{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,2]],"date-time":"2026-07-02T15:56:26Z","timestamp":1783007786079,"version":"3.54.5"},"publisher-location":"New York, NY, USA","reference-count":52,"publisher":"ACM","license":[{"start":{"date-parts":[[2023,11,15]],"date-time":"2023-11-15T00:00:00Z","timestamp":1700006400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"funder":[{"name":"ETH Zurich Research Grant"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2023,11,15]]},"DOI":"10.1145\/3576915.3616607","type":"proceedings-article","created":{"date-parts":[[2023,11,21]],"date-time":"2023-11-21T12:35:13Z","timestamp":1700570113000},"page":"1905-1918","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":13,"title":["Group and Attack: Auditing Differential Privacy"],"prefix":"10.1145","author":[{"ORCID":"https:\/\/orcid.org\/0009-0001-5096-1219","authenticated-orcid":false,"given":"Johan","family":"Lokna","sequence":"first","affiliation":[{"name":"ETH Zurich, Zurich, Switzerland"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-6029-1386","authenticated-orcid":false,"given":"Anouk","family":"Paradis","sequence":"additional","affiliation":[{"name":"ETH Zurich, Zurich, Switzerland"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-9813-0900","authenticated-orcid":false,"given":"Dimitar I.","family":"Dimitrov","sequence":"additional","affiliation":[{"name":"ETH Zurich, Zurich, Switzerland"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-0054-9568","authenticated-orcid":false,"given":"Martin","family":"Vechev","sequence":"additional","affiliation":[{"name":"ETH Zurich, Zurich, Switzerland"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2023,11,21]]},"reference":[{"key":"e_1_3_2_1_1_1","volume-title":"Proceedings of the ACM on Programming Languages, 2, POPL, 1--30","author":"Albarghouthi Aws","year":"2017","unstructured":"Aws Albarghouthi and Justin Hsu. 2017. Synthesizing coupling proofs of differential privacy. Proceedings of the ACM on Programming Languages, 2, POPL, 1--30."},{"key":"e_1_3_2_1_2_1","unstructured":"\u00d6nder Askin Tim Kutta and Holger Dette. 2021. Statistical quantification of differential privacy: A local approach. CoRR abs\/2108.09528. https:\/\/arxiv.org \/abs\/2108.09528 arXiv: 2108.09528."},{"key":"e_1_3_2_1_3_1","volume-title":"International Conference on Machine Learning. PMLR, 394--403","author":"Balle Borja","year":"2018","unstructured":"Borja Balle and Yu-Xiang Wang. 2018. Improving the gaussian mechanism for differential privacy: analytical calibration and optimal denoising. In International Conference on Machine Learning. PMLR, 394--403."},{"key":"e_1_3_2_1_4_1","doi-asserted-by":"publisher","DOI":"10.1145\/3373718.3394796"},{"key":"e_1_3_2_1_5_1","doi-asserted-by":"publisher","DOI":"10.1109\/CSF.2013.26"},{"key":"e_1_3_2_1_6_1","doi-asserted-by":"publisher","DOI":"10.1145\/2976749.2978391"},{"key":"e_1_3_2_1_7_1","doi-asserted-by":"publisher","DOI":"10.1145\/2775051.2677000"},{"key":"e_1_3_2_1_8_1","doi-asserted-by":"publisher","DOI":"10.1145\/2103656.2103670"},{"key":"e_1_3_2_1_9_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP40001.2021.00081"},{"key":"e_1_3_2_1_10_1","doi-asserted-by":"publisher","DOI":"10.1214\/aoms\/1177706645"},{"key":"e_1_3_2_1_11_1","volume-title":"Computer Systems: A programmer's perspective","author":"Chapter","unstructured":"2016. Chapter 2.4.5 floating-point operations. Computer Systems: A programmer's perspective. (3rd ed.). Pearson, 160.","edition":"3"},{"key":"e_1_3_2_1_12_1","unstructured":"Mark Bun and Thomas Steinke. 2016. Concentrated differential privacy: simplifications extensions and lower bounds. CoRR abs\/1605.02065. http:\/\/arxiv.org\/abs\/1605.02065 arXiv: 1605.02065."},{"key":"e_1_3_2_1_13_1","volume-title":"State of California. (Jan. 17, 2022","year":"2022","unstructured":"2022. California consumer privacy act. State of California. (Jan. 17, 2022). Re-trieved Jan. 17, 2022 from https:\/\/leginfo.legislature.ca.gov\/faces\/codes_displa yText.xhtml?division=3.&part=4.&lawCode=CIV&title=1.81.5."},{"key":"e_1_3_2_1_14_1","volume-title":"The discrete gaussian for differential privacy. CoRR, abs\/2004.00010. https:\/\/arxiv.org\/abs\/2 004.00010 arXiv","author":"Canonne Cl\u00e9ment L.","year":"2004","unstructured":"Cl\u00e9ment L. Canonne, Gautam Kamath, and Thomas Steinke. 2020. The discrete gaussian for differential privacy. CoRR, abs\/2004.00010. https:\/\/arxiv.org\/abs\/2 004.00010 arXiv: 2004.00010."},{"key":"e_1_3_2_1_15_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP4"},{"key":"e_1_3_2_1_16_1","doi-asserted-by":"publisher","DOI":"10.1145\/3548606.3560708"},{"key":"e_1_3_2_1_17_1","volume-title":"Proceedings of the 38th International Conference on Machine Learning (Proceedings of Machine Learning Research). Marina Meila and Tong Zhang, (Eds.)","volume":"139","author":"Choquette-Choo Christopher A.","year":"2021","unstructured":"Christopher A. Choquette-Choo, Florian Tramer, Nicholas Carlini, and Nicolas Papernot. 2021. Label-only membership inference attacks. In Proceedings of the 38th International Conference on Machine Learning (Proceedings of Machine Learning Research). Marina Meila and Tong Zhang, (Eds.) Vol. 139. PMLR, (July 2021), 1964--1974. https:\/\/proceedings.mlr.press\/v139\/choquette-choo21a.html."},{"key":"e_1_3_2_1_18_1","volume-title":"A list of real-world uses of differential privacy. https:\/\/desfontain.es\/privacy\/real-world-differential-privacy.html. Ted is writing things (personal blog). (Oct","author":"Desfontaines Damien","year":"2021","unstructured":"Damien Desfontaines. 2021. A list of real-world uses of differential privacy. https:\/\/desfontain.es\/privacy\/real-world-differential-privacy.html. Ted is writing things (personal blog). (Oct. 2021)."},{"key":"e_1_3_2_1_19_1","volume-title":"National Conference of State Legislatures. (Nov. 10, 2021","year":"2022","unstructured":"2021. Differential privacy for census data explained. National Conference of State Legislatures. (Nov. 10, 2021). Retrieved Jan. 12, 2022 from https:\/\/www.n csl.org\/health\/differential-privacy-for-census-data-explained."},{"key":"e_1_3_2_1_20_1","volume-title":"European Commission. (Sept. 14, 2022","year":"2022","unstructured":"2022. Digital markets act. European Commission. (Sept. 14, 2022). Retrieved Jan. 12, 2022 from https:\/\/eur-lex.europa.eu\/legal-content\/EN\/TXT\/?uri =CELEX%3A32022R1925\/."},{"key":"e_1_3_2_1_21_1","doi-asserted-by":"publisher","unstructured":"Cynthia Dwork and Aaron Roth. 2014. The algorithmic foundations of differential privacy. Foundations and Trends\u00ae in Theoretical Computer Science 9 3--4 211--407. doi: 10.1561\/0400000042.","DOI":"10.1561\/0400000042"},{"key":"e_1_3_2_1_22_1","doi-asserted-by":"publisher","DOI":"10.1561\/0400000042"},{"key":"e_1_3_2_1_23_1","unstructured":"Marco Gaboardi Michael Hay and Salil Vadhan. 2020. A programming framework for opendp. Manuscript May."},{"key":"e_1_3_2_1_24_1","volume-title":"European Commission. (May 25, 2018","year":"2022","unstructured":"2018. General data protection regulation. European Commission. (May 25, 2018). Retrieved Jan. 12, 2022 from https:\/\/gdpr-info.eu\/."},{"key":"e_1_3_2_1_25_1","unstructured":"Google. 2021. Differential privacy. https:\/\/github.com\/google\/differential-priv acy. (2021)."},{"key":"e_1_3_2_1_26_1","unstructured":"Samuel Haney Damien Desfontaines Luke Hartman Ruchit Shrestha and Michael Hay. 2022. Precision-based attacks and interval refining: how to break then fix differential privacy on finite computers. arXiv preprint arXiv:2207.13793. https:\/\/arxiv.org\/abs\/2207.13793."},{"key":"e_1_3_2_1_27_1","unstructured":"Naoise Holohan and Stefano Braghin. 2021. Secure random sampling in differential privacy. CoRR abs\/2107.10138. https:\/\/arxiv.org\/abs\/2107.10138 arXiv: 2107.10138."},{"key":"e_1_3_2_1_28_1","volume-title":"P\u00f3l Mac Aonghusa, and Killian Levacher","author":"Holohan Naoise","year":"2019","unstructured":"Naoise Holohan, Stefano Braghin, P\u00f3l Mac Aonghusa, and Killian Levacher. 2019. Diffprivlib: the IBM differential privacy library. ArXiv e-prints, 1907.02444, (July 2019)."},{"key":"e_1_3_2_1_29_1","doi-asserted-by":"publisher","DOI":"10.1145\/3523273"},{"key":"e_1_3_2_1_30_1","volume-title":"Auditing differ-entially private machine learning: how private is private sgd? CoRR, abs\/2006.07709. https:\/\/arxiv.org\/abs\/2006.07709 arXiv","author":"Jagielski Matthew","year":"2006","unstructured":"Matthew Jagielski, Jonathan R. Ullman, and Alina Oprea. 2020. Auditing differ-entially private machine learning: how private is private sgd? CoRR, abs\/2006.07709. https:\/\/arxiv.org\/abs\/2006.07709 arXiv: 2006.07709."},{"key":"e_1_3_2_1_31_1","unstructured":"Jiankai Jin Eleanor McMurtry Benjamin I. P. Rubinstein and Olga Ohrimenko. 2021. Are we there yet? timing and floating-point attacks on differential privacy systems. CoRR abs\/2112.05307. https:\/\/arxiv.org\/abs\/2112.05307 arXiv: 2112.0 5307."},{"key":"e_1_3_2_1_32_1","doi-asserted-by":"publisher","DOI":"10.1109\/EuroSP48549.2020.00041"},{"key":"e_1_3_2_1_33_1","unstructured":"Diederik P Kingma and Jimmy Ba. 2014. Adam: a method for stochastic optimization. arXiv preprint arXiv:1412.6980."},{"key":"e_1_3_2_1_34_1","doi-asserted-by":"publisher","unstructured":"Tim Kutta \u00d6nder Askin and Martin Dunsche. 2022. Lower bounds for r\u00e9nyi differential privacy in a black-box setting. (2022). doi: 10.48550\/ARXIV.2212.04 739.","DOI":"10.48550\/ARXIV.2212.04"},{"key":"e_1_3_2_1_35_1","volume-title":"Advances in Neural Information Processing Systems. H. Wallach, H. Larochelle, A. Beygelzimer, F. d'Alch\u00e9-Buc","author":"Liu Xiyang","year":"2019","unstructured":"Xiyang Liu and Sewoong Oh. 2019. Minimax optimal estimation of approximate differential privacy on neighboring databases. In Advances in Neural Information Processing Systems. H. Wallach, H. Larochelle, A. Beygelzimer, F. d'Alch\u00e9-Buc, E. Fox, and R. Garnett, (Eds.) Vol. 32. Curran Associates, Inc. https:\/\/proceedings.neurips.cc\/paper\/2019\/file\/7a674153c63cff1ad7f0e261c36 9ab2c-Paper.pdf."},{"key":"e_1_3_2_1_36_1","doi-asserted-by":"publisher","unstructured":"Fred Lu Joseph Munoz Maya Fuchs Tyler LeBlond Elliott Zaresky-Williams Edward Raff Francis Ferraro and Brian Testa. 2022. A general framework for auditing differentially private machine learning. (2022). doi: 10.48550\/ARXIV.2 210.08643.","DOI":"10.48550\/ARXIV.2"},{"key":"e_1_3_2_1_37_1","volume-title":"Paper 2022\/1250. https:\/\/eprint.iacr.org\/2022\/1250.","author":"Lu Yun","year":"2022","unstructured":"Yun Lu, Yu Wei, Malik Magdon-Ismail, and Vassilis Zikas. 2022. Eureka: a general framework for black-box differential privacy estimators. Cryptology ePrint Archive, Paper 2022\/1250. https:\/\/eprint.iacr.org\/2022\/1250. (2022). https:\/\/eprint.iacr.org\/2022\/1250."},{"key":"e_1_3_2_1_38_1","doi-asserted-by":"publisher","DOI":"10.1137\/1006063"},{"key":"e_1_3_2_1_39_1","doi-asserted-by":"publisher","DOI":"10.18637\/jss.v005.i08"},{"key":"e_1_3_2_1_40_1","unstructured":"Ryan McKenna Gerome Miklau and Daniel Sheldon. 2021. Winning the NIST contest: A scalable and general approach to differentially private synthetic data. CoRR abs\/2108.04978. https:\/\/arxiv.org\/abs\/2108.04978 arXiv: 2108.04978."},{"key":"e_1_3_2_1_41_1","unstructured":"Ryan McKenna Brett Mullins Daniel Sheldon and Gerome Miklau. 2022. AIM: an adaptive and iterative mechanism for differentially private synthetic data. CoRR abs\/2201.12677. https:\/\/arxiv.org\/abs\/2201.12677 arXiv: 2201.12677."},{"key":"e_1_3_2_1_42_1","doi-asserted-by":"publisher","DOI":"10.1145\/2382196.2382264"},{"key":"e_1_3_2_1_43_1","doi-asserted-by":"publisher","DOI":"10.1109\/csf.2017.11"},{"key":"e_1_3_2_1_44_1","doi-asserted-by":"crossref","unstructured":"Ben Niu Zejun Zhou Yahong Chen Jin Cao and Fenghua Li. 2022. Dp-opt: identify high differential privacy violation by optimization. In Wireless Algorithms Systems and Applications. Lei Wang Michael Segal Jenhui Chen and Tie Qiu (Eds.) Springer Nature Switzerland Cham 406--416. isbn: 978-3-031-19214-2.","DOI":"10.1007\/978-3-031-19214-2_34"},{"key":"e_1_3_2_1_45_1","unstructured":"OpenMinded. 2021. Pydp. https:\/\/github.com\/OpenMined\/PyDP. (2021)."},{"key":"e_1_3_2_1_46_1","first-page":"61","article-title":"Membership inference attack against differentially private deep learning model","volume":"11","author":"Rahman Atiqur","year":"2018","unstructured":"Md.Atiqur Rahman, Tanzila Rahman, Robert Lagani\u00e8re, and Noman Mohammed. 2018. Membership inference attack against differentially private deep learning model. Trans. Data Priv., 11, 61--79.","journal-title":"Trans. Data Priv."},{"key":"e_1_3_2_1_47_1","doi-asserted-by":"publisher","DOI":"10.1145\/1863543.1863568"},{"key":"e_1_3_2_1_48_1","volume-title":"31st USENIX Security Symposium (USENIX Security 22)","author":"Stadler Theresa","year":"2022","unstructured":"Theresa Stadler, Bristena Oprisanu, and Carmela Troncoso. 2022. Synthetic data--anonymisation groundhog day. In 31st USENIX Security Symposium (USENIX Security 22), 1451--1468."},{"key":"e_1_3_2_1_49_1","doi-asserted-by":"publisher","DOI":"10.1145\/3372297.3417282"},{"key":"e_1_3_2_1_50_1","unstructured":"Yuxin Wang Zeyu Ding Guanhong Wang Daniel Kifer and Danfeng Zhang. 2019. Proving differential privacy with shadow execution. CoRR abs\/1903.12254. http:\/\/arxiv.org\/abs\/1903.12254 arXiv: 1903.12254."},{"key":"e_1_3_2_1_51_1","volume-title":"Opacus: User-friendly differential privacy library in PyTorch. arXiv preprint arXiv:2109.12298.","author":"Ashkan Yousefpour","year":"2021","unstructured":"Ashkan Yousefpour et al. 2021. Opacus: User-friendly differential privacy library in PyTorch. arXiv preprint arXiv:2109.12298."},{"key":"e_1_3_2_1_52_1","doi-asserted-by":"publisher","DOI":"10.1145\/3009837.3009884"}],"event":{"name":"CCS '23: ACM SIGSAC Conference on Computer and Communications Security","location":"Copenhagen Denmark","acronym":"CCS '23","sponsor":["SIGSAC ACM Special Interest Group on Security, Audit, and Control"]},"container-title":["Proceedings of the 2023 ACM SIGSAC Conference on Computer and Communications Security"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3576915.3616607","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3576915.3616607","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,8,21]],"date-time":"2025-08-21T01:43:34Z","timestamp":1755740614000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3576915.3616607"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2023,11,15]]},"references-count":52,"alternative-id":["10.1145\/3576915.3616607","10.1145\/3576915"],"URL":"https:\/\/doi.org\/10.1145\/3576915.3616607","relation":{},"subject":[],"published":{"date-parts":[[2023,11,15]]},"assertion":[{"value":"2023-11-21","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}