{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,6,18]],"date-time":"2025-06-18T04:09:27Z","timestamp":1750219767629,"version":"3.41.0"},"publisher-location":"New York, NY, USA","reference-count":39,"publisher":"ACM","license":[{"start":{"date-parts":[[2023,6,12]],"date-time":"2023-06-12T00:00:00Z","timestamp":1686528000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"DOI":"10.13039\/100000001","name":"NSF (National Science Foundation)","doi-asserted-by":"publisher","award":["1845852,2040880,1900750"],"award-info":[{"award-number":["1845852,2040880,1900750"]}],"id":[{"id":"10.13039\/100000001","id-type":"DOI","asserted-by":"publisher"}]},{"name":"SNSF (Swiss National Science Foundation)","award":["200021-188824"],"award-info":[{"award-number":["200021-188824"]}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2023,6,12]]},"DOI":"10.1145\/3593013.3594103","type":"proceedings-article","created":{"date-parts":[[2023,6,12]],"date-time":"2023-06-12T14:40:46Z","timestamp":1686580846000},"page":"1609-1623","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":8,"title":["Arbitrary Decisions are a Hidden Cost of Differentially Private Training"],"prefix":"10.1145","author":[{"ORCID":"https:\/\/orcid.org\/0000-0001-5923-3931","authenticated-orcid":false,"given":"Bogdan","family":"Kulynych","sequence":"first","affiliation":[{"name":"SPRING Lab, EPFL, Switzerland"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-8084-3929","authenticated-orcid":false,"given":"Hsiang","family":"Hsu","sequence":"additional","affiliation":[{"name":"Harvard University, USA"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-2374-2248","authenticated-orcid":false,"given":"Carmela","family":"Troncoso","sequence":"additional","affiliation":[{"name":"SPRING Lab, EPFL, Switzerland"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-7493-1428","authenticated-orcid":false,"given":"Flavio P.","family":"Calmon","sequence":"additional","affiliation":[{"name":"Harvard University, USA"}]}],"member":"320","published-online":{"date-parts":[[2023,6,12]]},"reference":[{"key":"e_1_3_2_1_1_1","doi-asserted-by":"publisher","DOI":"10.1145\/2976749.2978318"},{"key":"e_1_3_2_1_2_1","volume-title":"Exponentially many local minima for single neurons. Advances in neural information processing systems 8","author":"Auer Peter","year":"1995","unstructured":"Peter Auer, Mark Herbster, and Manfred KK Warmuth. 1995. Exponentially many local minima for single neurons. Advances in neural information processing systems 8 (1995)."},{"key":"e_1_3_2_1_3_1","volume-title":"Differential privacy has disparate impact on model accuracy. Advances in neural information processing systems 32","author":"Bagdasaryan Eugene","year":"2019","unstructured":"Eugene Bagdasaryan, Omid Poursaeed, and Vitaly Shmatikov. 2019. Differential privacy has disparate impact on model accuracy. Advances in neural information processing systems 32 (2019)."},{"key":"e_1_3_2_1_4_1","volume-title":"Selective Ensembles for Consistent Predictions. In International Conference on Learning Representations.","author":"Black Emily","year":"2021","unstructured":"Emily Black, Klas Leino, and Matt Fredrikson. 2021. Selective Ensembles for Consistent Predictions. In International Conference on Learning Representations."},{"key":"e_1_3_2_1_5_1","doi-asserted-by":"publisher","DOI":"10.1145\/3531146.3533149"},{"key":"e_1_3_2_1_6_1","volume-title":"Statistical modeling: The two cultures (with comments and a rejoinder by the author). Statistical science 16, 3","author":"Breiman Leo","year":"2001","unstructured":"Leo Breiman. 2001. Statistical modeling: The two cultures (with comments and a rejoinder by the author). Statistical science 16, 3 (2001)."},{"key":"e_1_3_2_1_7_1","volume-title":"Differentially private empirical risk minimization.Journal of Machine Learning Research 12, 3","author":"Chaudhuri Kamalika","year":"2011","unstructured":"Kamalika Chaudhuri, Claire Monteleoni, and Anand D Sarwate. 2011. Differentially private empirical risk minimization.Journal of Machine Learning Research 12, 3 (2011)."},{"key":"e_1_3_2_1_8_1","volume-title":"The scored society: Due process for automated predictions. Wash. L. Rev. 89","author":"Citron Danielle Keats","year":"2014","unstructured":"Danielle Keats Citron and Frank Pasquale. 2014. The scored society: Due process for automated predictions. Wash. L. Rev. 89 (2014)."},{"key":"e_1_3_2_1_9_1","volume-title":"International Conference on Machine Learning. PMLR.","author":"Coston Amanda","year":"2021","unstructured":"Amanda Coston, Ashesh Rambachan, and Alexandra Chouldechova. 2021. Characterizing fairness over the set of good models under selective labels. In International Conference on Machine Learning. PMLR."},{"key":"e_1_3_2_1_10_1","volume-title":"The Algorithmic Leviathan: Arbitrariness, Fairness, and Opportunity in Algorithmic Decision-Making Systems. Canadian Journal of Philosophy","author":"Creel Kathleen","year":"2022","unstructured":"Kathleen Creel and Deborah Hellman. 2022. The Algorithmic Leviathan: Arbitrariness, Fairness, and Opportunity in Algorithmic Decision-Making Systems. Canadian Journal of Philosophy (2022)."},{"key":"e_1_3_2_1_11_1","doi-asserted-by":"publisher","DOI":"10.1145\/3314183.3323847"},{"key":"e_1_3_2_1_12_1","unstructured":"Dheeru Dua and Casey Graff. 2017. UCI Machine Learning Repository. http:\/\/archive.ics.uci.edu\/ml"},{"key":"e_1_3_2_1_13_1","doi-asserted-by":"publisher","DOI":"10.1145\/2090236.2090255"},{"volume-title":"Theory of cryptography conference","author":"Dwork Cynthia","key":"e_1_3_2_1_14_1","unstructured":"Cynthia Dwork, Frank McSherry, Kobbi Nissim, and Adam Smith. 2006. Calibrating noise to sensitivity in private data analysis. In Theory of cryptography conference. Springer."},{"key":"e_1_3_2_1_15_1","doi-asserted-by":"crossref","unstructured":"Cynthia Dwork Aaron Roth 2014. The algorithmic foundations of differential privacy.Found. Trends Theor. Comput. Sci. (2014).","DOI":"10.1561\/9781601988195"},{"key":"e_1_3_2_1_16_1","volume-title":"Underspecification presents challenges for credibility in modern machine learning. Journal of Machine Learning Research","author":"D\u2019Amour Alexander","year":"2020","unstructured":"Alexander D\u2019Amour, Katherine Heller, Dan Moldovan, Ben Adlam, Babak Alipanahi, Alex Beutel, Christina Chen, Jonathan Deaton, Jacob Eisenstein, Matthew D Hoffman, 2020. Underspecification presents challenges for credibility in modern machine learning. Journal of Machine Learning Research (2020)."},{"key":"e_1_3_2_1_17_1","volume-title":"All Models are Wrong, but Many are Useful: Learning a Variable\u2019s Importance by Studying an Entire Class of Prediction Models Simultaneously.Journal of Machine Learning Research 20, 177","author":"Fisher Aaron","year":"2019","unstructured":"Aaron Fisher, Cynthia Rudin, and Francesca Dominici. 2019. All Models are Wrong, but Many are Useful: Learning a Variable\u2019s Importance by Studying an Entire Class of Prediction Models Simultaneously.Journal of Machine Learning Research 20, 177 (2019)."},{"key":"e_1_3_2_1_18_1","volume-title":"Robin Hood and Matthew Effects: Differential Privacy Has Disparate Impact on Synthetic Data. In International Conference on Machine Learning. PMLR.","author":"Ganev Georgi","year":"2022","unstructured":"Georgi Ganev, Bristena Oprisanu, and Emiliano De Cristofaro. 2022. Robin Hood and Matthew Effects: Differential Privacy Has Disparate Impact on Synthetic Data. In International Conference on Machine Learning. PMLR."},{"key":"e_1_3_2_1_19_1","volume-title":"Mark Wiebe, Pearu Peterson, Pierre G\u00e9rard-Marchant, Kevin Sheppard, Tyler Reddy, Warren Weckesser, Hameer Abbasi, Christoph Gohlke, and Travis E. Oliphant.","author":"Harris Charles R.","year":"2020","unstructured":"Charles R. Harris, K. Jarrod Millman, St\u00e9fan J. van der Walt, Ralf Gommers, Pauli Virtanen, David Cournapeau, Eric Wieser, Julian Taylor, Sebastian Berg, Nathaniel J. Smith, Robert Kern, Matti Picus, Stephan Hoyer, Marten H. van Kerkwijk, Matthew Brett, Allan Haldane, Jaime Fern\u00e1ndez del R\u00edo, Mark Wiebe, Pearu Peterson, Pierre G\u00e9rard-Marchant, Kevin Sheppard, Tyler Reddy, Warren Weckesser, Hameer Abbasi, Christoph Gohlke, and Travis E. Oliphant. 2020. Array programming with NumPy. Nature (2020)."},{"key":"e_1_3_2_1_20_1","volume-title":"P\u00f3l Mac Aonghusa, and Killian Levacher","author":"Holohan Naoise","year":"2019","unstructured":"Naoise Holohan, Stefano Braghin, P\u00f3l Mac Aonghusa, and Killian Levacher. 2019. Diffprivlib: the IBM differential privacy library. arXiv preprint arXiv:1907.02444 (2019)."},{"key":"e_1_3_2_1_21_1","volume-title":"Rashomon Capacity: A Metric for Predictive Multiplicity in Probabilistic Classification. Advances in Neural Information Processing Systems","author":"Hsu Hsiang","year":"2022","unstructured":"Hsiang Hsu and Flavio du Pin Calmon. 2022. Rashomon Capacity: A Metric for Predictive Multiplicity in Probabilistic Classification. Advances in Neural Information Processing Systems (2022)."},{"key":"e_1_3_2_1_22_1","volume-title":"USENIX Security Symposium.","author":"Jayaraman Bargav","year":"2019","unstructured":"Bargav Jayaraman and David Evans. 2019. Evaluating differentially private machine learning in practice. In USENIX Security Symposium."},{"key":"e_1_3_2_1_23_1","volume-title":"Learning multiple layers of features from tiny images. Technical report","author":"Krizhevsky Alex","year":"2009","unstructured":"Alex Krizhevsky, Geoffrey Hinton, 2009. Learning multiple layers of features from tiny images. Technical report (2009)."},{"key":"e_1_3_2_1_24_1","volume-title":"International Conference on Machine Learning. PMLR.","author":"Marx Charles","year":"2020","unstructured":"Charles Marx, Flavio Calmon, and Berk Ustun. 2020. Predictive multiplicity in classification. In International Conference on Machine Learning. PMLR."},{"key":"e_1_3_2_1_25_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2015.7298904"},{"key":"e_1_3_2_1_26_1","doi-asserted-by":"publisher","unstructured":"The pandas development team. 2020. pandas-dev\/pandas: Pandas. https:\/\/doi.org\/10.5281\/zenodo.3509134","DOI":"10.5281\/zenodo.3509134"},{"key":"e_1_3_2_1_27_1","volume-title":"International Conference on Learning Representations.","author":"Papernot Nicolas","year":"2022","unstructured":"Nicolas Papernot and Thomas Steinke. 2022. Hyperparameter tuning with Renyi differential privacy. In International Conference on Learning Representations."},{"key":"e_1_3_2_1_28_1","volume-title":"Advances in Neural Information Processing Systems 32: Annual Conference on Neural Information Processing Systems (NeurIPS).","author":"Paszke Adam","year":"2019","unstructured":"Adam Paszke, Sam Gross, Francisco Massa, Adam Lerer, James Bradbury, Gregory Chanan, Trevor Killeen, Zeming Lin, Natalia Gimelshein, Luca Antiga, 2019. Pytorch: An imperative style, high-performance deep learning library. In Advances in Neural Information Processing Systems 32: Annual Conference on Neural Information Processing Systems (NeurIPS)."},{"key":"e_1_3_2_1_29_1","doi-asserted-by":"publisher","DOI":"10.29012\/jpc.v4i1.612"},{"key":"e_1_3_2_1_30_1","unstructured":"Amartya Sanyal Yaxi Hu and Fanny Yang. 2022. How unfair is private learning?. In Uncertainty in Artificial Intelligence. PMLR."},{"key":"e_1_3_2_1_31_1","doi-asserted-by":"publisher","DOI":"10.1145\/3531146.3533232"},{"key":"e_1_3_2_1_32_1","volume-title":"International Conference on Learning Representations.","author":"Tramer Florian","year":"2021","unstructured":"Florian Tramer and Dan Boneh. 2021. Differentially Private Learning Needs Better Features (or Much More Data). In International Conference on Learning Representations."},{"key":"e_1_3_2_1_33_1","volume-title":"Fundamental Algorithms for Scientific Computing in Python. Nature Methods","author":"Virtanen Pauli","year":"2020","unstructured":"Pauli Virtanen, Ralf Gommers, Travis E. Oliphant, Matt Haberland, Tyler Reddy, David Cournapeau, Evgeni Burovski, Pearu Peterson, Warren Weckesser, Jonathan Bright, St\u00e9fan J. van der Walt, Matthew Brett, Joshua Wilson, K. Jarrod Millman, Nikolay Mayorov, Andrew R. J. Nelson, Eric Jones, Robert Kern, Eric Larson, C J Carey, \u0130lhan Polat, Yu Feng, Eric W. Moore, Jake VanderPlas, Denis Laxalde, Josef Perktold, Robert Cimrman, Ian Henriksen, E. A. Quintero, Charles R. Harris, Anne M. Archibald, Ant\u00f4nio H. Ribeiro, Fabian Pedregosa, Paul van Mulbregt, and SciPy 1.0 Contributors. 2020. SciPy 1.0: Fundamental Algorithms for Scientific Computing in Python. Nature Methods (2020)."},{"key":"e_1_3_2_1_34_1","volume-title":"Generalization Bounds for Noisy Iterative Algorithms Using Properties of Additive Noise Channels. Journal of Machine Learning Research 24","author":"Wang Hao","year":"2023","unstructured":"Hao Wang, Rui Gao, and Flavio P Calmon. 2023. Generalization Bounds for Noisy Iterative Algorithms Using Properties of Additive Noise Channels. Journal of Machine Learning Research 24 (2023)."},{"key":"e_1_3_2_1_35_1","doi-asserted-by":"publisher","DOI":"10.21105\/joss.03021"},{"key":"e_1_3_2_1_36_1","doi-asserted-by":"crossref","unstructured":"Jamelle Watson-Daniels David C Parkes and Berk Ustun. 2023. Predictive Multiplicity in Probabilistic Classification. In AAAI.","DOI":"10.1609\/aaai.v37i9.26227"},{"key":"e_1_3_2_1_37_1","volume-title":"Differential privacy: A primer for a non-technical audience. Vand. J. Ent. & Tech. L. 21","author":"Wood Alexandra","year":"2018","unstructured":"Alexandra Wood, Micah Altman, Aaron Bembenek, Mark Bun, Marco Gaboardi, James Honaker, Kobbi Nissim, David R O\u2019Brien, Thomas Steinke, and Salil Vadhan. 2018. Differential privacy: A primer for a non-technical audience. Vand. J. Ent. & Tech. L. 21 (2018)."},{"key":"e_1_3_2_1_38_1","doi-asserted-by":"publisher","DOI":"10.1145\/3035918.3064047"},{"key":"e_1_3_2_1_39_1","volume-title":"Opacus: User-Friendly Differential Privacy Library in PyTorch. arXiv preprint arXiv:2109.12298","author":"Yousefpour Ashkan","year":"2021","unstructured":"Ashkan Yousefpour, Igor Shilov, Alexandre Sablayrolles, Davide Testuggine, Karthik Prasad, Mani Malek, John Nguyen, Sayan Ghosh, Akash Bharadwaj, Jessica Zhao, Graham Cormode, and Ilya Mironov. 2021. Opacus: User-Friendly Differential Privacy Library in PyTorch. arXiv preprint arXiv:2109.12298 (2021)."}],"event":{"name":"FAccT '23: the 2023 ACM Conference on Fairness, Accountability, and Transparency","acronym":"FAccT '23","location":"Chicago IL USA"},"container-title":["2023 ACM Conference on Fairness Accountability and Transparency"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3593013.3594103","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3593013.3594103","content-type":"application\/pdf","content-version":"vor","intended-application":"syndication"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3593013.3594103","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,17]],"date-time":"2025-06-17T16:37:19Z","timestamp":1750178239000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3593013.3594103"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2023,6,12]]},"references-count":39,"alternative-id":["10.1145\/3593013.3594103","10.1145\/3593013"],"URL":"https:\/\/doi.org\/10.1145\/3593013.3594103","relation":{},"subject":[],"published":{"date-parts":[[2023,6,12]]},"assertion":[{"value":"2023-06-12","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}