{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,8,21]],"date-time":"2026-08-21T13:08:23Z","timestamp":1787317703147,"version":"build-2736575974"},"publisher-location":"New York, NY, USA","reference-count":63,"publisher":"ACM","license":[{"start":{"date-parts":[[2024,12,2]],"date-time":"2024-12-02T00:00:00Z","timestamp":1733097600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2024,12,2]]},"DOI":"10.1145\/3658644.3670277","type":"proceedings-article","created":{"date-parts":[[2024,12,9]],"date-time":"2024-12-09T12:19:20Z","timestamp":1733746760000},"page":"1834-1848","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":3,"title":["Formal Privacy Proof of Data Encoding: The Possibility and Impossibility of Learnable Encryption"],"prefix":"10.1145","author":[{"ORCID":"https:\/\/orcid.org\/0000-0003-3380-4518","authenticated-orcid":false,"given":"Hanshen","family":"Xiao","sequence":"first","affiliation":[{"name":"Purdue University\/NVIDIA Research, West Lafayette, IN, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-6409-9888","authenticated-orcid":false,"given":"G. Edward","family":"Suh","sequence":"additional","affiliation":[{"name":"NVIDIA Research\/Cornell University, Westford, MA, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-8253-7714","authenticated-orcid":false,"given":"Srinivas","family":"Devadas","sequence":"additional","affiliation":[{"name":"Massachusetts Institute of Technology, Cambridge, MA, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2024,12,9]]},"reference":[{"key":"e_1_3_2_1_1_1","doi-asserted-by":"publisher","DOI":"10.1145\/1007568.1007632"},{"key":"e_1_3_2_1_2_1","doi-asserted-by":"publisher","DOI":"10.1145\/2976749.2978355"},{"key":"e_1_3_2_1_3_1","volume-title":"Privacy amplification by subsampling: Tight analyses via couplings and divergences. Advances in neural information processing systems","author":"Balle Borja","year":"2018","unstructured":"Borja Balle, Gilles Barthe, and Marco Gaboardi. 2018. Privacy amplification by subsampling: Tight analyses via couplings and divergences. Advances in neural information processing systems, Vol. 31 (2018)."},{"key":"e_1_3_2_1_4_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP46214.2022.9833677"},{"key":"e_1_3_2_1_5_1","doi-asserted-by":"publisher","DOI":"10.1109\/FOCS.2012.67"},{"key":"e_1_3_2_1_6_1","volume-title":"DP-instahide: Provably defusing poisoning and backdoor attacks with differentially private data augmentations. arXiv preprint arXiv:2103.02079","author":"Borgnia Eitan","year":"2021","unstructured":"Eitan Borgnia, Jonas Geiping, Valeriia Cherepanova, Liam Fowl, Arjun Gupta, Amin Ghiasi, Furong Huang, Micah Goldblum, and Tom Goldstein. 2021. DP-instahide: Provably defusing poisoning and backdoor attacks with differentially private data augmentations. arXiv preprint arXiv:2103.02079 (2021)."},{"key":"e_1_3_2_1_7_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-662-53641-4_24"},{"key":"e_1_3_2_1_8_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP46214.2022.9833649"},{"key":"e_1_3_2_1_9_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP40001.2021.00099"},{"key":"e_1_3_2_1_10_1","volume-title":"NeuraCrypt is not private. arXiv preprint arXiv:2108.07256","author":"Carlini Nicholas","year":"2021","unstructured":"Nicholas Carlini, Sanjam Garg, Somesh Jha, Saeed Mahloujifar, Mohammad Mahmoody, and Florian Tramer. 2021. NeuraCrypt is not private. arXiv preprint arXiv:2108.07256 (2021)."},{"key":"e_1_3_2_1_11_1","volume-title":"arXiv preprint arXiv:2011.11181","author":"Chen Sitan","year":"2020","unstructured":"Sitan Chen, Zhao Song, and Danyang Zhuo. 2020. On InstaHide, Phase Retrieval, and Sparse Matrix Factorization. arXiv preprint arXiv:2011.11181 (2020)."},{"key":"e_1_3_2_1_12_1","doi-asserted-by":"publisher","DOI":"10.1145\/2897518.2897520"},{"key":"e_1_3_2_1_13_1","volume-title":"Advances in Neural Information Processing Systems","volume":"33","author":"Daniely Amit","year":"2020","unstructured":"Amit Daniely and Gal Vardi. 2020. Hardness of learning neural networks with natural weights. Advances in Neural Information Processing Systems, Vol. 33 (2020)."},{"key":"e_1_3_2_1_14_1","volume-title":"Bert: Pre-training of deep bidirectional transformers for language understanding. arXiv preprint arXiv:1810.04805","author":"Devlin Jacob","year":"2018","unstructured":"Jacob Devlin, Ming-Wei Chang, Kenton Lee, and Kristina Toutanova. 2018. Bert: Pre-training of deep bidirectional transformers for language understanding. arXiv preprint arXiv:1810.04805 (2018)."},{"key":"e_1_3_2_1_15_1","doi-asserted-by":"publisher","DOI":"10.29012\/jpc.674"},{"key":"e_1_3_2_1_16_1","volume-title":"Differentially private diffusion models. arXiv preprint arXiv:2210.09929","author":"Dockhorn Tim","year":"2022","unstructured":"Tim Dockhorn, Tianshi Cao, Arash Vahdat, and Karsten Kreis. 2022. Differentially private diffusion models. arXiv preprint arXiv:2210.09929 (2022)."},{"key":"e_1_3_2_1_17_1","doi-asserted-by":"publisher","DOI":"10.1109\/FOCS.2013.53"},{"key":"e_1_3_2_1_18_1","volume-title":"International colloquium on automata, languages, and programming","author":"Dwork Cynthia","unstructured":"Cynthia Dwork. 2006. Differential privacy. In International colloquium on automata, languages, and programming. Springer, 1--12."},{"key":"e_1_3_2_1_19_1","doi-asserted-by":"publisher","DOI":"10.1145\/3357713.3384335"},{"key":"e_1_3_2_1_20_1","doi-asserted-by":"publisher","DOI":"10.1145\/1536414.1536440"},{"key":"e_1_3_2_1_21_1","volume-title":"International Conference on Machine Learning. PMLR, 3587--3596","author":"Goel Surbhi","year":"2020","unstructured":"Surbhi Goel, Aravind Gollakota, Zhihan Jin, Sushrut Karmalkar, and Adam Klivans. 2020. Superpolynomial lower bounds for learning one-layer neural networks using gradient descent. In International Conference on Machine Learning. PMLR, 3587--3596."},{"key":"e_1_3_2_1_22_1","volume-title":"Generative adversarial nets. Advances in neural information processing systems","author":"Goodfellow Ian","year":"2014","unstructured":"Ian Goodfellow, Jean Pouget-Abadie, Mehdi Mirza, Bing Xu, David Warde-Farley, Sherjil Ozair, Aaron Courville, and Yoshua Bengio. 2014. Generative adversarial nets. Advances in neural information processing systems, Vol. 27 (2014)."},{"key":"e_1_3_2_1_23_1","doi-asserted-by":"publisher","DOI":"10.1145\/3572832"},{"key":"e_1_3_2_1_24_1","volume-title":"Bounding Training Data Reconstruction in Private (Deep) Learning. arXiv preprint arXiv:2201.12383","author":"Guo Chuan","year":"2022","unstructured":"Chuan Guo, Brian Karrer, Kamalika Chaudhuri, and Laurens van der Maaten. 2022. Bounding Training Data Reconstruction in Private (Deep) Learning. arXiv preprint arXiv:2201.12383 (2022)."},{"key":"e_1_3_2_1_25_1","doi-asserted-by":"publisher","DOI":"10.1109\/FOCS54457.2022.00112"},{"key":"e_1_3_2_1_26_1","doi-asserted-by":"crossref","unstructured":"Awni Hannun Chuan Guo and Laurens van der Maaten. 2021. Measuring data leakage in machine-learning models with Fisher information. In Uncertainty in Artificial Intelligence. PMLR 760--770.","DOI":"10.24963\/ijcai.2022\/736"},{"key":"e_1_3_2_1_27_1","volume-title":"Bounding Training Data Reconstruction in DP-SGD. arXiv preprint arXiv:2302.07225","author":"Hayes Jamie","year":"2023","unstructured":"Jamie Hayes, Saeed Mahloujifar, and Borja Balle. 2023. Bounding Training Data Reconstruction in DP-SGD. arXiv preprint arXiv:2302.07225 (2023)."},{"key":"e_1_3_2_1_28_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.90"},{"key":"e_1_3_2_1_29_1","doi-asserted-by":"publisher","DOI":"10.14778\/3407790.3407794"},{"key":"e_1_3_2_1_30_1","volume-title":"Denoising diffusion probabilistic models. Advances in neural information processing systems","author":"Ho Jonathan","year":"2020","unstructured":"Jonathan Ho, Ajay Jain, and Pieter Abbeel. 2020. Denoising diffusion probabilistic models. Advances in neural information processing systems, Vol. 33 (2020), 6840--6851."},{"key":"e_1_3_2_1_31_1","volume-title":"International Conference on Machine Learning. PMLR, 4507--4518","author":"Huang Yangsibo","year":"2020","unstructured":"Yangsibo Huang, Zhao Song, Kai Li, and Sanjeev Arora. 2020. Instahide: Instance-hiding schemes for private distributed learning. In International Conference on Machine Learning. PMLR, 4507--4518."},{"key":"e_1_3_2_1_32_1","doi-asserted-by":"publisher","DOI":"10.1145\/258533.258656"},{"key":"e_1_3_2_1_33_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-39884-1_22"},{"key":"e_1_3_2_1_34_1","volume-title":"Proc. 47 IEEE Symp. on Foundations of Computer Science. Citeseer.","author":"Klivans Adam R","year":"2006","unstructured":"Adam R Klivans and Alex Sherstov. 2006. Cryptographic hardness results for learning intersections of halfspaces. In Proc. 47 IEEE Symp. on Foundations of Computer Science. Citeseer."},{"key":"e_1_3_2_1_35_1","doi-asserted-by":"publisher","DOI":"10.1109\/FOCS.2017.64"},{"key":"e_1_3_2_1_36_1","unstructured":"Yann LeCun Yoshua Bengio et al. 1995. Convolutional networks for images speech and time series. The handbook of brain theory and neural networks Vol. 3361 10 (1995) 1995."},{"key":"e_1_3_2_1_37_1","doi-asserted-by":"publisher","DOI":"10.1145\/2976749.2978376"},{"key":"e_1_3_2_1_38_1","doi-asserted-by":"publisher","DOI":"10.1145\/3394486.3403321"},{"key":"e_1_3_2_1_39_1","doi-asserted-by":"publisher","DOI":"10.1007\/s10115-014-0751-1"},{"key":"e_1_3_2_1_40_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-58621-8_34"},{"key":"e_1_3_2_1_41_1","volume-title":"Bounding the Invertibility of Privacy-preserving Instance Encoding using Fisher Information. arXiv preprint arXiv:2305.04146","author":"Maeng Kiwan","year":"2023","unstructured":"Kiwan Maeng, Chuan Guo, Sanjay Kariyappa, and G Edward Suh. 2023. Bounding the Invertibility of Privacy-preserving Instance Encoding using Fisher Information. arXiv preprint arXiv:2305.04146 (2023)."},{"key":"e_1_3_2_1_42_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2013.38"},{"key":"e_1_3_2_1_43_1","volume-title":"Proceedings of the Fourth Berkeley Symposium on Mathematical Statistics and Probability","volume":"4","author":"R\u00e9nyi Alfr\u00e9d","year":"1961","unstructured":"Alfr\u00e9d R\u00e9nyi. 1961. On measures of entropy and information. In Proceedings of the Fourth Berkeley Symposium on Mathematical Statistics and Probability, Volume 1: Contributions to the Theory of Statistics, Vol. 4. University of California Press, 547--562."},{"key":"e_1_3_2_1_44_1","volume-title":"Aur\u00e9lien Bellet, and Daniel Gatica-Perez.","author":"Sajadmanesh Sina","year":"2023","unstructured":"Sina Sajadmanesh, Ali Shahin Shamsabadi, Aur\u00e9lien Bellet, and Daniel Gatica-Perez. 2023. Gap: Differentially private graph neural networks with aggregation perturbation. In USENIX Security 2023--32nd USENIX Security Symposium."},{"key":"e_1_3_2_1_45_1","doi-asserted-by":"publisher","DOI":"10.5555\/3291125.3291157"},{"key":"e_1_3_2_1_46_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.41"},{"key":"e_1_3_2_1_47_1","volume-title":"Practical dynamic searchable encryption with small leakage. Cryptology ePrint Archive","author":"Stefanov Emil","year":"2013","unstructured":"Emil Stefanov, Charalampos Papamanthou, and Elaine Shi. 2013. Practical dynamic searchable encryption with small leakage. Cryptology ePrint Archive (2013)."},{"key":"e_1_3_2_1_48_1","volume-title":"Bounding membership inference. arXiv preprint arXiv:2202.12232","author":"Thudi Anvith","year":"2022","unstructured":"Anvith Thudi, Ilia Shumailov, Franziska Boenisch, and Nicolas Papernot. 2022. Bounding membership inference. arXiv preprint arXiv:2202.12232 (2022)."},{"key":"e_1_3_2_1_49_1","doi-asserted-by":"publisher","DOI":"10.1504\/IJICS.2008.016823"},{"key":"e_1_3_2_1_50_1","unstructured":"Florian Tramer and Dan Boneh. 2020. Differentially private learning needs better features (or much more data). arXiv preprint arXiv:2011.11660."},{"key":"e_1_3_2_1_51_1","doi-asserted-by":"publisher","DOI":"10.1145\/1968.1972"},{"key":"e_1_3_2_1_52_1","unstructured":"Ashish Vaswani Noam Shazeer Niki Parmar Jakob Uszkoreit Llion Jones Aidan N Gomez \u0141ukasz Kaiser and Illia Polosukhin. 2017. Attention is all you need. In Advances in neural information processing systems. 5998--6008."},{"key":"e_1_3_2_1_53_1","volume-title":"International Conference on Machine Learning. PMLR, 10081--10091","author":"Wang Di","year":"2020","unstructured":"Di Wang, Hanshen Xiao, Srinivas Devadas, and Jinhui Xu. 2020. On differentially private stochastic convex optimization with heavy-tailed data. In International Conference on Machine Learning. PMLR, 10081--10091."},{"key":"e_1_3_2_1_54_1","doi-asserted-by":"publisher","DOI":"10.1198\/jasa.2009.tm08651"},{"key":"e_1_3_2_1_55_1","volume-title":"Advances in Cryptology--CRYPTO 2023: 43rd Annual International Cryptology Conference. arxiv:2210.03458.","author":"Xiao Hanshen","unstructured":"Hanshen Xiao and Srinivas Devadas. 2023. PAC Privacy: Automatic Privacy Measurement and Control of Data Processing. In Advances in Cryptology--CRYPTO 2023: 43rd Annual International Cryptology Conference. arxiv:2210.03458."},{"key":"e_1_3_2_1_56_1","doi-asserted-by":"publisher","DOI":"10.1145\/3576915.3623142"},{"key":"e_1_3_2_1_57_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP46215.2023.10179409"},{"key":"e_1_3_2_1_58_1","doi-asserted-by":"publisher","DOI":"10.14778\/1453856.1453949"},{"key":"e_1_3_2_1_59_1","volume-title":"Ken R Duffy, Manya Ghobadi, Tommi S Jaakkola, Vinod Vaikuntanathan, Regina Barzilay, and Muriel Medard.","author":"Yala Adam","year":"2021","unstructured":"Adam Yala, Homa Esfahanizadeh, Rafael GL D' Oliveira, Ken R Duffy, Manya Ghobadi, Tommi S Jaakkola, Vinod Vaikuntanathan, Regina Barzilay, and Muriel Medard. 2021. NeuraCrypt: Hiding Private Health Data via Random Neural Networks for Public Training. arXiv preprint arXiv:2106.02484 (2021)."},{"key":"e_1_3_2_1_60_1","volume-title":"Ken R Duffy, Muriel M\u00e9dard, Tommi S Jaakkola, and Regina Barzilay.","author":"Yala Adam","year":"2022","unstructured":"Adam Yala, Victor Quach, Homa Esfahanizadeh, Rafael GL D'Oliveira, Ken R Duffy, Muriel M\u00e9dard, Tommi S Jaakkola, and Regina Barzilay. 2022. Syfer: Neural obfuscation for private data release. arXiv preprint arXiv:2201.12406 (2022)."},{"key":"e_1_3_2_1_61_1","volume-title":"2020 USENIX Annual Technical Conference (USENIXATC 20)","author":"Zhang Chengliang","year":"2020","unstructured":"Chengliang Zhang, Suyi Li, Junzhe Xia, Wei Wang, Feng Yan, and Yang Liu. 2020. Batchcrypt: Efficient homomorphic encryption for cross-silo federated learning. In 2020 USENIX Annual Technical Conference (USENIXATC 20). 493--506."},{"key":"e_1_3_2_1_62_1","volume-title":"International Conference on Learning Representations.","author":"Zhang Hongyi","year":"2018","unstructured":"Hongyi Zhang, Moustapha Cisse, Yann N Dauphin, and David Lopez-Paz. 2018. mixup: Beyond Empirical Risk Minimization. In International Conference on Learning Representations."},{"key":"e_1_3_2_1_63_1","volume-title":"Sparse matrix masking-based non-interactive verifiable (outsourced) computation, revisited","author":"Zhao Liang","year":"2018","unstructured":"Liang Zhao and Liqun Chen. 2018. Sparse matrix masking-based non-interactive verifiable (outsourced) computation, revisited. IEEE transactions on dependable and secure computing, Vol. 17, 6 (2018), 1188--1206."}],"event":{"name":"CCS '24: ACM SIGSAC Conference on Computer and Communications Security","location":"Salt Lake City UT USA","acronym":"CCS '24","sponsor":["SIGSAC ACM Special Interest Group on Security, Audit, and Control"]},"container-title":["Proceedings of the 2024 on ACM SIGSAC Conference on Computer and Communications Security"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3658644.3670277","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3658644.3670277","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,8,22]],"date-time":"2025-08-22T06:01:11Z","timestamp":1755842471000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3658644.3670277"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024,12,2]]},"references-count":63,"alternative-id":["10.1145\/3658644.3670277","10.1145\/3658644"],"URL":"https:\/\/doi.org\/10.1145\/3658644.3670277","relation":{},"subject":[],"published":{"date-parts":[[2024,12,2]]},"assertion":[{"value":"2024-12-09","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}