{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,8,22]],"date-time":"2025-08-22T00:40:29Z","timestamp":1755823229699,"version":"3.44.0"},"publisher-location":"New York, NY, USA","reference-count":48,"publisher":"ACM","license":[{"start":{"date-parts":[[2023,11,15]],"date-time":"2023-11-15T00:00:00Z","timestamp":1700006400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"funder":[{"DOI":"10.13039\/501100001459","name":"Ministry of Education - Singapore","doi-asserted-by":"publisher","award":["MOE-T2EP20121-0011"],"award-info":[{"award-number":["MOE-T2EP20121-0011"]}],"id":[{"id":"10.13039\/501100001459","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100006757","name":"Centre for Quantum Technologies","doi-asserted-by":"publisher","award":["Quantum algorithms, complexity, and communication"],"award-info":[{"award-number":["Quantum algorithms, complexity, and communication"]}],"id":[{"id":"10.13039\/501100006757","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2023,11,15]]},"DOI":"10.1145\/3576915.3623093","type":"proceedings-article","created":{"date-parts":[[2023,11,21]],"date-time":"2023-11-21T12:35:13Z","timestamp":1700570113000},"page":"1138-1152","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":0,"title":["Unforgeability in Stochastic Gradient Descent"],"prefix":"10.1145","author":[{"ORCID":"https:\/\/orcid.org\/0000-0003-3655-9810","authenticated-orcid":false,"given":"Teodora","family":"Baluta","sequence":"first","affiliation":[{"name":"National University of Singapore, Singapore, Singapore"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-9578-4837","authenticated-orcid":false,"given":"Ivica","family":"Nikolic","sequence":"additional","affiliation":[{"name":"National University of Singapore, Singapore, Singapore"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0009-0003-1009-2447","authenticated-orcid":false,"given":"Racchit","family":"Jain","sequence":"additional","affiliation":[{"name":"National University of Singapore, Singapore, Singapore"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-3841-0262","authenticated-orcid":false,"given":"Divesh","family":"Aggarwal","sequence":"additional","affiliation":[{"name":"National University of Singapore, Singapore, Singapore"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-1875-8675","authenticated-orcid":false,"given":"Prateek","family":"Saxena","sequence":"additional","affiliation":[{"name":"National University of Singapore, Singapore, Singapore"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2023,11,21]]},"reference":[{"key":"e_1_3_2_1_1_1","doi-asserted-by":"publisher","DOI":"10.1145\/2976749.2978318"},{"key":"e_1_3_2_1_2_1","first-page":"1333","article-title":"Privacy-preserving deep learning via additively homomorphic encryption","volume":"13","author":"Aono Yoshinori","year":"2017","unstructured":"Yoshinori Aono, Takuya Hayashi, Lihua Wang, Shiho Moriai, et al. 2017. Privacy-preserving deep learning via additively homomorphic encryption. IEEE Transactions on Information Forensics and Security, Vol. 13, 5 (2017), 1333--1345.","journal-title":"IEEE Transactions on Information Forensics and Security"},{"key":"e_1_3_2_1_3_1","unstructured":"IEEE Standards Association et al. 2019. 754--2019-IEEE Standard for Floating-Point Arithmetic."},{"key":"e_1_3_2_1_4_1","volume-title":"Scalable methods for 8-bit training of neural networks. Advances in neural information processing systems (NeurIPS)","author":"Banner Ron","year":"2018","unstructured":"Ron Banner, Itay Hubara, Elad Hoffer, and Daniel Soudry. 2018. Scalable methods for 8-bit training of neural networks. Advances in neural information processing systems (NeurIPS) , Vol. 31 (2018)."},{"key":"e_1_3_2_1_5_1","volume-title":"Neural gradients are near-lognormal: improved quantized and sparse training. arXiv preprint arXiv:2006.08173","author":"Chmiel Brian","year":"2020","unstructured":"Brian Chmiel, Liad Ben-Uri, Moran Shkolnik, Elad Hoffer, Ron Banner, and Daniel Soudry. 2020. Neural gradients are near-lognormal: improved quantized and sparse training. arXiv preprint arXiv:2006.08173 (2020)."},{"key":"e_1_3_2_1_6_1","unstructured":"Ella Creamer. 5 July 2023. Authors file a lawsuit against OpenAI for unlawfully 'ingesting' their books. https:\/\/www.theguardian.com\/books\/2023\/jul\/05\/authors-file-a-lawsuit-against-openai-for-unlawfully-ingesting-their-books. Accessed: 2023-08--13."},{"key":"e_1_3_2_1_7_1","volume-title":"High-accuracy low-precision training. arXiv preprint arXiv:1803.03383","author":"Sa Christopher De","year":"2018","unstructured":"Christopher De Sa, Megan Leszczynski, Jian Zhang, Alana Marzoev, Christopher R Aberger, Kunle Olukotun, and Christopher R\u00e9. 2018. High-accuracy low-precision training. arXiv preprint arXiv:1803.03383 (2018)."},{"key":"e_1_3_2_1_8_1","volume-title":"Documenting large webtext corpora: A case study on the colossal clean crawled corpus. arXiv preprint arXiv:2104.08758","author":"Dodge Jesse","year":"2021","unstructured":"Jesse Dodge, Maarten Sap, Ana Marasovi\u0107, William Agnew, Gabriel Ilharco, Dirk Groeneveld, Margaret Mitchell, and Matt Gardner. 2021. Documenting large webtext corpora: A case study on the colossal clean crawled corpus. arXiv preprint arXiv:2104.08758 (2021)."},{"key":"e_1_3_2_1_9_1","volume-title":"Ce Ju, Tianyu Zhang, Chang Liu, Chee Seng Chan, and Qiang Yang.","author":"Fan Lixin","year":"2020","unstructured":"Lixin Fan, Kam Woh Ng, Ce Ju, Tianyu Zhang, Chang Liu, Chee Seng Chan, and Qiang Yang. 2020. Rethinking privacy preserving deep learning: How to evaluate and thwart privacy attacks. Federated Learning: Privacy and Incentive (2020), 32--50."},{"key":"e_1_3_2_1_10_1","doi-asserted-by":"crossref","unstructured":"Congyu Fang Hengrui Jia Anvith Thudi Mohammad Yaghini Christopher A Choquette-Choo Natalie Dullerud Varun Chandrasekaran and Nicolas Papernot. 2023. Proof-of-Learning is Currently More Broken Than You Think. (2023).","DOI":"10.1109\/EuroSP57164.2023.00052"},{"key":"e_1_3_2_1_11_1","unstructured":"Michael R Gary and David S Johnson. 1979. Computers and Intractability: A Guide to the Theory of NP-completeness."},{"key":"e_1_3_2_1_12_1","first-page":"16937","article-title":"Inverting gradients-how easy is it to break privacy in federated learning","volume":"33","author":"Geiping Jonas","year":"2020","unstructured":"Jonas Geiping, Hartmut Bauermeister, Hannah Dr\u00f6ge, and Michael Moeller. 2020. Inverting gradients-how easy is it to break privacy in federated learning? Advances in Neural Information Processing Systems, Vol. 33 (2020), 16937--16947.","journal-title":"Advances in Neural Information Processing Systems"},{"key":"e_1_3_2_1_13_1","first-page":"27402","article-title":"Is Integer Arithmetic Enough for Deep Learning Training","volume":"35","author":"Ghaffari Alireza","year":"2022","unstructured":"Alireza Ghaffari, Marzieh S Tahaei, Mohammadreza Tayaranian, Masoud Asgharian, and Vahid Partovi Nia. 2022. Is Integer Arithmetic Enough for Deep Learning Training? Advances in Neural Information Processing Systems (NeurIPS), Vol. 35 (2022), 27402--27413.","journal-title":"Advances in Neural Information Processing Systems (NeurIPS)"},{"key":"e_1_3_2_1_14_1","volume-title":"A survey of quantization methods for efficient neural network inference. arXiv preprint arXiv:2103.13630","author":"Gholami Amir","year":"2021","unstructured":"Amir Gholami, Sehoon Kim, Zhen Dong, Zhewei Yao, Michael W Mahoney, and Kurt Keutzer. 2021. A survey of quantization methods for efficient neural network inference. arXiv preprint arXiv:2103.13630 (2021)."},{"key":"e_1_3_2_1_15_1","volume-title":"What every computer scientist should know about floating-point arithmetic. ACM computing surveys (CSUR)","author":"Goldberg David","year":"1991","unstructured":"David Goldberg. 1991. What every computer scientist should know about floating-point arithmetic. ACM computing surveys (CSUR), Vol. 23, 1 (1991), 5--48."},{"key":"e_1_3_2_1_16_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.90"},{"key":"e_1_3_2_1_17_1","volume-title":"NTRU: A ring-based public key cryptosystem. In Algorithmic Number Theory: Third International Symposiun, ANTS-III Portland, Oregon, USA","author":"Hoffstein Jeffrey","year":"2006","unstructured":"Jeffrey Hoffstein, Jill Pipher, and Joseph H Silverman. 2006. NTRU: A ring-based public key cryptosystem. In Algorithmic Number Theory: Third International Symposiun, ANTS-III Portland, Oregon, USA, June 21-25, 1998 Proceedings. Springer, 267--288."},{"key":"e_1_3_2_1_18_1","first-page":"7232","article-title":"Evaluating gradient inversion attacks and defenses in federated learning","volume":"34","author":"Huang Yangsibo","year":"2021","unstructured":"Yangsibo Huang, Samyak Gupta, Zhao Song, Kai Li, and Sanjeev Arora. 2021. Evaluating gradient inversion attacks and defenses in federated learning. Advances in Neural Information Processing Systems (NeurIPS), Vol. 34 (2021), 7232--7241.","journal-title":"Advances in Neural Information Processing Systems (NeurIPS)"},{"key":"e_1_3_2_1_19_1","volume-title":"Binarized neural networks. Advances in neural information processing systems (NeurIPS)","author":"Hubara Itay","year":"2016","unstructured":"Itay Hubara, Matthieu Courbariaux, Daniel Soudry, Ran El-Yaniv, and Yoshua Bengio. 2016. Binarized neural networks. Advances in neural information processing systems (NeurIPS), Vol. 29 (2016)."},{"key":"e_1_3_2_1_20_1","doi-asserted-by":"publisher","DOI":"10.5555\/3122009.3242044"},{"key":"e_1_3_2_1_21_1","unstructured":"Jinwoo Jeon Kangwook Lee Sewoong Oh Jungseul Ok et al. 2021. Gradient inversion with generative image prior. Advances in neural information processing systems (NeurIPS) Vol. 34 (2021) 29898--29908."},{"key":"e_1_3_2_1_22_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP40001.2021.00106"},{"key":"e_1_3_2_1_23_1","volume-title":"Amrita Roy Chowdhury, and Kamalika Chaudhuri","author":"Kong Zhifeng","year":"2023","unstructured":"Zhifeng Kong, Amrita Roy Chowdhury, and Kamalika Chaudhuri. 2023. Can Membership Inferencing be Refuted? arXiv preprint arXiv:2303.03648 (2023)."},{"key":"e_1_3_2_1_24_1","doi-asserted-by":"publisher","DOI":"10.1145\/3560830.3563731"},{"key":"e_1_3_2_1_25_1","unstructured":"Alex Krizhevsky Geoffrey Hinton et al. 2009. Learning multiple layers of features from tiny images. (2009)."},{"key":"e_1_3_2_1_26_1","unstructured":"Yann LeCun. 1998. The MNIST database of handwritten digits. http:\/\/yann. lecun. com\/exdb\/mnist\/ (1998)."},{"key":"e_1_3_2_1_27_1","volume-title":"Backpropagation applied to handwritten zip code recognition. Neural computation","author":"LeCun Yann","year":"1989","unstructured":"Yann LeCun, Bernhard Boser, John S Denker, Donnie Henderson, Richard E Howard, Wayne Hubbard, and Lawrence D Jackel. 1989. Backpropagation applied to handwritten zip code recognition. Neural computation, Vol. 1, 4 (1989), 541--551."},{"key":"e_1_3_2_1_28_1","volume-title":"Advances in Neural Information Processing Systems (NeurIPS)","volume":"32","author":"Li Ke","year":"2019","unstructured":"Ke Li, Tianhao Zhang, and Jitendra Malik. 2019. Approximate feature collisions in neural nets. Advances in Neural Information Processing Systems (NeurIPS), Vol. 32 (2019)."},{"key":"e_1_3_2_1_29_1","volume-title":"International conference on machine learning (ICML). PMLR, 2849--2858","author":"Lin Darryl","year":"2016","unstructured":"Darryl Lin, Sachin Talathi, and Sreekanth Annapureddy. 2016. Fixed point quantization of deep convolutional networks. In International conference on machine learning (ICML). PMLR, 2849--2858."},{"key":"e_1_3_2_1_30_1","volume-title":"A parallel algorithm for Gaussian elimination over finite fields. arXiv preprint arXiv:1806.04211","author":"Linton Stephen","year":"2018","unstructured":"Stephen Linton, Gabriele Nebe, Alice Niemeyer, Richard Parker, and Jon Thackray. 2018. A parallel algorithm for Gaussian elimination over finite fields. arXiv preprint arXiv:1806.04211 (2018)."},{"key":"e_1_3_2_1_31_1","doi-asserted-by":"publisher","DOI":"10.1080\/01621459.1951.10500769"},{"key":"e_1_3_2_1_32_1","volume-title":"Wesley De Neve, and Arnout Van Messem","author":"Ozbulak Utku","year":"2022","unstructured":"Utku Ozbulak, Manvel Gasparyan, Shodhan Rao, Wesley De Neve, and Arnout Van Messem. 2022. Exact Feature Collisions in Neural Networks. arXiv preprint arXiv:2205.15763 (2022)."},{"key":"e_1_3_2_1_33_1","doi-asserted-by":"publisher","DOI":"10.5555\/3546258.3546422"},{"key":"e_1_3_2_1_34_1","unstructured":"PyTorch. 2022. Reference Implementation of \u0142enet for Forging. https:\/\/github.com\/cleverhans-lab\/Forging. Accessed: 2023-02-28."},{"key":"e_1_3_2_1_35_1","unstructured":"PyTorch Contributors. 2022. PyTorch Reproducibility Documentation. https:\/\/pytorch.org\/docs\/1.13\/notes\/randomness.html?highlight=reproducibility. Accessed: 2023-04-28."},{"key":"e_1_3_2_1_36_1","unstructured":"Jack Queen. 9 July 2023. Sarah Silverman sues Meta OpenAI for copyright infringement. hhttps:\/\/www.reuters.com\/legal\/sarah-silverman-sues-meta-openai-copyright-infringement-2023-07-09\/. Accessed: 2023-08-13."},{"key":"e_1_3_2_1_37_1","doi-asserted-by":"publisher","DOI":"10.5555\/3455716.3455856"},{"key":"e_1_3_2_1_38_1","unstructured":"Github Repo. 2018. Reference Implementation of resnet for Forging. https:\/\/github.com\/nikhilbarhate99\/Image-Classifiers. Accessed: 2023-04-10."},{"key":"e_1_3_2_1_39_1","unstructured":"Adam Roberts Hyung Won Chung Anselm Levskaya Gaurav Mishra James Bradbury Daniel Andor Sharan Narang Brian Lester Colin Gaffney Afroz Mohiuddin Curtis Hawthorne Aitor Lewkowycz Alex Salcianu Marc van Zee Jacob Austin Sebastian Goodman Livio Baldini Soares Haitang Hu Sasha Tsvyashchenko Aakanksha Chowdhery Jasmijn Bastings Jannis Bulian Xavier Garcia Jianmo Ni Andrew Chen Kathleen Kenealy Jonathan H. Clark Stephan Lee Dan Garrette James Lee-Thorp Colin Raffel Noam Shazeer Marvin Ritter Maarten Bosma Alexandre Passos Jeremy Maitin-Shepard Noah Fiedel Mark Omernick Brennan Saeta Ryan Sepassi Alexander Spiridonov Joshua Newlan and Andrea Gesmundo. 2022. Scaling Up Models and Data with t5x and seqio. arXiv preprint arXiv:2203.17189 (2022). https:\/\/arxiv.org\/abs\/2203.17189"},{"key":"e_1_3_2_1_40_1","volume-title":"SoK: Let The Privacy Games Begin! A Unified Treatment of Data Inference Privacy in Machine Learning. arXiv preprint arXiv:2212.10986","author":"Salem Ahmed","year":"2022","unstructured":"Ahmed Salem, Giovanni Cherubin, David Evans, Boris K\u00f6pf, Andrew Paverd, Anshuman Suri, Shruti Tople, and Santiago Zanella-B\u00e9guelin. 2022. SoK: Let The Privacy Games Begin! A Unified Treatment of Data Inference Privacy in Machine Learning. arXiv preprint arXiv:2212.10986 (2022)."},{"key":"e_1_3_2_1_41_1","volume-title":"Advances in Neural Information Processing Systems (NeurIPS","volume":"34","author":"Shumailov Ilia","year":"2021","unstructured":"Ilia Shumailov, Zakhar Shumaylov, Dmitry Kazhdan, Yiren Zhao, Nicolas Papernot, Murat A Erdogdu, and Ross J Anderson. 2021. Manipulating sgd with data ordering attacks. Advances in Neural Information Processing Systems (NeurIPS, Vol. 34 (2021), 18021--18032."},{"key":"e_1_3_2_1_42_1","unstructured":"Rachael Tatman Jake VanderPlas and Sohier Dane. 2018. A practical taxonomy of reproducibility for machine learning research."},{"key":"e_1_3_2_1_43_1","volume-title":"31st USENIX Security Symposium (USENIX Security). 4007--4022","author":"Thudi Anvith","year":"2022","unstructured":"Anvith Thudi, Hengrui Jia, Ilia Shumailov, and Nicolas Papernot. 2022. On the necessity of auditable algorithmic definitions for machine unlearning. In 31st USENIX Security Symposium (USENIX Security). 4007--4022."},{"key":"e_1_3_2_1_44_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-58595-2_20"},{"key":"e_1_3_2_1_45_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR46437.2021.01607"},{"key":"e_1_3_2_1_46_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP46214.2022.9833596"},{"key":"e_1_3_2_1_47_1","volume-title":"R-gap: Recursive gradient attack on privacy. arXiv preprint arXiv:2010.07733","author":"Zhu Junyi","year":"2020","unstructured":"Junyi Zhu and Matthew Blaschko. 2020. R-gap: Recursive gradient attack on privacy. arXiv preprint arXiv:2010.07733 (2020)."},{"key":"e_1_3_2_1_48_1","volume-title":"Deep leakage from gradients. Advances in neural information processing systems (NeurIPS)","author":"Zhu Ligeng","year":"2019","unstructured":"Ligeng Zhu, Zhijian Liu, and Song Han. 2019. Deep leakage from gradients. Advances in neural information processing systems (NeurIPS), Vol. 32 (2019)."}],"event":{"name":"CCS '23: ACM SIGSAC Conference on Computer and Communications Security","sponsor":["SIGSAC ACM Special Interest Group on Security, Audit, and Control"],"location":"Copenhagen Denmark","acronym":"CCS '23"},"container-title":["Proceedings of the 2023 ACM SIGSAC Conference on Computer and Communications Security"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3576915.3623093","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3576915.3623093","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,8,21]],"date-time":"2025-08-21T01:37:13Z","timestamp":1755740233000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3576915.3623093"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2023,11,15]]},"references-count":48,"alternative-id":["10.1145\/3576915.3623093","10.1145\/3576915"],"URL":"https:\/\/doi.org\/10.1145\/3576915.3623093","relation":{},"subject":[],"published":{"date-parts":[[2023,11,15]]},"assertion":[{"value":"2023-11-21","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}