{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,8,24]],"date-time":"2026-08-24T17:23:45Z","timestamp":1787592225390,"version":"build-2736575974"},"reference-count":85,"publisher":"Association for Computing Machinery (ACM)","issue":"OOPSLA1","license":[{"start":{"date-parts":[[2025,4,9]],"date-time":"2025-04-09T00:00:00Z","timestamp":1744156800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/legalcode"}],"funder":[{"DOI":"10.13039\/501100003977","name":"Israel Science Foundation","doi-asserted-by":"publisher","award":["2605\/20"],"award-info":[{"award-number":["2605\/20"]}],"id":[{"id":"10.13039\/501100003977","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["Proc. ACM Program. Lang."],"published-print":{"date-parts":[[2025,4,9]]},"abstract":"<jats:p>\n                    Neural networks are susceptible to privacy attacks that can extract private information of the training set. To cope, several training algorithms guarantee differential privacy (DP) by adding noise to their computation. However, DP requires to add noise considering\n                    <jats:italic toggle=\"yes\">every possible<\/jats:italic>\n                    training set. This leads to a significant decrease in the network\u2019s accuracy. Individual DP (iDP) restricts DP to a given training set. We observe that some inputs deterministically satisfy iDP\n                    <jats:italic toggle=\"yes\">without any noise<\/jats:italic>\n                    . By identifying them, we can provide iDP label-only access to the network with a minor decrease to its accuracy. However, identifying the inputs that satisfy iDP without any noise is highly challenging. Our key idea is to compute the\n                    <jats:italic toggle=\"yes\">iDP deterministic bound<\/jats:italic>\n                    (iDP-DB), which overapproximates the set of inputs that do not satisfy iDP, and add noise only to their predicted labels. To compute the tightest iDP-DB, which enables to guard the label-only access with minimal accuracy decrease, we propose\n                    <jats:monospace>LUCID<\/jats:monospace>\n                    , which leverages several formal verification techniques. First, it encodes the problem as a mixed-integer linear program, defined over a network and over every network trained identically but without a unique data point. Second, it abstracts a set of networks using a\n                    <jats:italic toggle=\"yes\">hyper-network<\/jats:italic>\n                    . Third, it eliminates the overapproximation error via a novel branch-and-bound technique. Fourth, it bounds the differences of matching neurons in the network and the hyper-network, encodes them as linear constraints to prune the search space, and employs linear relaxation if they are small. We evaluate\n                    <jats:monospace>LUCID<\/jats:monospace>\n                    on fully-connected and convolutional networks for four datasets and compare the results to existing DP training algorithms, which in particular provide iDP guarantees. We show that\n                    <jats:monospace>LUCID<\/jats:monospace>\n                    can provide classifiers with a perfect individuals\u2019 privacy guarantee (0-iDP) \u2013 which is infeasible for DP training algorithms \u2013 with an accuracy decrease of 1.4%. For more relaxed\n                    <jats:inline-formula>\n                      <mml:math xmlns:mml=\"http:\/\/www.w3.org\/1998\/Math\/MathML\" display=\"inline\">\n                        <mml:mi>\u03b5<\/mml:mi>\n                      <\/mml:math>\n                    <\/jats:inline-formula>\n                    -iDP guarantees,\n                    <jats:monospace>LUCID<\/jats:monospace>\n                    has an accuracy decrease of 1.2%. In contrast, existing DP training algorithms that obtain\n                    <jats:inline-formula>\n                      <mml:math xmlns:mml=\"http:\/\/www.w3.org\/1998\/Math\/MathML\" display=\"inline\">\n                        <mml:mi>\u03b5<\/mml:mi>\n                      <\/mml:math>\n                    <\/jats:inline-formula>\n                    -DP guarantees, and in particular\n                    <jats:inline-formula>\n                      <mml:math xmlns:mml=\"http:\/\/www.w3.org\/1998\/Math\/MathML\" display=\"inline\">\n                        <mml:mi>\u03b5<\/mml:mi>\n                      <\/mml:math>\n                    <\/jats:inline-formula>\n                    -iDP guarantees, reduce the accuracy by\n                    <jats:inline-formula>\n                      <mml:math xmlns:mml=\"http:\/\/www.w3.org\/1998\/Math\/MathML\" display=\"inline\">\n                        <mml:mn>12.7<\/mml:mn>\n                        <mml:mi mathvariant=\"normal\">%<\/mml:mi>\n                      <\/mml:math>\n                    <\/jats:inline-formula>\n                    .\n                  <\/jats:p>","DOI":"10.1145\/3720480","type":"journal-article","created":{"date-parts":[[2025,4,9]],"date-time":"2025-04-09T13:48:26Z","timestamp":1744206506000},"page":"1184-1212","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":1,"title":["Guarding the Privacy of Label-Only Access to Neural Network Classifiers via iDP Verification"],"prefix":"10.1145","volume":"9","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-0969-6169","authenticated-orcid":false,"given":"Anan","family":"Kabaha","sequence":"first","affiliation":[{"name":"Technion, Haifa, Israel"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-6644-5377","authenticated-orcid":false,"given":"Dana Drachsler","family":"Cohen","sequence":"additional","affiliation":[{"name":"Technion, Haifa, Israel"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2025,4,9]]},"reference":[{"key":"e_1_3_1_2_1","doi-asserted-by":"publisher","DOI":"10.1145\/2976749.2978318"},{"key":"e_1_3_1_3_1","doi-asserted-by":"publisher","DOI":"10.1109\/MSEC.2018.2888775"},{"key":"e_1_3_1_4_1","unstructured":"Amazon Web Services. 2024. Machine Learning on AWS. https:\/\/aws.amazon.com\/machine-learning"},{"key":"e_1_3_1_5_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-59152-6_5"},{"key":"e_1_3_1_6_1","unstructured":"Eugene Bagdasaryan Omid Poursaeed and Vitaly Shmatikov. 2019. Differential Privacy Has Disparate Impact on Model Accuracy. In NeurIPS (2019). https:\/\/proceedings.neurips.cc\/paper\/2019\/hash\/fc0de4e0396fff257ea362983c2dda5aAbstract.html"},{"key":"e_1_3_1_7_1","unstructured":"Sina Baharlouei Maher Nouiehed Ahmad Beirami and Meisam Razaviyayn. 2020. R\u00e9nyi Fair Inference. In 8th International Conference on Learning Representations ICLR. https:\/\/openreview.net\/forum?id=HkgsUJrtDB"},{"key":"e_1_3_1_8_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP46214.2022.9833677"},{"key":"e_1_3_1_9_1","doi-asserted-by":"publisher","DOI":"10.1145\/3656377"},{"key":"e_1_3_1_10_1","doi-asserted-by":"publisher","DOI":"10.24432\/C5XW20"},{"key":"e_1_3_1_11_1","doi-asserted-by":"publisher","DOI":"10.1137\/1.9781611978032.1"},{"key":"e_1_3_1_12_1","unstructured":"Franziska Boenisch Christopher M\u00fchl Adam Dziedzic Roy Rinberg and Nicolas Papernot. 2023a. Have it your way: Individualized Privacy Assignment for DP-SGD. In NeurIPS (2023). http:\/\/papers.nips.cc\/paper_files\/paper\/2023\/hash\/3cbf627fa24fb6cb576e04e689b9428b-Abstract-Conference.html"},{"key":"e_1_3_1_13_1","doi-asserted-by":"publisher","DOI":"10.56553\/POPETS-2023-0010"},{"key":"e_1_3_1_14_1","article-title":"Branch and Bound for Piecewise Linear Neural Network Verification","volume":"7","author":"Bunel Rudy","year":"2020","unstructured":"Rudy Bunel, Jingyue Lu, Ilker Turkaslan, Philip H. S. Torr, Pushmeet Kohli, and M. Pawan Kumar. 2020. Branch and Bound for Piecewise Linear Neural Network Verification. 7. Mach. Learn. Res. (2020). https:\/\/jmlr.org\/papers\/v21\/19-468.html","journal-title":"Mach. Learn. Res. (2020)"},{"key":"e_1_3_1_15_1","unstructured":"Rudy Bunel Ilker Turkaslan Philip H. S. Torr Pushmeet Kohli and Pawan Kumar Mudigonda. 2018. A Unified View of Piecewise Linear Neural Network Verification. In NeurIPS (2018). https:\/\/proceedings.neurips.cc\/paper\/2018\/hash\/be53d253d6bc3258a8160556dda3e9b2-Abstract.html"},{"key":"e_1_3_1_16_1","doi-asserted-by":"publisher","DOI":"10.1109\/JIOT.2019.2952146"},{"key":"e_1_3_1_17_1","doi-asserted-by":"publisher","DOI":"10.1145\/3606017"},{"key":"e_1_3_1_18_1","doi-asserted-by":"publisher","DOI":"10.1016\/J.JNCA.2020.102736"},{"key":"e_1_3_1_19_1","doi-asserted-by":"publisher","DOI":"10.1609\/AAAI.V36I6.20586"},{"key":"e_1_3_1_20_1","unstructured":"Christopher A. Choquette-Choo Florian Tram\u00e8r Nicholas Carlini and Nicolas Papernot. 2021. Label-Only Membership Inference Attacks. In ICML (2021)."},{"key":"e_1_3_1_21_1","doi-asserted-by":"publisher","unstructured":"Cynthia Dwork. 2006. Differential Privacy. In Automata Languages and Programming 33rd International Colloquium ICALP (Lecture Notes in Computer Science Vol. 4052). Springer 1\u201312. https:\/\/doi.org\/10.1007\/11787006_1 10.1007\/11787006_1","DOI":"10.1007\/11787006_1"},{"key":"e_1_3_1_22_1","doi-asserted-by":"publisher","unstructured":"R\u00fcdiger Ehlers. 2017. Formal Verification of Piece-Wise Linear Feed-Forward Neural Networks. In Automated Technology for Verification and Analysis - 15th International Symposium ATVA (Lecture Notes in Computer Science Vol. 10482). Springer 269\u2013286. https:\/\/doi.org\/10.1007\/978-3-319-68167-2_19 10.1007\/978-3-319-68167-2_19","DOI":"10.1007\/978-3-319-68167-2_19"},{"key":"e_1_3_1_23_1","doi-asserted-by":"publisher","unstructured":"Ahmed Roushdy Elkordy Jiang Zhang Yahya H. Ezzeldin Konstantinos Psounis and Salman Avestimehr. 2023. How Much Privacy Does Federated Learning with Secure Aggregation Guarantee? In Proc. Priv. Enhancing Technol. (2023). https:\/\/doi.org\/10.56553\/POPETS-2023-0030 10.56553\/POPETS-2023-0030","DOI":"10.56553\/POPETS-2023-0030"},{"key":"e_1_3_1_24_1","unstructured":"Mani Malek Esmaeili Ilya Mironov Karthik Prasad Igor Shilov and Florian Tram\u00e8r. 2021. Antipodes of Label Differential Privacy: PATE and ALIBI. In NeurIPS. https:\/\/proceedings.neurips.cc\/paper\/2021\/hash\/37ecd27608480aa3569a511a638ca74fAbstract.html"},{"key":"e_1_3_1_25_1","unstructured":"Jonas Geiping Hartmut Bauermeister Hannah Dr\u00f6ge and Michael Moeller. 2020. Inverting Gradients - How easy is it to break privacy in federated learning? In NeurIPS (2020). https:\/\/proceedings.neurips.cc\/paper\/2020\/hash\/c4ede56bbd98819ae6112b20ac6bf145-Abstract.html"},{"key":"e_1_3_1_26_1","doi-asserted-by":"publisher","DOI":"10.1145\/2976749.2978318"},{"key":"e_1_3_1_27_1","unstructured":"Badih Ghazi Pritish Kamath Ravi Kumar Ethan Leeman Pasin Manurangsi Avinash V. Varadarajan and Chiyuan Zhang. 2023. Regression with Label Differential Privacy. In ICLR (2023). https:\/\/openreview.net\/forum?id=h9O0wsmL-cT"},{"key":"e_1_3_1_28_1","unstructured":"Google Cloud. 2024. Vertex AI. https:\/\/cloud.google.com\/vertex-ai"},{"key":"e_1_3_1_29_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-01090-4_1"},{"key":"e_1_3_1_30_1","unstructured":"Gurobi Optimization LLC. 2023. Gurobi Optimizer Reference Manual. https:\/\/www.gurobi.com"},{"key":"e_1_3_1_31_1","doi-asserted-by":"publisher","DOI":"10.1007\/S10618-017-0532-Z"},{"key":"e_1_3_1_32_1","doi-asserted-by":"publisher","DOI":"10.2478\/POPETS-2019-0008"},{"key":"e_1_3_1_33_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.90"},{"key":"e_1_3_1_34_1","doi-asserted-by":"publisher","DOI":"10.24963\/IJCAI.2021\/351"},{"key":"e_1_3_1_35_1","doi-asserted-by":"publisher","DOI":"10.1145\/3485832.3485838"},{"key":"e_1_3_1_36_1","doi-asserted-by":"publisher","DOI":"10.1109\/MSEC.2020.3039941"},{"key":"e_1_3_1_37_1","unstructured":"Dihong Jiang Sun Sun and Yaoliang Yu. 2023. Functional Renyi Differential Privacy for Generative Modeling. In NeurIPS (2023). http:\/\/papers.nips.cc\/paper_files\/paper\/2023\/hash\/2f9ee101e35b890d9eae79ee27bcd69a-Abstract-Conference.html"},{"key":"e_1_3_1_38_1","doi-asserted-by":"publisher","DOI":"10.1007\/S44196-024-00422-X"},{"key":"e_1_3_1_39_1","doi-asserted-by":"publisher","DOI":"10.1145\/3649847"},{"key":"e_1_3_1_40_1","doi-asserted-by":"publisher","unstructured":"Anan Kabaha and Dana Drachsler-Cohen. 2025. Guarding the Privacy of Label-Only Access to Neural Network Classifiers via iDP Verification. In arXiv:2502.16519 (2025). https:\/\/doi.org\/10.48550\/arXiv.2502.16519 10.48550\/arXiv.2502.16519","DOI":"10.48550\/arXiv.2502.16519"},{"key":"e_1_3_1_41_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52688.2022.01462"},{"key":"e_1_3_1_42_1","unstructured":"Peter Kairouz Sewoong Oh and Pramod Viswanath. 2015. The Composition Theorem for Differential Privacy. In ICML (2015). http:\/\/proceedings.mlr.press\/v37\/kairouz15.html"},{"key":"e_1_3_1_43_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-63387-9_5"},{"key":"e_1_3_1_44_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-25540-4_26"},{"key":"e_1_3_1_45_1","doi-asserted-by":"publisher","DOI":"10.1145\/3308558.3313665"},{"key":"e_1_3_1_46_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV51070.2023.00449"},{"key":"e_1_3_1_47_1","doi-asserted-by":"publisher","DOI":"10.1109\/5.726791"},{"key":"e_1_3_1_48_1","unstructured":"Kyumin Lee Brian David Eoff and James Caverlee. 2011. Seven Months with the Devils: A Long-Term Study of Content Polluters on Twitter. In AAAI (2011). http:\/\/www.aaai.org\/ocs\/index.php\/ICWSM\/ICWSM11\/paper\/view\/2780"},{"key":"e_1_3_1_49_1","doi-asserted-by":"publisher","DOI":"10.1145\/3460120.3484575"},{"key":"e_1_3_1_50_1","doi-asserted-by":"publisher","DOI":"10.1145\/3634737.3657002"},{"key":"e_1_3_1_51_1","doi-asserted-by":"publisher","DOI":"10.1145\/3644387"},{"key":"e_1_3_1_52_1","doi-asserted-by":"publisher","DOI":"10.1109\/TIT.1982.1056489"},{"key":"e_1_3_1_53_1","unstructured":"Jingyue Lu and M. Pawan Kumar. 2020. Neural Network Branching for Neural Network Verification. In ICLR (2020). https:\/\/openreview.net\/forum?id=B1evfa4tPB"},{"key":"e_1_3_1_54_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-88806-0_15"},{"key":"e_1_3_1_55_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2019.00029"},{"key":"e_1_3_1_56_1","doi-asserted-by":"publisher","DOI":"10.1109\/CSF.2017.11"},{"key":"e_1_3_1_57_1","doi-asserted-by":"publisher","DOI":"10.1145\/3498704"},{"key":"e_1_3_1_58_1","doi-asserted-by":"publisher","unstructured":"Tabitha Ogilvie. 2024. Differential Privacy for Free? Harnessing the Noise in Approximate Homomorphic Encryption. In CT-RSA (2024). https:\/\/doi.org\/10.1007\/978-3-031-58868-6_12 10.1007\/978-3-031-58868-6_12","DOI":"10.1007\/978-3-031-58868-6_12"},{"key":"e_1_3_1_59_1","unstructured":"Alessandro De Palma and et al. 2021. Improved Branch and Bound for Neural Network Verification via Lagrangian Decomposition. arXiv:2104.06718 (2021). https:\/\/arxiv.org\/abs\/2104.06718"},{"key":"e_1_3_1_60_1","doi-asserted-by":"publisher","DOI":"10.1145\/3270101.3270102"},{"key":"e_1_3_1_61_1","doi-asserted-by":"publisher","DOI":"10.1145\/3377811.3380337"},{"key":"e_1_3_1_62_1","doi-asserted-by":"publisher","DOI":"10.1145\/3324884.3416560"},{"key":"e_1_3_1_63_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-031-50521-8_5"},{"key":"e_1_3_1_64_1","unstructured":"Arnaud Grivet S\u00e9bert. 2023. Combining differential privacy and homomorphic encryption for privacy-preserving collaborative machine learning. (Approches combinant confidentialit\u00e9 diff\u00e9rentielle et chiffrement homomorphe pour la protection des donn\u00e9es en apprentissage automatique collaboratif). Ph. D. Dissertation. University of Paris-Saclay France. https:\/\/tel.archives-ouvertes.fr\/tel-04223076"},{"key":"e_1_3_1_65_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.41"},{"key":"e_1_3_1_66_1","unstructured":"Gagandeep Singh Timon Gehr Markus P\u00fcschel and Martin T. Vechev. 2019. Boosting Robustness Certification of Neural Networks. In ICLR (2019). https:\/\/openreview.net\/forum?id=HJgeEh09KQ"},{"key":"e_1_3_1_67_1","doi-asserted-by":"publisher","DOI":"10.3390\/S24196161"},{"key":"e_1_3_1_68_1","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2017.2663337"},{"key":"e_1_3_1_69_1","unstructured":"Vincent Tjeng Kai Y. Xiao and Russ Tedrake. 2019. Evaluating robustness of neural networks with mixed integer programming. In ICLR (2019). https:\/\/openreview.net\/forum?id=HyGIdiRqtm"},{"key":"e_1_3_1_70_1","doi-asserted-by":"publisher","DOI":"10.1145\/3591299"},{"key":"e_1_3_1_71_1","doi-asserted-by":"publisher","DOI":"10.1145\/3527319"},{"key":"e_1_3_1_72_1","doi-asserted-by":"publisher","DOI":"10.1145\/3428253"},{"key":"e_1_3_1_73_1","doi-asserted-by":"publisher","unstructured":"Robert J. Vanderbei. 1996. Linear Programming: Foundations and Extensions. (1996). https:\/\/doi.org\/10.1007\/978-0-387-74388-2 10.1007\/978-0-387-74388-2","DOI":"10.1007\/978-0-387-74388-2"},{"key":"e_1_3_1_74_1","doi-asserted-by":"publisher","unstructured":"Fuyi Wang Leo Yu Zhang Lei Pan Shengshan Hu and Robin Doss. 2022c. Towards Privacy-Preserving Neural Architecture Search. In ISCC (2022). https:\/\/doi.org\/10.1109\/ISCC55528.2022.9913012 10.1109\/ISCC55528.2022.9913012","DOI":"10.1109\/ISCC55528.2022.9913012"},{"key":"e_1_3_1_75_1","unstructured":"Shiqi Wang Huan Zhang Kaidi Xu Xue Lin Suman Jana Cho-Jui Hsieh and J Zico Kolter. 2021. Beta-CROWN: Efficient Bound Propagation with Per-neuron Split Constraints for Neural Network Robustness Verification. In NeurIPS (2021). https:\/\/proceedings.neurips.cc\/paper\/2021\/hash\/fac7fead96dafceaf80c1daffeae82a4-Abstract.html"},{"key":"e_1_3_1_76_1","article-title":"Per-instance Differential Privacy","volume":"7","author":"Wang Yu-Xiang","year":"2019","unstructured":"Yu-Xiang Wang. 2019. Per-instance Differential Privacy. In 7. Priv. Confidentiality(2019). https:\/\/journalprivacyconfidentiality.org\/index.php\/jpc\/article\/download\/662\/675\/1038","journal-title":"Priv. Confidentiality(2019)"},{"key":"e_1_3_1_77_1","doi-asserted-by":"publisher","DOI":"10.1109\/TCSS.2019.2950017"},{"key":"e_1_3_1_78_1","doi-asserted-by":"publisher","DOI":"10.23919\/DATE54114.2022.9774719"},{"key":"e_1_3_1_79_1","doi-asserted-by":"publisher","unstructured":"Zhilu Wang Yixuan Wang Feisi Fu Ruochen Jiao Chao Huang Wenchao Li and Qi Zhu. 2022b. A Tool for Neural Network Global Robustness Certification and Training. In https:\/\/doi.org\/10.48550\/arXiv.2208.072892022 10.48550\/arXiv.2208.072892022 (2022). https:\/\/doi.org\/10.48550\/ARXIV.2208.07289 10.48550\/ARXIV.2208.07289","DOI":"10.48550\/arXiv.2208.072892022"},{"key":"e_1_3_1_80_1","doi-asserted-by":"publisher","unstructured":"Wayne L. Winston. 1991. Operations Research: Applications and Algorithms. (1991). https:\/\/doi.org\/10.1002\/net.3230180310 10.1002\/net.3230180310","DOI":"10.1002\/net.3230180310"},{"key":"e_1_3_1_81_1","doi-asserted-by":"publisher","unstructured":"Haoze Wu and et al. 2020. Parallelization Techniques for Verifying Neural Networks. In FMCAD (2020). https:\/\/doi.org\/10.34727\/2020\/ISBN.978-3-85448-042-6_20 10.34727\/2020\/ISBN.978-3-85448-042-6_20","DOI":"10.34727\/2020\/ISBN.978-3-85448-042-6_20"},{"key":"e_1_3_1_82_1","doi-asserted-by":"publisher","DOI":"10.1609\/AAAI.V38I18.29974"},{"key":"e_1_3_1_83_1","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2020.3005909"},{"key":"e_1_3_1_84_1","unstructured":"Jiayuan Ye and Reza Shokri. 2022. Differentially Private Learning Needs Hidden State (Or Much Faster Convergence). In NeurIPS (2022). http:\/\/papers.nips.cc\/paper_files\/paper\/2022\/hash\/04b42392f9a3a16aea012395359b8148-AbstractConference.html"},{"key":"e_1_3_1_85_1","doi-asserted-by":"publisher","unstructured":"I-Cheng Yeh. 2016. Default of credit card clients. UCI Machine Learning Repository. https:\/\/doi.org\/10.24432\/C55S3H 10.24432\/C55S3H","DOI":"10.24432\/C55S3H"},{"key":"e_1_3_1_86_1","unstructured":"Ligeng Zhu Zhijian Liu and Song Han. 2019. Deep Leakage from Gradients. In NeurIPS (2019). https:\/\/proceedings.neurips.cc\/paper\/2019\/hash\/60a6c4002cc7b29142def8871531281a-Abstract.html"}],"container-title":["Proceedings of the ACM on Programming Languages"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3720480","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3720480","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,8,24]],"date-time":"2026-08-24T16:29:22Z","timestamp":1787588962000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3720480"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,4,9]]},"references-count":85,"journal-issue":{"issue":"OOPSLA1","published-print":{"date-parts":[[2025,4,9]]}},"alternative-id":["10.1145\/3720480"],"URL":"https:\/\/doi.org\/10.1145\/3720480","relation":{},"ISSN":["2475-1421"],"issn-type":[{"value":"2475-1421","type":"electronic"}],"subject":[],"published":{"date-parts":[[2025,4,9]]},"assertion":[{"value":"2024-10-15","order":0,"name":"received","label":"Received","group":{"name":"publication_history","label":"Publication History"}},{"value":"2025-02-18","order":2,"name":"accepted","label":"Accepted","group":{"name":"publication_history","label":"Publication History"}},{"value":"2025-04-09","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}