{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,4]],"date-time":"2026-06-04T16:03:28Z","timestamp":1780589008885,"version":"3.54.1"},"publisher-location":"New York, NY, USA","reference-count":57,"publisher":"ACM","license":[{"start":{"date-parts":[[2026,6,1]],"date-time":"2026-06-01T00:00:00Z","timestamp":1780272000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/legalcode"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2026,6]]},"DOI":"10.1145\/3779208.3785288","type":"proceedings-article","created":{"date-parts":[[2026,6,4]],"date-time":"2026-06-04T15:21:58Z","timestamp":1780586518000},"page":"1755-1769","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":0,"title":["Auditing Differentially Private Interactive Database Systems"],"prefix":"10.1145","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-6667-4724","authenticated-orcid":false,"given":"Sagar","family":"Sharma","sequence":"first","affiliation":[{"name":"TikTok Inc., Bellevue, Washington, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-2393-2308","authenticated-orcid":false,"given":"Wanrong","family":"Zhang","sequence":"additional","affiliation":[{"name":"TikTok Inc., San Jose, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-7044-6142","authenticated-orcid":false,"given":"Qiang","family":"Yan","sequence":"additional","affiliation":[{"name":"TikTok Inc., Shanghai, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-8703-8762","authenticated-orcid":false,"given":"Florian","family":"Tramer","sequence":"additional","affiliation":[{"name":"ETH Zurich, Zurich, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2026,6,4]]},"reference":[{"key":"e_1_3_2_1_1_1","doi-asserted-by":"publisher","DOI":"10.1109\/CSF51468.2021.00043"},{"key":"e_1_3_2_1_2_1","doi-asserted-by":"publisher","DOI":"10.1145\/3243734.3243863"},{"key":"e_1_3_2_1_3_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP40001.2021.00081"},{"key":"e_1_3_2_1_4_1","doi-asserted-by":"publisher","DOI":"10.1145\/3132747.3132769"},{"key":"e_1_3_2_1_5_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-662-53641-4_24"},{"key":"e_1_3_2_1_6_1","doi-asserted-by":"publisher","DOI":"10.1145\/2591796.2591877"},{"key":"e_1_3_2_1_7_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP46214.2022.9833649"},{"key":"e_1_3_2_1_8_1","doi-asserted-by":"publisher","DOI":"10.1145\/3548606.3560708"},{"key":"e_1_3_2_1_9_1","unstructured":"Mark Cesar and Ryan Rogers. 2021. Bounding concentrating and truncating: Unifying privacy loss composition for data analytics. In Algorithmic Learning Theory. PMLR 421\u2014457."},{"key":"e_1_3_2_1_10_1","doi-asserted-by":"publisher","DOI":"10.1145\/3548606.3560581"},{"key":"e_1_3_2_1_11_1","volume-title":"Proceedings of the 2021 ACM SIGSAC Conference on Computer and Communications Security. 3037\u20133052","author":"Cummings Rachel","year":"2021","unstructured":"Rachel Cummings, Gabriel Kaptchuk, and Elissa M Redmiles. 2021. \u201c I need a better description\u201d: An Investigation Into User Expectations For Differential Privacy. In Proceedings of the 2021 ACM SIGSAC Conference on Computer and Communications Security. 3037\u20133052."},{"key":"e_1_3_2_1_12_1","doi-asserted-by":"publisher","DOI":"10.1145\/3243734.3243818"},{"key":"e_1_3_2_1_13_1","doi-asserted-by":"publisher","DOI":"10.1145\/773153.773173"},{"key":"e_1_3_2_1_14_1","volume-title":"TCC 2006, New York, NY, USA, March 4-7, 2006. Proceedings 3. Springer, 265\u2014284","author":"Dwork Cynthia","year":"2006","unstructured":"Cynthia Dwork, Frank McSherry, Kobbi Nissim, and Adam Smith. 2006. Calibrating noise to sensitivity in private data analysis. In Theory of Cryptography : Third Theory of Cryptography Conference, TCC 2006, New York, NY, USA, March 4-7, 2006. Proceedings 3. Springer, 265\u2014284."},{"key":"e_1_3_2_1_15_1","volume-title":"The algorithmic foundations of differential privacy. Foundations and Trends\u00ae in Theoretical Computer Science 9, 3\u20134","author":"Dwork Cynthia","year":"2014","unstructured":"Cynthia Dwork and Aaron Roth. 2014. The algorithmic foundations of differential privacy. Foundations and Trends\u00ae in Theoretical Computer Science 9, 3\u20134 (2014), 211\u2013407."},{"key":"e_1_3_2_1_16_1","doi-asserted-by":"publisher","DOI":"10.1109\/FOCS.2015.46"},{"key":"e_1_3_2_1_17_1","doi-asserted-by":"publisher","DOI":"10.1145\/2660267.2660348"},{"key":"e_1_3_2_1_18_1","volume-title":"Sebastian Probst Eide, and Reinhard Munz","author":"Francis Paul","year":"2017","unstructured":"Paul Francis, Sebastian Probst Eide, and Reinhard Munz. 2017. Diffix: High-utility database anonymization. In Privacy Technologies and Policy: 5th Annual Privacy Forum, APF 2017, Vienna, Austria, June 7-8, 2017, Revised Selected Papers 5. Springer, 141\u2013158."},{"key":"e_1_3_2_1_19_1","unstructured":"Marco Gaboardi Michael Hay and Salil Vadhan. 2020. A programming framework for opendp."},{"key":"e_1_3_2_1_20_1","volume-title":"28th USENIX Security Symposium (USENIX Security 19)","author":"Gadotti Andrea","year":"2019","unstructured":"Andrea Gadotti, Florimond Houssiau, Luc Rocher, Benjamin Livshits, and Yves-Alexandre De Montjoye. 2019. When the signal is in the noise: Exploiting diffix's sticky noise. In 28th USENIX Security Symposium (USENIX Security 19). 1081\u20131098."},{"key":"e_1_3_2_1_21_1","doi-asserted-by":"crossref","unstructured":"Simson Garfinkel. 2022. Differential privacy and the 2020 us census. (2022).","DOI":"10.21428\/2c646de5.7ec6ab93"},{"key":"e_1_3_2_1_22_1","unstructured":"Hans Graux and Dear Mr Graux. 2018. Article 29 data protection Working Party. ec.europa.eu\/newsroom\/document.cfm(2018)."},{"key":"e_1_3_2_1_23_1","volume-title":"P\u00f3l Mac Aonghusa, and Killian Levacher","author":"Holohan Naoise","year":"2019","unstructured":"Naoise Holohan, Stefano Braghin, P\u00f3l Mac Aonghusa, and Killian Levacher. 2019. Diffprivlib: the IBM differential privacy library. ArXiv e-prints 1907.02444 [cs.CR] (July 2019)."},{"key":"e_1_3_2_1_24_1","volume-title":"Resolving individuals contributing trace amounts of DNA to highly complex mixtures using high-density SNP genotyping microarrays. PLoS genetics 4, 8","author":"Homer Nils","year":"2008","unstructured":"Nils Homer, Szabolcs Szelinger, Margot Redman, David Duggan, Waibhav Tembe, Jill Muehling, John V Pearson, Dietrich A Stephan, Stanley F Nelson, and David W Craig. 2008. Resolving individuals contributing trace amounts of DNA to highly complex mixtures using high-density SNP genotyping microarrays. PLoS genetics 4, 8 (2008), el000167."},{"key":"e_1_3_2_1_25_1","first-page":"22205","article-title":"Auditing differentially private machine learning: How private is private SGD","volume":"33","author":"Jagielski Matthew","year":"2020","unstructured":"Matthew Jagielski, Jonathan Ullman, and Alina Oprea. 2020. Auditing differentially private machine learning: How private is private SGD? Advances in Neural Information Processing Systems 33 (2020), 22205\u201322216.","journal-title":"Advances in Neural Information Processing Systems"},{"key":"e_1_3_2_1_26_1","doi-asserted-by":"publisher","DOI":"10.1109\/EuroSP48549.2020.00041"},{"key":"e_1_3_2_1_27_1","doi-asserted-by":"publisher","DOI":"10.1145\/3187009.3177733"},{"key":"e_1_3_2_1_28_1","volume-title":"International conference on machine learning. PMLR, 1376\u20131385","author":"Kairouz Peter","year":"2015","unstructured":"Peter Kairouz, Sewoong Oh, and Pramod Viswanath. 2015. The composition theorem for differential privacy. In International conference on machine learning. PMLR, 1376\u20131385."},{"key":"e_1_3_2_1_29_1","volume-title":"DP-Auditorium: A Large Scale Library for Auditing Differential Privacy. In 2024 IEEE Symposium on Security and Privacy (SP). IEEE Computer Society, 219\u2013219","author":"Kong William","year":"2024","unstructured":"William Kong, Andres Munoz Medina, Monica Ribero, and Umar Syed. 2024. DP-Auditorium: A Large Scale Library for Auditing Differential Privacy. In 2024 IEEE Symposium on Security and Privacy (SP). IEEE Computer Society, 219\u2013219."},{"key":"e_1_3_2_1_30_1","doi-asserted-by":"publisher","DOI":"10.14778\/3342263.3342274"},{"key":"e_1_3_2_1_31_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-24861-0_22"},{"key":"e_1_3_2_1_32_1","volume-title":"Kai Ming Ting, and Zhi-Hua Zhou","author":"Liu Fei Tony","year":"2008","unstructured":"Fei Tony Liu, Kai Ming Ting, and Zhi-Hua Zhou. 2008. Isolation forest. In 2008 eighth ieee international conference on data mining. IEEE, 413\u2013422."},{"key":"e_1_3_2_1_33_1","doi-asserted-by":"publisher","DOI":"10.1145\/3576915.3616607"},{"key":"e_1_3_2_1_34_1","first-page":"4165","article-title":"A general framework for auditing differentially private machine learning","volume":"35","author":"Lu Fred","year":"2022","unstructured":"Fred Lu, Joseph Munoz, Maya Fuchs, Tyler LeBlond, Elliott Zaresky-Williams, Edward Raff, Francis Ferraro, and Brian Testa. 2022. A general framework for auditing differentially private machine learning. Advances in Neural Information Processing Systems 35 (2022), 4165\u20134176.","journal-title":"Advances in Neural Information Processing Systems"},{"key":"e_1_3_2_1_35_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP54263.2024.00166"},{"key":"e_1_3_2_1_36_1","doi-asserted-by":"publisher","DOI":"10.1145\/1559845.1559850"},{"key":"e_1_3_2_1_37_1","doi-asserted-by":"publisher","DOI":"10.1109\/EuroSPW54576.2021.00041"},{"key":"e_1_3_2_1_38_1","doi-asserted-by":"publisher","DOI":"10.1145\/2382196.2382264"},{"key":"e_1_3_2_1_39_1","volume-title":"R\u00e9nyi differential privacy. In 2017 IEEE 30th computer security foundations symposium (CSF)","author":"Mironov Ilya","unstructured":"Ilya Mironov. 2017. R\u00e9nyi differential privacy. In 2017 IEEE 30th computer security foundations symposium (CSF). IEEE, 263\u2013275."},{"key":"e_1_3_2_1_40_1","volume-title":"32nd USENIX Security Symposium (USENIX Security 23)","author":"Nanayakkara Priyanka","year":"2023","unstructured":"Priyanka Nanayakkara, Mary Anne Smart, Rachel Cummings, Gabriel Kaptchuk, and Elissa M Redmiles. 2023. What are the chances? explaining the epsilon parameter in differential privacy. In 32nd USENIX Security Symposium (USENIX Security 23). 1613\u20131630."},{"key":"e_1_3_2_1_41_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2008.33"},{"key":"e_1_3_2_1_42_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP40001.2021.00069"},{"key":"e_1_3_2_1_43_1","doi-asserted-by":"publisher","DOI":"10.1145\/3360598"},{"key":"e_1_3_2_1_44_1","unstructured":"Joseph P Near David Darais Naomi Lefkovitz Gary Howarth et al. 2023. Guidelines for evaluating differential privacy guarantees. National Institute of Standards and Technology Tech. Rep (2023)."},{"key":"e_1_3_2_1_45_1","doi-asserted-by":"publisher","DOI":"10.1145\/1863543.1863568"},{"key":"e_1_3_2_1_46_1","volume-title":"Shraddha Sahay, and Parvez Ahammad.","author":"Rogers Ryan","year":"2020","unstructured":"Ryan Rogers, Subbu Subramaniam, Sean Peng, David Durfee, Seunghyun Lee, Santosh Kumar Kancha, Shraddha Sahay, and Parvez Ahammad. 2020. LinkedIn's Audience Engagements API: A privacy preserving data analytics system at scale. arXiv preprint arXiv:2002.05839 (2020)."},{"key":"e_1_3_2_1_47_1","doi-asserted-by":"publisher","DOI":"10.56553\/popets-2022-0111"},{"key":"e_1_3_2_1_48_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.41"},{"key":"e_1_3_2_1_49_1","doi-asserted-by":"publisher","DOI":"10.1145\/1993636.1993743"},{"key":"e_1_3_2_1_50_1","unstructured":"Thomas Steinke. 2022. Composition of Differential Privacy & Privacy Amplification by Subsampling. arXiv:2210.00597 [cs.CR] https:\/\/arxiv.org\/abs\/2210.00597"},{"key":"e_1_3_2_1_51_1","volume-title":"Privacy auditing with one (1) training run. Advances in Neural Information Processing Systems 36","author":"Steinke Thomas","year":"2024","unstructured":"Thomas Steinke, Milad Nasr, and Matthew Jagielski. 2024. Privacy auditing with one (1) training run. Advances in Neural Information Processing Systems 36 (2024)."},{"key":"e_1_3_2_1_52_1","volume-title":"Privacy loss in apple's implementation of differential privacy on macos 10.12. arXiv preprint arXiv:1709.02753","author":"Tang Jun","year":"2017","unstructured":"Jun Tang, Aleksandra Korolova, Xiaolong Bai, Xueqiang Wang, and Xiaofeng Wang. 2017. Privacy loss in apple's implementation of differential privacy on macos 10.12. arXiv preprint arXiv:1709.02753 (2017)."},{"key":"e_1_3_2_1_53_1","doi-asserted-by":"publisher","DOI":"10.1145\/3318464.3389698"},{"key":"e_1_3_2_1_54_1","volume-title":"Debugging differential privacy: A case study for privacy auditing. arXiv preprint arXiv:2202.12219","author":"Tramer Florian","year":"2022","unstructured":"Florian Tramer, Andreas Terzis, Thomas Steinke, Shuang Song, Matthew Jagielski, and Nicholas Carlini. 2022. Debugging differential privacy: A case study for privacy auditing. arXiv preprint arXiv:2202.12219 (2022)."},{"key":"e_1_3_2_1_55_1","unstructured":"TikTok US. 2024. TikTok Research API - TikTok for Developers. https:\/\/developers.tiktok.com\/doc\/research-api-get-started."},{"key":"e_1_3_2_1_56_1","doi-asserted-by":"publisher","DOI":"10.1145\/3372297.3417282"},{"key":"e_1_3_2_1_57_1","volume-title":"William Lam, Damien Desfontaines, Daniel Simmons-Marengo, and Bryant Gipson.","author":"Wilson Royce J","year":"2019","unstructured":"Royce J Wilson, Celia Yuxin Zhang, William Lam, Damien Desfontaines, Daniel Simmons-Marengo, and Bryant Gipson. 2019. Differentially private sql with bounded user contribution. arXiv preprint arXiv:1909. 01917 (2019)."}],"event":{"name":"ASIA CCS '26: ACM Asia Conference on Computer and Communications Security","location":"Bangalore India","acronym":"ASIA CCS '26","sponsor":["SIGSAC ACM Special Interest Group on Security, Audit, and Control"]},"container-title":["Proceedings of the ACM Asia Conference on Computer and Communications Security"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3779208.3785288","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,6,4]],"date-time":"2026-06-04T15:40:51Z","timestamp":1780587651000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3779208.3785288"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,6]]},"references-count":57,"alternative-id":["10.1145\/3779208.3785288","10.1145\/3779208"],"URL":"https:\/\/doi.org\/10.1145\/3779208.3785288","relation":{},"subject":[],"published":{"date-parts":[[2026,6]]},"assertion":[{"value":"2026-06-04","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}