{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,12,20]],"date-time":"2025-12-20T22:13:02Z","timestamp":1766268782156,"version":"3.44.0"},"publisher-location":"New York, NY, USA","reference-count":63,"publisher":"ACM","license":[{"start":{"date-parts":[[2025,3,30]],"date-time":"2025-03-30T00:00:00Z","timestamp":1743292800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"funder":[{"DOI":"10.13039\/501100006374","name":"NSF (National Science Foundation)","doi-asserted-by":"publisher","award":["NSF EEC-2133516, NSF CNS2106530, NSF CNS-2104292, NSERC RGPIN-2022-04469, NSF CNS-2106184"],"award-info":[{"award-number":["NSF EEC-2133516, NSF CNS2106530, NSF CNS-2104292, NSERC RGPIN-2022-04469, NSF CNS-2106184"]}],"id":[{"id":"10.13039\/501100006374","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2025,3,30]]},"DOI":"10.1145\/3689031.3696096","type":"proceedings-article","created":{"date-parts":[[2025,3,26]],"date-time":"2025-03-26T06:25:20Z","timestamp":1742970320000},"page":"1194-1209","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":2,"title":["DPack: Efficiency-Oriented Privacy Budget Scheduling"],"prefix":"10.1145","author":[{"ORCID":"https:\/\/orcid.org\/0000-0003-2815-5357","authenticated-orcid":false,"given":"Pierre","family":"Tholoniat","sequence":"first","affiliation":[{"name":"Columbia University, New York City, NY, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0009-0006-2148-9767","authenticated-orcid":false,"given":"Kelly","family":"Kostopoulou","sequence":"additional","affiliation":[{"name":"Columbia University, New York City, NY, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-0884-6740","authenticated-orcid":false,"given":"Mosharaf","family":"Chowdhury","sequence":"additional","affiliation":[{"name":"University of Michigan, Ann Arbor, MI, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0009-0007-4046-2022","authenticated-orcid":false,"given":"Asaf","family":"Cidon","sequence":"additional","affiliation":[{"name":"Columbia University, New York City, NY, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0009-0004-5209-9206","authenticated-orcid":false,"given":"Roxana","family":"Geambasu","sequence":"additional","affiliation":[{"name":"Columbia University, New York City, NY, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-9828-1688","authenticated-orcid":false,"given":"Mathias","family":"L\u00e9cuyer","sequence":"additional","affiliation":[{"name":"University of British Columbia, Vancouver, BC, Canada"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0009-0000-2277-6545","authenticated-orcid":false,"given":"Junfeng","family":"Yang","sequence":"additional","affiliation":[{"name":"Columbia University, New York City, NY, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2025,3,30]]},"reference":[{"key":"e_1_3_2_1_1_1","doi-asserted-by":"publisher","DOI":"10.1145\/2976749.2978318"},{"key":"e_1_3_2_1_2_1","doi-asserted-by":"publisher","DOI":"10.1145\/2488608.2488730"},{"key":"e_1_3_2_1_3_1","doi-asserted-by":"publisher","DOI":"10.1145\/2976749.2978355"},{"key":"e_1_3_2_1_4_1","doi-asserted-by":"publisher","DOI":"10.1145\/1265530.1265569"},{"key":"e_1_3_2_1_5_1","volume-title":"Dec.","author":"Berghel S.","year":"2022","unstructured":"S. Berghel, P. Bohannon, D. Desfontaines, C. Estes, S. Haney, L. Hartman, M. Hay, A. Machanavajjhala, T. Magerlein, G. Miklau, A. Pai, W. Sexton, and R. Shrestha. Tumult Analytics: a robust, easy-to-use, scalable, and expressive framework for differential privacy. arXiv, Dec. 2022."},{"key":"e_1_3_2_1_6_1","first-page":"267","volume-title":"28th USENIX Security Symposium, USENIX Security 2019","author":"Carlini N.","year":"2019","unstructured":"N. Carlini, C. Liu, \u00da. Erlingsson, J. Kos, and D. Song. The secret sharer: Evaluating and testing unintended memorization in neural networks. In N. Heninger and P. Traynor, editors, 28th USENIX Security Symposium, USENIX Security 2019, Santa Clara, CA, USA, August 14-16, 2019, pages 267--284. USENIX Association, 2019."},{"key":"e_1_3_2_1_7_1","first-page":"2633","volume-title":"30th USENIX Security Symposium, USENIX Security 2021","author":"Carlini N.","year":"2021","unstructured":"N. Carlini, F. Tram\u00e8r, E. Wallace, M. Jagielski, A. Herbert-Voss, K. Lee, A. Roberts, T. B. Brown, D. Song, \u00da. Erlingsson, A. Oprea, and C. Raffel. Extracting training data from large language models. In M. Bailey and R. Greenstadt, editors, 30th USENIX Security Symposium, USENIX Security 2021, August 11-13, 2021, pages 2633--2650. USENIX Association, 2021."},{"key":"e_1_3_2_1_8_1","first-page":"407","volume-title":"13th USENIX Symposium on Networked Systems Design and Implementation (NSDI 16)","author":"Chowdhury M.","year":"2016","unstructured":"M. Chowdhury, Z. Liu, A. Ghodsi, and I. Stoica. HUG: Multi-resource fairness for correlated and elastic demands. In 13th USENIX Symposium on Networked Systems Design and Implementation (NSDI 16), pages 407--424, Santa Clara, CA, Mar. 2016. USENIX Association."},{"key":"e_1_3_2_1_9_1","volume-title":"Differential privacy for growing databases","author":"Cummings R.","year":"2018","unstructured":"R. Cummings, S. Krehbiel, K. A. Lai, and U. Tantipongpipat. Differential privacy for growing databases. 2018."},{"key":"e_1_3_2_1_10_1","doi-asserted-by":"publisher","DOI":"10.1145\/773153.773173"},{"key":"e_1_3_2_1_11_1","doi-asserted-by":"publisher","DOI":"10.1007\/11681878_14"},{"key":"e_1_3_2_1_12_1","doi-asserted-by":"publisher","DOI":"10.1146\/annurev-statistics-060116-054123"},{"key":"e_1_3_2_1_13_1","doi-asserted-by":"publisher","DOI":"10.1109\/FOCS.2015.46"},{"key":"e_1_3_2_1_14_1","unstructured":"Facebook. Opacus. https:\/\/opacus.ai\/. Accessed: 2020-11-10."},{"key":"e_1_3_2_1_15_1","volume-title":"Thirty-Fifth Conference on Neural Information Processing Systems","author":"Feldman V.","year":"2021","unstructured":"V. Feldman and T. Zrnic. Individual privacy accounting via a renyi filter. In Thirty-Fifth Conference on Neural Information Processing Systems, 2021."},{"key":"e_1_3_2_1_16_1","volume-title":"Proceedings of the 8th USENIX Symposium on Networked Systems Design and Implementation, NSDI 2011","author":"Ghodsi A.","year":"2011","unstructured":"A. Ghodsi, M. Zaharia, B. Hindman, A. Konwinski, S. Shenker, and I. Stoica. Dominant resource fairness: Fair allocation of multiple resource types. In D. G. Andersen and S. Ratnasamy, editors, Proceedings of the 8th USENIX Symposium on Networked Systems Design and Implementation, NSDI 2011, Boston, MA, USA, March 30-April 1, 2011. USENIX Association, 2011."},{"key":"e_1_3_2_1_17_1","unstructured":"Google. Differential Privacy. https:\/\/github.com\/google\/differential-privacy\/. Accessed: 2020-11-10."},{"key":"e_1_3_2_1_18_1","unstructured":"Google. TensorFlow Privacy. https:\/\/github.com\/tensorflow\/privacy. Accessed: 2020-11-10."},{"key":"e_1_3_2_1_19_1","volume-title":"https:\/\/github.com\/google\/differential-privacy\/tree\/main\/python\/dp_accounting","author":"Privacy Google Differential","year":"2022","unstructured":"Google Differential Privacy. https:\/\/github.com\/google\/differential-privacy\/tree\/main\/python\/dp_accounting, 2022."},{"key":"e_1_3_2_1_20_1","volume-title":"Goop homepage. https:\/\/github.com\/mit-drl\/goop\/","author":"Go Goop","year":"2021","unstructured":"Goop generalized mixed integer optimization in Go. Goop homepage. https:\/\/github.com\/mit-drl\/goop\/, 2021."},{"key":"e_1_3_2_1_21_1","doi-asserted-by":"publisher","DOI":"10.1145\/2619239.2626334"},{"key":"e_1_3_2_1_22_1","first-page":"65","volume-title":"12th USENIX Symposium on Operating Systems Design and Implementation (OSDI 16)","author":"Grandl R.","year":"2016","unstructured":"R. Grandl, M. Chowdhury, A. Akella, and G. Ananthanarayanan. Altruistic scheduling in multi-resource clusters. In 12th USENIX Symposium on Operating Systems Design and Implementation (OSDI 16), pages 65--80, Savannah, GA, Nov. 2016. USENIX Association."},{"key":"e_1_3_2_1_23_1","first-page":"81","volume-title":"Proceedings of the 12th USENIX Conference on Operating Systems Design and Implementation, OSDI'16","author":"Grandl R.","year":"2016","unstructured":"R. Grandl, S. Kandula, S. Rao, A. Akella, and J. Kulkarni. Graphene: Packing and dependency-aware scheduling for data-parallel clusters. In Proceedings of the 12th USENIX Conference on Operating Systems Design and Implementation, OSDI'16, page 81--97, USA, 2016. USENIX Association."},{"key":"e_1_3_2_1_24_1","volume-title":"Dp-xgboost: Private machine learning at scale. CoRR, abs\/2110.12770","author":"Grislain N.","year":"2021","unstructured":"N. Grislain and J. Gonzalvez. Dp-xgboost: Private machine learning at scale. CoRR, abs\/2110.12770, 2021."},{"key":"e_1_3_2_1_25_1","first-page":"485","volume-title":"USENIX NSDI","author":"Gu J.","year":"2019","unstructured":"J. Gu, M. Chowdhury, K. G. Shin, Y. Zhu, M. Jeon, J. Qian, H. H. Liu, and C. Guo. Tiresias: A GPU cluster manager for distributed deep learning. In USENIX NSDI, pages 485--500, 2019."},{"key":"e_1_3_2_1_26_1","volume-title":"Gurobi Optimization homepage. www.gurobi.com\/","author":"Optimization Gurobi","year":"2021","unstructured":"Gurobi Optimization. Gurobi Optimization homepage. www.gurobi.com\/, 2021."},{"key":"e_1_3_2_1_27_1","first-page":"719","volume-title":"Proceedings of the 11th International Conference on Autonomous Agents and Multiagent Systems -","volume":"2","author":"Gutman A.","year":"2012","unstructured":"A. Gutman and N. Nisan. Fair allocation without trade. In Proceedings of the 11th International Conference on Autonomous Agents and Multiagent Systems - Volume 2, AAMAS '12, page 719--728, Richland, SC, 2012. International Foundation for Autonomous Agents and Multiagent Systems."},{"key":"e_1_3_2_1_28_1","doi-asserted-by":"publisher","DOI":"10.1109\/FOCS.2010.85"},{"key":"e_1_3_2_1_29_1","doi-asserted-by":"publisher","DOI":"10.1371\/journal.pgen.1000167"},{"key":"e_1_3_2_1_30_1","unstructured":"IBM. Diffprivlib. https:\/\/github.com\/IBM\/differential-privacy-library. Accessed: 2020-12-7."},{"key":"e_1_3_2_1_31_1","volume-title":"Proc. of USENIX Security","author":"Jayaraman B.","year":"2019","unstructured":"B. Jayaraman and D. Evans. Evaluating differentially private machine learning in practice. In Proc. of USENIX Security, 2019."},{"issue":"6","key":"e_1_3_2_1_32_1","first-page":"1785","volume":"21","author":"Joe-Wong C.","year":"2013","unstructured":"C. Joe-Wong, S. Sen, T. Lan, and M. Chiang. Multiresource allocation: Fairness-efficiency tradeoffs in a unifying framework. IEEE\/ACM Transactions on Networking, 21(6):1785--1798, 2013.","journal-title":"Multiresource allocation: Fairness-efficiency tradeoffs in a unifying framework. IEEE\/ACM Transactions on Networking"},{"key":"e_1_3_2_1_33_1","series-title":"Proceedings of Machine Learning Research","first-page":"5213","volume-title":"Proceedings of the 38th International Conference on Machine Learning, ICML","author":"Kairouz P.","year":"2021","unstructured":"P. Kairouz, B. McMahan, S. Song, O. Thakkar, A. Thakurta, and Z. Xu. Practical and private (deep) learning without sampling or shuffling. In M. Meila and T. Zhang, editors, Proceedings of the 38th International Conference on Machine Learning, ICML 2021, 18--24 July 2021, Virtual Event, volume 139 of Proceedings of Machine Learning Research, pages 5213--5225. PMLR, 2021."},{"key":"e_1_3_2_1_34_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-540-24777-7"},{"key":"e_1_3_2_1_35_1","doi-asserted-by":"publisher","DOI":"10.1147\/rd.215.0443"},{"key":"e_1_3_2_1_36_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP54263.2024.00122"},{"key":"e_1_3_2_1_37_1","first-page":"v2","author":"L\u00e9cuyer M.","year":"2021","unstructured":"M. L\u00e9cuyer. Practical Privacy Filters and Odometers with R\u00e9nyi Differential Privacy and Applications to Differentially Private Deep Learning. In arXiv, v2, 2021.","journal-title":"Xiv"},{"key":"e_1_3_2_1_38_1","doi-asserted-by":"publisher","DOI":"10.1145\/3341301.3359639"},{"key":"e_1_3_2_1_39_1","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v34i01.5422"},{"key":"e_1_3_2_1_40_1","first-page":"55","volume-title":"15th USENIX Symposium on Operating Systems Design and Implementation (OSDI 21)","author":"Luo T.","year":"2021","unstructured":"T. Luo, M. Pan, P. Tholoniat, A. Cidon, R. Geambasu, and M. L\u00e9cuyer. Privacy budget scheduling. In 15th USENIX Symposium on Operating Systems Design and Implementation (OSDI 21), pages 55--74. USENIX Association, July 2021."},{"key":"e_1_3_2_1_41_1","volume-title":"Privacy Resource Scheduling (extended version). https:\/\/github.com\/columbia\/privatekube","author":"Luo T.","year":"2021","unstructured":"T. Luo, M. Pan, P. Tholoniat, A. Cidon, R. Geambasu, and M. L\u00e9cuyer. Privacy Resource Scheduling (extended version). https:\/\/github.com\/columbia\/privatekube, 2021."},{"key":"e_1_3_2_1_42_1","volume-title":"Learning differentially private recurrent language models","author":"McMahan H. B.","year":"2018","unstructured":"H. B. McMahan, D. Ramage, K. Talwar, and L. Zhang. Learning differentially private recurrent language models. 2018."},{"key":"e_1_3_2_1_43_1","volume-title":"An extensible platform for privacy-preserving data analysis","author":"McSherry F. D.","year":"2009","unstructured":"F. D. McSherry. Privacy integrated queries: An extensible platform for privacy-preserving data analysis. 2009."},{"key":"e_1_3_2_1_44_1","volume-title":"R\u00e9nyi Differential Privacy. In Computer Security Foundations Symposium (CSF)","author":"Mironov I.","year":"2017","unstructured":"I. Mironov. R\u00e9nyi Differential Privacy. In Computer Security Foundations Symposium (CSF), 2017."},{"key":"e_1_3_2_1_45_1","doi-asserted-by":"publisher","DOI":"10.1145\/2213836.2213876"},{"key":"e_1_3_2_1_46_1","first-page":"157","volume-title":"Theory of Cryptography","author":"Murtagh J.","year":"2015","unstructured":"J. Murtagh and S. Vadhan. The Complexity of Computing the Optimal Composition of Differential Privacy. In Theory of Cryptography, pages 157--175. Springer, Berlin, Germany, Dec. 2015."},{"key":"e_1_3_2_1_47_1","volume-title":"Scalable extraction of training data from (production) language models","author":"Nasr M.","year":"2023","unstructured":"M. Nasr, N. Carlini, J. Hayase, M. Jagielski, A. F. Cooper, D. Ippolito, C. A. Choquette-Choo, E. Wallace, F. Tram\u00e8r, and K. Lee. Scalable extraction of training data from (production) language models, 2023."},{"key":"e_1_3_2_1_48_1","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/D19-1018"},{"key":"e_1_3_2_1_49_1","unstructured":"OpenDP. https:\/\/smartnoise.org\/. Accessed: 2020-11-10."},{"key":"e_1_3_2_1_50_1","volume-title":"Heuristics for vector bin packing. Technical report","author":"Panigrahy R.","year":"2011","unstructured":"R. Panigrahy, K. Talwar, L. Uyeda, and U. Wieder. Heuristics for vector bin packing. Technical report, 2011."},{"issue":"1","key":"e_1_3_2_1_51_1","first-page":"1","volume":"3","author":"Parkes D. C.","year":"2015","unstructured":"D. C. Parkes, A. D. Procaccia, and N. Shah. Beyond dominant resource fairness: Extensions, limitations, and indivisibilities. ACM Transactions on Economics and Computation (TEAC), 3(1):1--22, 2015.","journal-title":"Beyond dominant resource fairness: Extensions, limitations, and indivisibilities. ACM Transactions on Economics and Computation (TEAC)"},{"key":"e_1_3_2_1_52_1","doi-asserted-by":"publisher","DOI":"10.14778\/2732296.2732300"},{"key":"e_1_3_2_1_53_1","volume-title":"Privacy odometers and filters: Pay-as-you-go composition","author":"Rogers R. M.","year":"2016","unstructured":"R. M. Rogers, A. Roth, J. Ullman, and S. Vadhan. Privacy odometers and filters: Pay-as-you-go composition. 2016."},{"key":"e_1_3_2_1_54_1","volume-title":"Proc. of the USENIX Symposium on Networked Systems Design and Implementation (NSDI)","author":"Roy I.","year":"2010","unstructured":"I. Roy, S. T. Setty, A. Kilzer, V. Shmatikov, and E. Witchel. Airavat: Security and privacy for MapReduce. In Proc. of the USENIX Symposium on Networked Systems Design and Implementation (NSDI), 2010."},{"key":"e_1_3_2_1_55_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.41"},{"volume-title":"Discrete event simulation for Python. https:\/\/simpy.readthedocs.io\/en\/latest\/index.html","year":"2020","key":"e_1_3_2_1_56_1","unstructured":"Simpy. Discrete event simulation for Python. https:\/\/simpy.readthedocs.io\/en\/latest\/index.html, 2020."},{"key":"e_1_3_2_1_57_1","volume-title":"https:\/\/www.tensorflow.org\/tfx\/guide\/examplegen","author":"Extended Guide TensorFlow","year":"2022","unstructured":"TensorFlow Extended Guide. https:\/\/www.tensorflow.org\/tfx\/guide\/examplegen, 2022."},{"key":"e_1_3_2_1_58_1","volume-title":"Tutorials on the Foundations of Cryptography.","author":"Vadhan S.","year":"2017","unstructured":"S. Vadhan. The complexity of differential privacy. In Tutorials on the Foundations of Cryptography. 2017."},{"key":"e_1_3_2_1_59_1","first-page":"945","volume-title":"19th USENIX Symposium on Networked Systems Design and Implementation (NSDI 22)","author":"Weng Q.","year":"2022","unstructured":"Q. Weng, W. Xiao, Y. Yu, W. Wang, C. Wang, J. He, Y. Li, L. Zhang, W. Lin, and Y. Ding. MLaaS in the wild: Workload analysis and scheduling in Large-Scale heterogeneous GPU clusters. In 19th USENIX Symposium on Networked Systems Design and Implementation (NSDI 22), pages 945--960, Renton, WA, Apr. 2022. USENIX Association."},{"key":"e_1_3_2_1_60_1","doi-asserted-by":"publisher","DOI":"10.2478\/popets-2020-0025"},{"key":"e_1_3_2_1_61_1","doi-asserted-by":"publisher","DOI":"10.1016\/S0020-0190(97)00179-8"},{"key":"e_1_3_2_1_62_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICDE.2012.48"},{"key":"e_1_3_2_1_63_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2019.00019"}],"event":{"name":"EuroSys '25: Twentieth European Conference on Computer Systems","sponsor":["SIGOPS ACM Special Interest Group on Operating Systems"],"location":"Rotterdam Netherlands","acronym":"EuroSys '25"},"container-title":["Proceedings of the Twentieth European Conference on Computer Systems"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3689031.3696096","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3689031.3696096","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,8,21]],"date-time":"2025-08-21T11:23:17Z","timestamp":1755775397000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3689031.3696096"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,3,30]]},"references-count":63,"alternative-id":["10.1145\/3689031.3696096","10.1145\/3689031"],"URL":"https:\/\/doi.org\/10.1145\/3689031.3696096","relation":{},"subject":[],"published":{"date-parts":[[2025,3,30]]},"assertion":[{"value":"2025-03-30","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}