{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,7]],"date-time":"2026-05-07T08:23:30Z","timestamp":1778142210997,"version":"3.51.4"},"publisher-location":"New York, NY, USA","reference-count":49,"publisher":"ACM","license":[{"start":{"date-parts":[[2023,11,15]],"date-time":"2023-11-15T00:00:00Z","timestamp":1700006400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2023,11,15]]},"DOI":"10.1145\/3576915.3623142","type":"proceedings-article","created":{"date-parts":[[2023,11,21]],"date-time":"2023-11-21T12:35:13Z","timestamp":1700570113000},"page":"2636-2650","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":8,"title":["Geometry of Sensitivity: Twice Sampling and Hybrid Clipping in Differential Privacy with Optimal Gaussian Noise and Application to Deep Learning"],"prefix":"10.1145","author":[{"ORCID":"https:\/\/orcid.org\/0000-0003-3380-4518","authenticated-orcid":false,"given":"Hanshen","family":"Xiao","sequence":"first","affiliation":[{"name":"Massachusetts Institute of Technology, Cambridge , MA, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0009-0008-6357-3515","authenticated-orcid":false,"given":"Jun","family":"Wan","sequence":"additional","affiliation":[{"name":"Massachusetts Institute of Technology, Cambridge , MA, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-8253-7714","authenticated-orcid":false,"given":"Srinivas","family":"Devadas","sequence":"additional","affiliation":[{"name":"Massachusetts Institute of Technology, Cambridge , MA, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2023,11,21]]},"reference":[{"key":"e_1_3_2_1_1_1","doi-asserted-by":"publisher","DOI":"10.1145\/2976749.2978318"},{"key":"e_1_3_2_1_2_1","volume-title":"Principal component analysis","author":"Abdi Herv\u00e9","year":"2010","unstructured":"Herv\u00e9 Abdi and Lynne J Williams. 2010. Principal component analysis. Wiley interdisciplinary reviews: computational statistics, Vol. 2, 4 (2010), 433--459."},{"key":"e_1_3_2_1_3_1","doi-asserted-by":"publisher","DOI":"10.1080\/01621459.2020.1773831"},{"key":"e_1_3_2_1_4_1","volume-title":"Advances in Neural Information Processing Systems","volume":"31","author":"Balle Borja","year":"2018","unstructured":"Borja Balle, Gilles Barthe, and Marco Gaboardi. 2018. Privacy amplification by subsampling: Tight analyses via couplings and divergences. Advances in Neural Information Processing Systems, Vol. 31 (2018)."},{"key":"e_1_3_2_1_5_1","volume-title":"Private empirical risk minimization: Efficient algorithms and tight error bounds. In 2014 IEEE 55th annual symposium on foundations of computer science","author":"Bassily Raef","unstructured":"Raef Bassily, Adam Smith, and Abhradeep Thakurta. 2014. Private empirical risk minimization: Efficient algorithms and tight error bounds. In 2014 IEEE 55th annual symposium on foundations of computer science. IEEE, 464--473."},{"key":"e_1_3_2_1_6_1","volume-title":"Convex optimization","author":"Boyd Stephen","unstructured":"Stephen Boyd, Stephen P Boyd, and Lieven Vandenberghe. 2004. Convex optimization. Cambridge university press."},{"key":"e_1_3_2_1_7_1","doi-asserted-by":"publisher","DOI":"10.1145\/2591796.2591877"},{"key":"e_1_3_2_1_8_1","volume-title":"Neural networks and back propagation algorithm","author":"Cilimkovic Mirza","year":"2015","unstructured":"Mirza Cilimkovic. 2015. Neural networks and back propagation algorithm. Institute of Technology Blanchardstown, Blanchardstown Road North Dublin, Vol. 15, 1 (2015)."},{"key":"e_1_3_2_1_9_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-28914-9_18"},{"key":"e_1_3_2_1_10_1","volume-title":"Unlocking high-accuracy differentially private image classification through scale. arXiv preprint arXiv:2204.13650","author":"De Soham","year":"2022","unstructured":"Soham De, Leonard Berrada, Jamie Hayes, Samuel L Smith, and Borja Balle. 2022. Unlocking high-accuracy differentially private image classification through scale. arXiv preprint arXiv:2204.13650 (2022)."},{"key":"e_1_3_2_1_11_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2009.5206848"},{"key":"e_1_3_2_1_12_1","doi-asserted-by":"publisher","DOI":"10.1111\/rssb.12454"},{"key":"e_1_3_2_1_13_1","doi-asserted-by":"publisher","DOI":"10.1007\/11761679_29"},{"key":"e_1_3_2_1_14_1","volume-title":"Theory of cryptography conference","author":"Dwork Cynthia","unstructured":"Cynthia Dwork, Frank McSherry, Kobbi Nissim, and Adam Smith. 2006 b. Calibrating noise to sensitivity in private data analysis. In Theory of cryptography conference. Springer, 265--284."},{"key":"e_1_3_2_1_15_1","first-page":"3","article-title":"The algorithmic foundations of differential privacy","volume":"9","author":"Dwork Cynthia","year":"2014","unstructured":"Cynthia Dwork, Aaron Roth, et al. 2014. The algorithmic foundations of differential privacy. Found. Trends Theor. Comput. Sci., Vol. 9, 3--4 (2014), 211--407.","journal-title":"Found. Trends Theor. Comput. Sci."},{"key":"e_1_3_2_1_16_1","doi-asserted-by":"publisher","DOI":"10.1109\/FOCS.2010.12"},{"key":"e_1_3_2_1_17_1","doi-asserted-by":"publisher","DOI":"10.1109\/TIT.2015.2504967"},{"key":"e_1_3_2_1_18_1","doi-asserted-by":"publisher","DOI":"10.1109\/TIT.2015.2504972"},{"key":"e_1_3_2_1_19_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.ins.2013.06.018"},{"key":"e_1_3_2_1_20_1","doi-asserted-by":"publisher","DOI":"10.1145\/1806689.1806786"},{"key":"e_1_3_2_1_21_1","doi-asserted-by":"publisher","DOI":"10.1145\/1806689.1806786"},{"key":"e_1_3_2_1_22_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.90"},{"key":"e_1_3_2_1_23_1","doi-asserted-by":"publisher","DOI":"10.1145\/3517804.3524144"},{"key":"e_1_3_2_1_24_1","article-title":"Generalized power method for sparse principal component analysis","volume":"11","author":"Journ\u00e9e Michel","year":"2010","unstructured":"Michel Journ\u00e9e, Yurii Nesterov, Peter Richt\u00e1rik, and Rodolphe Sepulchre. 2010. Generalized power method for sparse principal component analysis. Journal of Machine Learning Research, Vol. 11, 2 (2010).","journal-title":"Journal of Machine Learning Research"},{"key":"e_1_3_2_1_25_1","volume-title":"Conference on Learning Theory. PMLR, 2717--2746","author":"Kairouz Peter","year":"2021","unstructured":"Peter Kairouz, Monica Ribero Diaz, Keith Rush, and Abhradeep Thakurta. 2021. (Nearly) Dimension Independent Private ERM with AdaGrad Rates via Publicly Estimated Subspaces. In Conference on Learning Theory. PMLR, 2717--2746."},{"key":"e_1_3_2_1_26_1","unstructured":"Alex Krizhevsky Geoffrey Hinton et al. 2009. Learning multiple layers of features from tiny images. (2009)."},{"key":"e_1_3_2_1_27_1","doi-asserted-by":"publisher","DOI":"10.1145\/2414456.2414474"},{"key":"e_1_3_2_1_28_1","volume-title":"Random walks in a convex body and an improved","author":"Lov\u00e1sz L\u00e1szl\u00f3","year":"1993","unstructured":"L\u00e1szl\u00f3 Lov\u00e1sz and Mikl\u00f3s Simonovits. 1993. Random walks in a convex body and an improved volume algorithm. Random structures & algorithms, Vol. 4, 4 (1993), 359--412."},{"key":"e_1_3_2_1_29_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR46437.2021.00502"},{"key":"e_1_3_2_1_30_1","volume-title":"A general approach to adding differential privacy to iterative training procedures. arXiv preprint arXiv:1812.06210","author":"McMahan H Brendan","year":"2018","unstructured":"H Brendan McMahan, Galen Andrew, Ulfar Erlingsson, Steve Chien, Ilya Mironov, Nicolas Papernot, and Peter Kairouz. 2018a. A general approach to adding differential privacy to iterative training procedures. arXiv preprint arXiv:1812.06210 (2018)."},{"key":"e_1_3_2_1_31_1","volume-title":"Learning Differentially Private Recurrent Language Models. In International Conference on Learning Representations.","author":"McMahan H Brendan","year":"2018","unstructured":"H Brendan McMahan, Daniel Ramage, Kunal Talwar, and Li Zhang. 2018b. Learning Differentially Private Recurrent Language Models. In International Conference on Learning Representations."},{"key":"e_1_3_2_1_32_1","volume-title":"R\u00e9nyi differential privacy. In 2017 IEEE 30th computer security foundations symposium (CSF)","author":"Mironov Ilya","unstructured":"Ilya Mironov. 2017. R\u00e9nyi differential privacy. In 2017 IEEE 30th computer security foundations symposium (CSF). IEEE, 263--275."},{"key":"e_1_3_2_1_33_1","volume-title":"arXiv preprint arXiv:1908.10530","author":"Mironov Ilya","year":"2019","unstructured":"Ilya Mironov, Kunal Talwar, and Li Zhang. 2019. R\\'enyi differential privacy of the sampled gaussian mechanism. arXiv preprint arXiv:1908.10530 (2019)."},{"key":"e_1_3_2_1_34_1","doi-asserted-by":"publisher","DOI":"10.1145\/2213977.2214090"},{"key":"e_1_3_2_1_35_1","doi-asserted-by":"publisher","DOI":"10.1145\/2488608.2488652"},{"key":"e_1_3_2_1_36_1","unstructured":"OpenAI. 2023. GPT-4 Technical Report. arxiv: 2303.08774 [cs.CL]"},{"key":"e_1_3_2_1_37_1","unstructured":"Nicolas Papernot Steve Chien Shuang Song Abhradeep Thakurta and Ulfar Erlingsson. 2020. Making the shoe fit: Architectures initializations and tuning for learning with privacy. (2020)."},{"key":"e_1_3_2_1_38_1","volume-title":"International Conference on Artificial Intelligence and Statistics. PMLR, 2638--2646","author":"Song Shuang","year":"2021","unstructured":"Shuang Song, Thomas Steinke, Om Thakkar, and Abhradeep Thakurta. 2021. Evading the curse of dimensionality in unconstrained private glms. In International Conference on Artificial Intelligence and Statistics. PMLR, 2638--2646."},{"key":"e_1_3_2_1_39_1","doi-asserted-by":"publisher","DOI":"10.1109\/TIT.2014.2320500"},{"key":"e_1_3_2_1_40_1","volume-title":"International Conference on Machine Learning. PMLR, 10081--10091","author":"Wang Di","year":"2020","unstructured":"Di Wang, Hanshen Xiao, Srinivas Devadas, and Jinhui Xu. 2020. On differentially private stochastic convex optimization with heavy-tailed data. In International Conference on Machine Learning. PMLR, 10081--10091."},{"key":"e_1_3_2_1_41_1","volume-title":"The 22nd International Conference on Artificial Intelligence and Statistics. PMLR, 1226--1235","author":"Wang Yu-Xiang","year":"2019","unstructured":"Yu-Xiang Wang, Borja Balle, and Shiva Prasad Kasiviswanathan. 2019. Subsampled r\u00e9nyi differential privacy and analytical moments accountant. In The 22nd International Conference on Artificial Intelligence and Statistics. PMLR, 1226--1235."},{"key":"e_1_3_2_1_42_1","volume-title":"2023 a. Geometry of Sensitivity: Twice Sampling and Hybrid Clipping in Differential Privacy with Optimal Gaussian Noise and Application to Deep Learning. arXiv preprint arXiv:2309.02672","author":"Xiao Hanshen","year":"2023","unstructured":"Hanshen Xiao, Jun Wan, and Srinivas Devadas. 2023 a. Geometry of Sensitivity: Twice Sampling and Hybrid Clipping in Differential Privacy with Optimal Gaussian Noise and Application to Deep Learning. arXiv preprint arXiv:2309.02672 (2023)."},{"key":"e_1_3_2_1_43_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP46215.2023.10179409"},{"key":"e_1_3_2_1_44_1","doi-asserted-by":"publisher","DOI":"10.14778\/1453856.1453949"},{"key":"e_1_3_2_1_45_1","volume-title":"International Conference on Machine Learning. PMLR, 12208--12218","author":"Yu Da","year":"2021","unstructured":"Da Yu, Huishuai Zhang, Wei Chen, Jian Yin, and Tie-Yan Liu. 2021. Large scale private learning via low-rank reparametrization. In International Conference on Machine Learning. PMLR, 12208--12218."},{"key":"e_1_3_2_1_46_1","volume-title":"Wide network learning with differential privacy. arXiv preprint arXiv:2103.01294","author":"Zhang Huanyu","year":"2021","unstructured":"Huanyu Zhang, Ilya Mironov, and Meisam Hejazinia. 2021. Wide network learning with differential privacy. arXiv preprint arXiv:2103.01294 (2021)."},{"key":"e_1_3_2_1_47_1","volume-title":"Bypassing the Ambient Dimension: Private SGD with Gradient Subspace Identification. In International Conference on Learning Representations.","author":"Zhou Yingxue","year":"2021","unstructured":"Yingxue Zhou, Steven Wu, and Arindam Banerjee. 2021. Bypassing the Ambient Dimension: Private SGD with Gradient Subspace Identification. In International Conference on Learning Representations."},{"key":"e_1_3_2_1_48_1","volume-title":"Differentially Private SGD with Sparse Gradients. arXiv preprint arXiv:2112.00845","author":"Zhu Junyi","year":"2021","unstructured":"Junyi Zhu and Matthew Blaschko. 2021. Differentially Private SGD with Sparse Gradients. arXiv preprint arXiv:2112.00845 (2021)."},{"key":"e_1_3_2_1_49_1","volume-title":"International Conference on Machine Learning. PMLR, 7634--7642","author":"Zhu Yuqing","year":"2019","unstructured":"Yuqing Zhu and Yu-Xiang Wang. 2019. Poission subsampled r\u00e9nyi differential privacy. In International Conference on Machine Learning. PMLR, 7634--7642."}],"event":{"name":"CCS '23: ACM SIGSAC Conference on Computer and Communications Security","location":"Copenhagen Denmark","acronym":"CCS '23","sponsor":["SIGSAC ACM Special Interest Group on Security, Audit, and Control"]},"container-title":["Proceedings of the 2023 ACM SIGSAC Conference on Computer and Communications Security"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3576915.3623142","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3576915.3623142","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,8,21]],"date-time":"2025-08-21T01:44:01Z","timestamp":1755740641000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3576915.3623142"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2023,11,15]]},"references-count":49,"alternative-id":["10.1145\/3576915.3623142","10.1145\/3576915"],"URL":"https:\/\/doi.org\/10.1145\/3576915.3623142","relation":{},"subject":[],"published":{"date-parts":[[2023,11,15]]},"assertion":[{"value":"2023-11-21","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}