{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,4,15]],"date-time":"2026-04-15T03:28:45Z","timestamp":1776223725152,"version":"3.50.1"},"reference-count":99,"publisher":"Association for Computing Machinery (ACM)","issue":"12","funder":[{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"crossref","award":["62272084"],"award-info":[{"award-number":["62272084"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"crossref"}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["ACM Comput. Surv."],"published-print":{"date-parts":[[2025,12,31]]},"abstract":"<jats:p>Differential privacy (DP), a rigorously quantifiable privacy preservation technique, has found widespread application within the domain of machine learning. As DP techniques are implemented in machine learning algorithms, a significant and intricate tradeoff between privacy and utility emerges, garnering extensive attention from researchers. In the pursuit of striking a delicate equilibrium between safeguarding sensitive data and optimizing its utility, researchers have introduced various variants of Relaxed Differential Privacy (RDP) definitions. These nuanced formulations, however, exhibit substantial diversity in their underlying principles and interpretations of the core concept of DP, thereby engendering a current void in the comprehensive synthesis of these related works.<\/jats:p>\n          <jats:p>The principal objective of this article is twofold. Firstly, it aims to provide a comprehensive summary of pertinent research endeavors pertaining to RDP within the realm of machine learning. Secondly, it endeavors to empirically assess the impact on both privacy and utility stemming from machine learning algorithms founded upon these RDP definitions. Additionally, this article undertakes a systematic analysis of the foundational principles underpinning distinct variants of relaxed definitions, culminating in the development of a taxonomy that categorizes these RDP definitions.<\/jats:p>","DOI":"10.1145\/3729216","type":"journal-article","created":{"date-parts":[[2025,6,3]],"date-time":"2025-06-03T07:29:56Z","timestamp":1748935796000},"page":"1-34","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":7,"title":["Benchmarking Relaxed Differential Privacy in Private Learning: A Comparative Survey"],"prefix":"10.1145","volume":"57","author":[{"ORCID":"https:\/\/orcid.org\/0009-0000-7712-937X","authenticated-orcid":false,"given":"Zhaolong","family":"Zheng","sequence":"first","affiliation":[{"name":"School of Software, Dalian University of Technology","place":["Dalian, China"]}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-8138-6045","authenticated-orcid":false,"given":"Lin","family":"Yao","sequence":"additional","affiliation":[{"name":"Dalian University of Technology","place":["Dalian, China"]}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-9008-2112","authenticated-orcid":false,"given":"Haibo","family":"Hu","sequence":"additional","affiliation":[{"name":"The Hong Kong Polytechnic University","place":["Hong Kong, Hong Kong"]}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-3929-3598","authenticated-orcid":false,"given":"Guowei","family":"Wu","sequence":"additional","affiliation":[{"name":"School of Software, Dalian University of Technology","place":["Dalian, China"]}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2025,7,12]]},"reference":[{"key":"e_1_3_1_2_2","first-page":"105","volume-title":"Introduction to Machine Learning","author":"Ba\u015ftanlar Yalin","year":"2014","unstructured":"Yalin Ba\u015ftanlar and Mustafa \u00d6zuysal. 2014. Introduction to Machine Learning. Humana Press, Totowa, NJ, 105\u2013128."},{"key":"e_1_3_1_3_2","first-page":"1125","article-title":"Sensitive information","volume":"88","author":"Ohm Paul","year":"2014","unstructured":"Paul Ohm. 2014. Sensitive information. Southern California Law Review 88, 5 (2014), 1125.","journal-title":"Southern California Law Review"},{"key":"e_1_3_1_4_2","doi-asserted-by":"publisher","DOI":"10.1145\/2810103.2813677"},{"key":"e_1_3_1_5_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-26059-4_20"},{"key":"e_1_3_1_6_2","first-page":"1895","volume-title":"Proceedings of the 28th USENIX Security Symposium (USENIX Security 19)","author":"Jayaraman Bargav","year":"2019","unstructured":"Bargav Jayaraman and David Evans. 2019. Evaluating differentially private machine learning in practice. In Proceedings of the 28th USENIX Security Symposium (USENIX Security 19). USENIX Association, Santa Clara, CA, 1895\u20131912."},{"key":"e_1_3_1_7_2","doi-asserted-by":"publisher","DOI":"10.14569\/IJACSA.2014.051126"},{"key":"e_1_3_1_8_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-0-387-70992-5_2"},{"key":"e_1_3_1_9_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-63076-8_2"},{"key":"e_1_3_1_10_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-540-79228-4_1"},{"key":"e_1_3_1_11_2","doi-asserted-by":"publisher","DOI":"10.1145\/2414456.2414474"},{"key":"e_1_3_1_12_2","doi-asserted-by":"crossref","unstructured":"Cynthia Dwork and Aaron Roth. 2014. The algorithmic foundations of differential privacy. Found. Trends Theor. Comput. Sci. 9 3\u20134 (2014) 211\u2013407.","DOI":"10.1561\/0400000042"},{"key":"e_1_3_1_13_2","doi-asserted-by":"publisher","DOI":"10.1109\/FOCS.2010.12"},{"key":"e_1_3_1_14_2","first-page":"arXiv\u20131412","article-title":"Differential privacy and machine learning: A survey and review","author":"Ji Zhanglong","year":"2014","unstructured":"Zhanglong Ji, Zachary C. Lipton, and Charles Elkan. 2014. Differential privacy and machine learning: A survey and review. arXiv E-prints (2014), arXiv\u20131412.","journal-title":"arXiv E-prints"},{"key":"e_1_3_1_15_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-40328-6_26"},{"key":"e_1_3_1_16_2","unstructured":"Cynthia Dwork and Guy N. Rothblum. 2016. Concentrated differential privacy. arXiv:1603.01887. Retrieved from https:\/\/arxiv.org\/abs\/1603.01887"},{"key":"e_1_3_1_17_2","doi-asserted-by":"publisher","DOI":"10.1111\/rssb.12454"},{"key":"e_1_3_1_18_2","doi-asserted-by":"publisher","DOI":"10.1109\/JSAIT.2021.3054692"},{"key":"e_1_3_1_19_2","doi-asserted-by":"publisher","DOI":"10.1126\/science.aaa8415"},{"key":"e_1_3_1_20_2","doi-asserted-by":"publisher","DOI":"10.1103\/RevModPhys.91.045002"},{"issue":"7","key":"e_1_3_1_21_2","first-page":"98","article-title":"Machine learning basics","volume":"1","author":"Goodfellow Ian","year":"2016","unstructured":"Ian Goodfellow, Yoshua Bengio, and Aaron Courville. 2016. Machine learning basics. Deep Learning 1, 7 (2016), 98\u2013164.","journal-title":"Deep Learning"},{"issue":"12","key":"e_1_3_1_22_2","first-page":"2222","article-title":"What is machine learning? A primer for the epidemiologist","volume":"188","author":"Bi Qifang","year":"2019","unstructured":"Qifang Bi, Katherine E. Goodman, Joshua Kaminsky, and Justin Lessler. 2019. What is machine learning? A primer for the epidemiologist. American Journal of Epidemiology 188, 12 (2019), 2222\u20132239.","journal-title":"American Journal of Epidemiology"},{"key":"e_1_3_1_23_2","doi-asserted-by":"publisher","DOI":"10.1017\/CBO9781107298019"},{"key":"e_1_3_1_24_2","doi-asserted-by":"publisher","DOI":"10.3390\/s18082674"},{"key":"e_1_3_1_25_2","doi-asserted-by":"publisher","DOI":"10.5555\/2371238"},{"key":"e_1_3_1_26_2","doi-asserted-by":"publisher","DOI":"10.5555\/2612156.2612159"},{"key":"e_1_3_1_27_2","doi-asserted-by":"publisher","DOI":"10.1145\/1835804.1835868"},{"key":"e_1_3_1_28_2","doi-asserted-by":"publisher","DOI":"10.1198\/jasa.2009.tm08651"},{"key":"e_1_3_1_29_2","doi-asserted-by":"publisher","DOI":"10.1145\/3490237"},{"key":"e_1_3_1_30_2","doi-asserted-by":"publisher","DOI":"10.1109\/FOCS.2007.66"},{"key":"e_1_3_1_31_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-24861-0_22"},{"key":"e_1_3_1_32_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-03356-8_8"},{"key":"e_1_3_1_33_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-57048-8_7"},{"key":"e_1_3_1_34_2","doi-asserted-by":"publisher","DOI":"10.1137\/1.9781611973075.16"},{"key":"e_1_3_1_35_2","doi-asserted-by":"publisher","DOI":"10.1145\/1806689.1806786"},{"key":"e_1_3_1_36_2","doi-asserted-by":"publisher","DOI":"10.1109\/CDC.2016.7798915"},{"key":"e_1_3_1_37_2","first-page":"1376","volume-title":"Proceedings of the International Conference on Machine Learning","author":"Kairouz Peter","year":"2015","unstructured":"Peter Kairouz, Sewoong Oh, and Pramod Viswanath. 2015. The composition theorem for differential privacy. In Proceedings of the International Conference on Machine Learning. PMLR, 1376\u20131385."},{"key":"e_1_3_1_38_2","doi-asserted-by":"publisher","DOI":"10.1145\/3243734.3243818"},{"key":"e_1_3_1_39_2","doi-asserted-by":"publisher","DOI":"10.1109\/COMST.2019.2944748"},{"key":"e_1_3_1_40_2","doi-asserted-by":"publisher","DOI":"10.1109\/TKDE.2010.247"},{"key":"e_1_3_1_41_2","doi-asserted-by":"publisher","DOI":"10.1145\/1806689.1806787"},{"key":"e_1_3_1_42_2","unstructured":"Tianwei Zhang Zecheng He and Ruby B. Lee. 2018. Privacy-preserving machine learning through data obfuscation. arXiv:1807.01860. Retrieved from https:\/\/arxiv.org\/abs\/1807.01860"},{"key":"e_1_3_1_43_2","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.41"},{"key":"e_1_3_1_44_2","doi-asserted-by":"publisher","DOI":"10.1145\/3523273"},{"issue":"1","key":"e_1_3_1_45_2","first-page":"61","article-title":"Membership inference attack against differentially private deep learning model.","volume":"11","author":"Rahman Md Atiqur","year":"2018","unstructured":"Md Atiqur Rahman, Tanzila Rahman, Robert Lagani\u00e8re, Noman Mohammed, and Yang Wang. 2018. Membership inference attack against differentially private deep learning model. Transactions on Data Privacy 11, 1 (2018), 61\u201379.","journal-title":"Transactions on Data Privacy"},{"key":"e_1_3_1_46_2","first-page":"1964","volume-title":"Proceedings of the 38th International Conference on Machine Learning (Proceedings of Machine Learning Research)","volume":"139","author":"Choquette-Choo Christopher A.","year":"2021","unstructured":"Christopher A. Choquette-Choo, Florian Tramer, Nicholas Carlini, and Nicolas Papernot. 2021. Label-only membership inference attacks. In Proceedings of the 38th International Conference on Machine Learning (Proceedings of Machine Learning Research). Marina Meila and Tong Zhang (Eds.), Vol. 139, PMLR, 1964\u20131974."},{"key":"e_1_3_1_47_2","doi-asserted-by":"publisher","DOI":"10.1145\/3359789.3359824"},{"key":"e_1_3_1_48_2","doi-asserted-by":"publisher","DOI":"10.1109\/CSF.2016.32"},{"key":"e_1_3_1_49_2","first-page":"1605","volume-title":"Proceedings of the 29th USENIX Security Symposium (USENIX Security 20)","author":"Leino Klas","year":"2020","unstructured":"Klas Leino and Matt Fredrikson. 2020. Stolen memories: Leveraging model memorization for calibrated white-box membership inference. In Proceedings of the 29th USENIX Security Symposium (USENIX Security 20). USENIX Association, 1605\u20131622."},{"key":"e_1_3_1_50_2","first-page":"267","volume-title":"Proceedings of the 28th USENIX Security Symposium (USENIX Security 19)","author":"Carlini Nicholas","year":"2019","unstructured":"Nicholas Carlini, Chang Liu, \u00dalfar Erlingsson, Jernej Kos, and Dawn Song. 2019. The secret sharer: Evaluating and testing unintended memorization in neural networks. In Proceedings of the 28th USENIX Security Symposium (USENIX Security 19). USENIX Association, Santa Clara, CA, 267\u2013284."},{"key":"e_1_3_1_51_2","doi-asserted-by":"publisher","DOI":"10.1145\/3133956.3134077"},{"key":"e_1_3_1_52_2","first-page":"13263","article-title":"The privacy onion effect: Memorization is relative","volume":"35","author":"Carlini Nicholas","year":"2022","unstructured":"Nicholas Carlini, Matthew Jagielski, Chiyuan Zhang, Nicolas Papernot, Andreas Terzis, and Florian Tramer. 2022. The privacy onion effect: Memorization is relative. Advances in Neural Information Processing Systems 35 (2022), 13263\u201313276.","journal-title":"Advances in Neural Information Processing Systems"},{"key":"e_1_3_1_53_2","first-page":"601","volume-title":"Proceedings of the 25th  \\(\\lbrace\\) USENIX \\(\\rbrace\\)  Security Symposium ( \\(\\lbrace\\) USENIX \\(\\rbrace\\)  Security 16)","author":"Tram\u00e8r Florian","year":"2016","unstructured":"Florian Tram\u00e8r, Fan Zhang, Ari Juels, Michael K. Reiter, and Thomas Ristenpart. 2016. Stealing machine learning models via prediction apis. In Proceedings of the 25th \\(\\lbrace\\) USENIX \\(\\rbrace\\) Security Symposium ( \\(\\lbrace\\) USENIX \\(\\rbrace\\) Security 16). 601\u2013618."},{"key":"e_1_3_1_54_2","doi-asserted-by":"publisher","DOI":"10.1109\/EuroSP.2019.00044"},{"key":"e_1_3_1_55_2","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2018.00038"},{"key":"e_1_3_1_56_2","doi-asserted-by":"publisher","DOI":"10.1021\/acs.molpharmaceut.9b00538"},{"key":"e_1_3_1_57_2","doi-asserted-by":"publisher","DOI":"10.1109\/MCI.2020.2976185"},{"key":"e_1_3_1_58_2","doi-asserted-by":"publisher","DOI":"10.1145\/3436755"},{"key":"e_1_3_1_59_2","unstructured":"Bargav Jayaraman Lingxiao Wang David Evans and Quanquan Gu. 2018. Distributed learning without distress: Privacy-preserving empirical risk minimization. InProceedings of the International Conference on Neural Information Processing Systems (NIPS\u201918). Curran Associates Inc. Red Hook NY USA 6346\u20136357."},{"key":"e_1_3_1_60_2","doi-asserted-by":"publisher","DOI":"10.29012\/jpc.v4i1.612"},{"key":"e_1_3_1_61_2","doi-asserted-by":"publisher","DOI":"10.5555\/1953048.2021036"},{"key":"e_1_3_1_62_2","first-page":"2451","article-title":"Probabilistic inference and differential privacy","volume":"23","author":"Williams Oliver","year":"2010","unstructured":"Oliver Williams and Frank McSherry. 2010. Probabilistic inference and differential privacy. Advances in Neural Information Processing Systems 23 (2010), 2451\u20132459.","journal-title":"Advances in Neural Information Processing Systems"},{"key":"e_1_3_1_63_2","doi-asserted-by":"publisher","DOI":"10.1145\/2792838.2800173"},{"key":"e_1_3_1_64_2","doi-asserted-by":"publisher","DOI":"10.1109\/CDC.2016.7798915"},{"key":"e_1_3_1_65_2","volume-title":"Advances in Neural Information Processing Systems","author":"Ligett Katrina","year":"2017","unstructured":"Katrina Ligett, Seth Neel, Aaron Roth, Bo Waggoner, and Steven Z. Wu. 2017. Accuracy first: Selecting a differential privacy level for accuracy constrained ERM. In Advances in Neural Information Processing Systems. I. Guyon, U. Von Luxburg, S. Bengio, H. Wallach, R. Fergus, S. Vishwanathan, and R. Garnett (Eds.), Vol. 30, Curran Associates, Inc."},{"key":"e_1_3_1_66_2","doi-asserted-by":"publisher","DOI":"10.1109\/GLOBECOM38437.2019.9014201"},{"key":"e_1_3_1_67_2","doi-asserted-by":"publisher","DOI":"10.1109\/JIOT.2020.3027586"},{"key":"e_1_3_1_68_2","doi-asserted-by":"publisher","unstructured":"Rui Hu Yuanxiong Guo and Yanmin Gong. 2024. Federated learning with sparsified model perturbation: Improving accuracy under client-level differential privacy. IEEE Transactions on Mobile Computing 23 8 (2024) 8242\u20138255. DOI:10.1109\/TMC.2023.3343288","DOI":"10.1109\/TMC.2023.3343288"},{"key":"e_1_3_1_69_2","volume-title":"Advances in Neural Information Processing Systems","author":"Chaudhuri Kamalika","year":"2008","unstructured":"Kamalika Chaudhuri and Claire Monteleoni. 2008. Privacy-preserving logistic regression. In Advances in Neural Information Processing Systems. D. Koller, D. Schuurmans, Y. Bengio, and L. Bottou (Eds.), Vol. 21, Curran Associates, Inc."},{"key":"e_1_3_1_70_2","first-page":"25.1\u201325.40","volume-title":"Proceedings of the 25th Annual Conference on Learning Theory (Proceedings of Machine Learning Research)","volume":"23","author":"Kifer Daniel","year":"2012","unstructured":"Daniel Kifer, Adam Smith, and Abhradeep Thakurta. 2012. Private convex empirical risk minimization and high-dimensional regression. In Proceedings of the 25th Annual Conference on Learning Theory (Proceedings of Machine Learning Research). Shie Mannor, Nathan Srebro, and Robert C. Williamson (Eds.), Vol. 23, PMLR, Edinburgh, Scotland, 25.1\u201325.40."},{"key":"e_1_3_1_71_2","doi-asserted-by":"crossref","unstructured":"Jun Zhang Zhenjie Zhang Xiaokui Xiao Yin Yang and Marianne Winslett. 2012. Functional mechanism: Regression analysis under differential privacy. 5 11 (July 2012) 1364\u20131375.","DOI":"10.14778\/2350229.2350253"},{"key":"e_1_3_1_72_2","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v30i1.10165"},{"key":"e_1_3_1_73_2","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2016.2607691"},{"key":"e_1_3_1_74_2","doi-asserted-by":"crossref","unstructured":"Jiaqi Zhang Kai Zheng Wenlong Mou and Liwei Wang. 2017. Efficient private ERM for smooth objectives. In Proceedings of the 26th International Joint Conference on Artificial Intelligence (IJCAI\u201917) AAAI Press Melbourne Australia 3922\u20133928.","DOI":"10.24963\/ijcai.2017\/548"},{"key":"e_1_3_1_75_2","doi-asserted-by":"publisher","DOI":"10.1109\/TBDATA.2018.2829886"},{"key":"e_1_3_1_76_2","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2019.2931068"},{"key":"e_1_3_1_77_2","first-page":"933","volume-title":"Proceedings of the 15th International Conference on Artificial Intelligence and Statistics (Proceedings of Machine Learning Research)","volume":"22","author":"Rajkumar Arun","year":"2012","unstructured":"Arun Rajkumar and Shivani Agarwal. 2012. A differentially private stochastic gradient descent algorithm for multiparty classification. In Proceedings of the 15th International Conference on Artificial Intelligence and Statistics (Proceedings of Machine Learning Research). Neil D. Lawrence and Mark Girolami (Eds.), Vol. 22, PMLR, La Palma, Canary Islands, 933\u2013941."},{"key":"e_1_3_1_78_2","volume-title":"Advances in Neural Information Processing Systems","author":"Wang Di","year":"2017","unstructured":"Di Wang, Minwei Ye, and Jinhui Xu. 2017. Differentially private empirical risk minimization revisited: Faster and more general. In Advances in Neural Information Processing Systems. I. Guyon, U. Von Luxburg, S. Bengio, H. Wallach, R. Fergus, S. Vishwanathan, and R. Garnett (Eds.), Vol. 30, Curran Associates, Inc."},{"key":"e_1_3_1_79_2","doi-asserted-by":"publisher","DOI":"10.1145\/3035918.3064047"},{"key":"e_1_3_1_80_2","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2020.2988575"},{"key":"e_1_3_1_81_2","doi-asserted-by":"publisher","DOI":"10.1109\/JIOT.2020.3037194"},{"key":"e_1_3_1_82_2","doi-asserted-by":"crossref","unstructured":"Da Yu Huishuai Zhang Wei Chen Jian Yin and Tie-Yan Liu. 2021. Gradient perturbation is underrated for differentially private convex optimization. In Proceedings of the Twenty-Ninth International Joint Conference on Artificial Intelligence (IJCAI\u201920) Yokohama Yokohama Japan.","DOI":"10.24963\/ijcai.2020\/431"},{"key":"e_1_3_1_83_2","unstructured":"Da Yu Huishuai Zhang Wei Chen and Tie-Yan Liu. 2021. Do not let privacy overbill utility: Gradient embedding perturbation for private learning. In International Conference on Learning Representations (ICLR)."},{"key":"e_1_3_1_84_2","doi-asserted-by":"publisher","DOI":"10.1007\/s00521-022-07393-0"},{"key":"e_1_3_1_85_2","doi-asserted-by":"publisher","DOI":"10.1109\/MSEC.2018.2888775"},{"issue":"3","key":"e_1_3_1_86_2","first-page":"4","article-title":"Robust physical-world attacks on machine learning models","volume":"2","author":"Evtimov Ivan","year":"2017","unstructured":"Ivan Evtimov, Kevin Eykholt, Earlence Fernandes, Tadayoshi Kohno, Bo Li, Atul Prakash, Amir Rahmati, and Dawn Song. 2017. Robust physical-world attacks on machine learning models. arXiv preprint arXiv:1707.08945 2, 3 (2017), 4.","journal-title":"arXiv preprint arXiv:1707.08945"},{"key":"e_1_3_1_87_2","first-page":"22205","article-title":"Auditing differentially private machine learning: How private is private SGD?","volume":"33","author":"Jagielski Matthew","year":"2020","unstructured":"Matthew Jagielski, Jonathan Ullman, and Alina Oprea. 2020. Auditing differentially private machine learning: How private is private SGD? Advances in Neural Information Processing Systems 33 (2020), 22205\u201322216.","journal-title":"Advances in Neural Information Processing Systems"},{"key":"e_1_3_1_88_2","doi-asserted-by":"publisher","DOI":"10.1109\/ACC.2016.7525222"},{"key":"e_1_3_1_89_2","doi-asserted-by":"publisher","DOI":"10.1080\/0740817X.2010.541899"},{"key":"e_1_3_1_90_2","doi-asserted-by":"publisher","DOI":"10.1109\/TCSVT.2023.3261333"},{"key":"e_1_3_1_91_2","doi-asserted-by":"publisher","DOI":"10.1109\/9.119632"},{"key":"e_1_3_1_92_2","doi-asserted-by":"publisher","DOI":"10.1145\/2723372.2747643"},{"issue":"2","key":"e_1_3_1_93_2","first-page":"43","article-title":"Random differential privacy","volume":"4","author":"Hall Rob","year":"2012","unstructured":"Rob Hall, Alessandro Rinaldo, and Larry Wasserman. 2012. Random differential privacy. Journal of Privacy and Confidentiality 4, 2 (2012), 43\u201359.","journal-title":"Journal of Privacy and Confidentiality"},{"key":"e_1_3_1_94_2","unstructured":"Zijian Zhang Zhan Qin Liehuang Zhu Wei Jiang Chen Xu and Kui Ren. 2015. Toward practical differential privacy in smart grid with capacity-limited rechargeable batteries. arXiv:1507.03000. Retrieved from https:\/\/arxiv.org\/abs\/1507.03000"},{"key":"e_1_3_1_95_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-662-53641-4_24"},{"key":"e_1_3_1_96_2","doi-asserted-by":"publisher","DOI":"10.1109\/CSF.2017.11"},{"key":"e_1_3_1_97_2","doi-asserted-by":"publisher","DOI":"10.1109\/JIOT.2019.2952146"},{"key":"e_1_3_1_98_2","unstructured":"L\u00e9o Colisson. 2016. L3 internship report: Quantum analog of differential privacy in term of R\u00e9nyi divergence. (2016)."},{"issue":"23","key":"e_1_3_1_99_2","article-title":"Deep learning with Gaussian differential privacy","volume":"2020","author":"Bu Zhiqi","year":"2020","unstructured":"Zhiqi Bu, Jinshuo Dong, Qi Long, and Weijie J. Su. 2020. Deep learning with Gaussian differential privacy. Harvard Data Science Review 2020, 23 (2020), 1\u201340.","journal-title":"Harvard Data Science Review"},{"key":"e_1_3_1_100_2","doi-asserted-by":"publisher","DOI":"10.1109\/MSP.2012.2211477"}],"container-title":["ACM Computing Surveys"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3729216","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,7,17]],"date-time":"2025-07-17T13:25:53Z","timestamp":1752758753000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3729216"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,7,12]]},"references-count":99,"journal-issue":{"issue":"12","published-print":{"date-parts":[[2025,12,31]]}},"alternative-id":["10.1145\/3729216"],"URL":"https:\/\/doi.org\/10.1145\/3729216","relation":{},"ISSN":["0360-0300","1557-7341"],"issn-type":[{"value":"0360-0300","type":"print"},{"value":"1557-7341","type":"electronic"}],"subject":[],"published":{"date-parts":[[2025,7,12]]},"assertion":[{"value":"2023-12-12","order":0,"name":"received","label":"Received","group":{"name":"publication_history","label":"Publication History"}},{"value":"2025-04-02","order":2,"name":"accepted","label":"Accepted","group":{"name":"publication_history","label":"Publication History"}},{"value":"2025-07-12","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}