs\/1812.00564."},{"key":"e_1_2_1_160_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2015.7298935"},{"key":"e_1_2_1_161_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2018.00038"},{"key":"e_1_2_1_162_1","unstructured":"K. Wang R. Chen B. C. Fung and P. S. Yu. 2010. Privacy-preserving data publishing: A survey on recent developments. Comput. Surveys (2010).  K. Wang R. Chen B. C. Fung and P. S. Yu. 2010. Privacy-preserving data publishing: A survey on recent developments. Comput. Surveys (2010)."},{"key":"e_1_2_1_163_1","doi-asserted-by":"publisher","DOI":"10.1109\/INFOCOM.2019.8737416"},{"key":"e_1_2_1_164_1","doi-asserted-by":"publisher","DOI":"10.1145\/3274694.3274696"},{"key":"e_1_2_1_165_1","volume-title":"Proceedings of the 24th USENIX Security Symposium (USENIX\u201915)","author":"Wijesekera Primal","year":"2015","unstructured":"Primal Wijesekera , Arjun Baokar , Ashkan Hosseini , Serge Egelman , David Wagner , and Konstantin Beznosov . 2015 . Android permissions remystified: A field study on contextual integrity . In Proceedings of the 24th USENIX Security Symposium (USENIX\u201915) . 499--514. Primal Wijesekera, Arjun Baokar, Ashkan Hosseini, Serge Egelman, David Wagner, and Konstantin Beznosov. 2015. Android permissions remystified: A field study on contextual integrity. In Proceedings of the 24th USENIX Security Symposium (USENIX\u201915). 499--514."},{"key":"e_1_2_1_166_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.51"},{"key":"e_1_2_1_167_1","doi-asserted-by":"publisher","DOI":"10.1145\/3173574.3173842"},{"key":"e_1_2_1_168_1","doi-asserted-by":"publisher","DOI":"10.1109\/WACV.2016.7477452"},{"key":"e_1_2_1_169_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP40000.2020.00025"},{"key":"e_1_2_1_170_1","volume-title":"Proceedings of the 27th Annual Conference of the Japanese Society for Artificial Intelligence (JSAI\u201913)","author":"Wu Shuang","year":"2013","unstructured":"Shuang Wu , Tadanori Teruya , Junpei Kawamoto , Jun Sakuma , and Hiroaki Kikuchi . 2013 . Privacy-preservation for stochastic gradient descent application to secure logistic regression . In Proceedings of the 27th Annual Conference of the Japanese Society for Artificial Intelligence (JSAI\u201913) . 6--9. Shuang Wu, Tadanori Teruya, Junpei Kawamoto, Jun Sakuma, and Hiroaki Kikuchi. 2013. Privacy-preservation for stochastic gradient descent application to secure logistic regression. In Proceedings of the 27th Annual Conference of the Japanese Society for Artificial Intelligence (JSAI\u201913). 6--9."},{"key":"e_1_2_1_171_1","unstructured":"Lei Xu and Kalyan Veeramachaneni. 2018. Synthesizing tabular data using generative adversarial networks. Retrieved from http:\/\/arxiv.org\/abs\/1811.11264.  Lei Xu and Kalyan Veeramachaneni. 2018. Synthesizing tabular data using generative adversarial networks. Retrieved from http:\/\/arxiv.org\/abs\/1811.11264."},{"key":"e_1_2_1_172_1","volume-title":"Proceedings of the ACM Conference on Computer and Communications Security (CCS\u201919). 2041--2055","author":"Yao Yuanshun","year":"1953","unstructured":"Yuanshun Yao , Haitao Zheng , Huiying Li , and Ben Y. Zhao . 2019. Latent backdoor attacks on deep neural networks . In Proceedings of the ACM Conference on Computer and Communications Security (CCS\u201919). 2041--2055 . DOI:https:\/\/doi.org\/10.1145\/33 1953 5.3354209 10.1145\/3319535.3354209 Yuanshun Yao, Haitao Zheng, Huiying Li, and Ben Y. Zhao. 2019. Latent backdoor attacks on deep neural networks. In Proceedings of the ACM Conference on Computer and Communications Security (CCS\u201919). 2041--2055. DOI:https:\/\/doi.org\/10.1145\/3319535.3354209"},{"key":"e_1_2_1_173_1","doi-asserted-by":"publisher","DOI":"10.1109\/CSF.2018.00027"},{"key":"e_1_2_1_174_1","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2016.2636090"},{"key":"e_1_2_1_175_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-58469-0_7"},{"key":"e_1_2_1_176_1","doi-asserted-by":"publisher","DOI":"10.1145\/2348283.2348292"},{"key":"e_1_2_1_177_1","doi-asserted-by":"publisher","DOI":"10.1109\/DSC.2018.00104"},{"key":"e_1_2_1_178_1","doi-asserted-by":"publisher","DOI":"10.14778\/2350229.2350253"},{"key":"e_1_2_1_179_1","volume-title":"Lee","author":"Zhang Tianwei","year":"2018","unstructured":"Tianwei Zhang , Zecheng He , and Ruby B . Lee . 2018 . Privacy-preserving machine learning through data obfuscation. Retrieved from http:\/\/arxiv.org\/abs\/1807.01860. Tianwei Zhang, Zecheng He, and Ruby B. Lee. 2018. Privacy-preserving machine learning through data obfuscation. Retrieved from http:\/\/arxiv.org\/abs\/1807.01860."},{"key":"e_1_2_1_180_1","unstructured":"Xinyang Zhang Shouling Ji and Ting Wang. 2018. Differentially private releasing via deep generative model (technical report). Retrieved from http:\/\/arxiv.org\/abs\/1801.01594.  Xinyang Zhang Shouling Ji and Ting Wang. 2018. Differentially private releasing via deep generative model (technical report). Retrieved from http:\/\/arxiv.org\/abs\/1801.01594."},{"key":"e_1_2_1_181_1","doi-asserted-by":"publisher","DOI":"10.1109\/TIP.2012.2199506"}],"container-title":["ACM Computing Surveys"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3436755","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3436755","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,18]],"date-time":"2025-06-18T17:45:04Z","timestamp":1750268704000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3436755"}},"subtitle":["A Survey and Outlook"],"short-title":[],"issued":{"date-parts":[[2021,3,5]]},"references-count":181,"journal-issue":{"issue":"2","published-print":{"date-parts":[[2022,3,31]]}},"alternative-id":["10.1145\/3436755"],"URL":"https:\/\/doi.org\/10.1145\/3436755","relation":{},"ISSN":["0360-0300","1557-7341"],"issn-type":[{"value":"0360-0300","type":"print"},{"value":"1557-7341","type":"electronic"}],"subject":[],"published":{"date-parts":[[2021,3,5]]},"assertion":[{"value":"2019-03-01","order":0,"name":"received","label":"Received","group":{"name":"publication_history","label":"Publication History"}},{"value":"2020-11-01","order":1,"name":"accepted","label":"Accepted","group":{"name":"publication_history","label":"Publication History"}},{"value":"2021-03-05","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}