{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,23]],"date-time":"2026-06-23T10:51:54Z","timestamp":1782211914640,"version":"3.54.5"},"reference-count":139,"publisher":"Association for Computing Machinery (ACM)","issue":"13","license":[{"start":{"date-parts":[[2026,6,23]],"date-time":"2026-06-23T00:00:00Z","timestamp":1782172800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/legalcode"}],"funder":[{"name":"Alan Turing Institute under the Turing\/Accenture","award":["R-AST-040"],"award-info":[{"award-number":["R-AST-040"]}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["ACM Comput. Surv."],"published-print":{"date-parts":[[2026,10,31]]},"abstract":"<jats:p>Generative models are extremely widely used, both in research and practice. Although many studies have shown privacy threats against generative models or proposed privacy protections, there is no systematic survey on which metrics should be used to quantify privacy and utility of generative models. In this article, we therefore present new taxonomies for privacy and utility metrics for generative models, including taxonomies for attacks against generative models and a discussion of the most common approaches for privacy protection. We also propose guidelines for selecting appropriate metrics in specific scenarios and show commonly used metrics in several use cases. Finally, we discuss open challenges and promising future research directions.<\/jats:p>","DOI":"10.1145\/3815777","type":"journal-article","created":{"date-parts":[[2026,5,22]],"date-time":"2026-05-22T11:20:41Z","timestamp":1779448841000},"page":"1-35","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":1,"title":["Metrics for Privacy-Preserving Generative Models: A Comprehensive Survey"],"prefix":"10.1145","volume":"58","author":[{"ORCID":"https:\/\/orcid.org\/0000-0003-0493-8939","authenticated-orcid":false,"given":"Debalina","family":"Padariya","sequence":"first","affiliation":[{"name":"Cyber Technology Institute, School of Computer Science and Informatics, De Montfort University Faculty of Computing Engineering and Media","place":["Leicester, United Kingdom of Great Britain and Northern Ireland"]}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-0242-6278","authenticated-orcid":false,"given":"Isabel","family":"Wagner","sequence":"additional","affiliation":[{"name":"Department of Mathematics and Computer Science, University of Basel","place":["Basel, Switzerland"]}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-3627-6362","authenticated-orcid":false,"given":"Aboozar","family":"Taherkhani","sequence":"additional","affiliation":[{"name":"School of Computer Science and Informatics, De Montfort University Faculty of Computing Engineering and Media","place":["Leicester, United Kingdom of Great Britain and Northern Ireland"]}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-9184-8968","authenticated-orcid":false,"given":"Eerke A.","family":"Boiten","sequence":"additional","affiliation":[{"name":"School of Computer Science and Informatics, De Montfort University Faculty of Computing Engineering and Media","place":["Leicester, United Kingdom of Great Britain and Northern Ireland"]}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2026,6,23]]},"reference":[{"key":"e_1_3_1_2_2","doi-asserted-by":"crossref","first-page":"308","DOI":"10.1145\/2976749.2978318","volume-title":"Proceedings of the 2016 ACM SIGSAC Conference on Computer and Communications Security","author":"Abadi Martin","year":"2016","unstructured":"Martin Abadi, Andy Chu, Ian Goodfellow, H. Brendan McMahan, Ilya Mironov, Kunal Talwar, and Li Zhang. 2016. Deep learning with differential privacy. In Proceedings of the 2016 ACM SIGSAC Conference on Computer and Communications Security. ACM, Vienna Austria, 308\u2013318. DOI:10.1145\/2976749.2978318"},{"key":"e_1_3_1_3_2","first-page":"715","volume-title":"Proceedings of the 2017 IEEE International Conference on Data Mining (ICDM)","author":"Acs Gergely","year":"2017","unstructured":"Gergely Acs, Luca Melis, Claude Castelluccia, and Emiliano De Cristofaro. 2017. Differentially private mixture of generative neural networks. In Proceedings of the 2017 IEEE International Conference on Data Mining (ICDM). IEEE, New Orleans, LA, 715\u2013720. DOI:10.1109\/ICDM.2017.81"},{"key":"e_1_3_1_4_2","volume-title":"Differential Privacy Synthetic Data Generation Using WGANs","author":"Alzantot Moustafa","year":"2019","unstructured":"Moustafa Alzantot and Mani Srivastava. 2019. Differential Privacy Synthetic Data Generation Using WGANs. Retrieved from https:\/\/github.com\/nesl\/nist_differential_privacy_synthetic_data_challenge"},{"key":"e_1_3_1_5_2","first-page":"214","volume-title":"Proceedings of the 34th International Conference on Machine Learning","author":"Arjovsky Martin","year":"2017","unstructured":"Martin Arjovsky, Soumith Chintala, and L\u00e9on Bottou. 2017. Wasserstein generative adversarial networks. In Proceedings of the 34th International Conference on Machine Learning. PMLR, Sydney, Australia, 214\u2013223. Retrieved from https:\/\/proceedings.mlr.press\/v70\/arjovsky17a.html"},{"key":"e_1_3_1_6_2","doi-asserted-by":"publisher","DOI":"10.1016\/0169-2070(92)90008-W"},{"key":"e_1_3_1_7_2","doi-asserted-by":"publisher","DOI":"10.1161\/CIRCOUTCOMES.118.005122"},{"key":"e_1_3_1_8_2","first-page":"51","article-title":"Privacy and synthetic datasets","volume":"22","author":"Bellovin Steven M.","year":"2019","unstructured":"Steven M. Bellovin, Preetam K. Dutta, and Nathan Reitinger. 2019. Privacy and synthetic datasets. Stanford Technology Law Review 22, 1 (2019), 51.","journal-title":"Stanford Technology Law Review"},{"key":"e_1_3_1_9_2","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"crossref","first-page":"3","DOI":"10.1007\/978-3-031-10684-2_1","volume-title":"Proceedings of the Data and Applications Security and Privacy XXXVI.","author":"Bernau Daniel","year":"2022","unstructured":"Daniel Bernau, Jonas Robl, and Florian Kerschbaum. 2022. Assessing differentially private variational autoencoders under membership inference. In Proceedings of the Data and Applications Security and Privacy XXXVI.Shamik Sural and Haibing Lu (Eds.), Lecture Notes in Computer Science, Springer International Publishing, Cham, 3\u201314. DOI:10.1007\/978-3-031-10684-2_1"},{"key":"e_1_3_1_10_2","unstructured":"Blake Bullwinkel Kristen Grabarz Lily Ke Scarlett Gong Chris Tanner and Joshua Allen. 2022. Evaluating the Fairness Impact of Differentially Private Synthetic Data. arXiv:2205.04321. Retrieved from https:\/\/arxiv.org\/abs\/2205.04321"},{"key":"e_1_3_1_11_2","doi-asserted-by":"publisher","DOI":"10.1145\/3459992"},{"key":"e_1_3_1_12_2","first-page":"55","volume-title":"Proceedings of the Progress in Artificial Intelligence","author":"Carvalho T\u00e2nia","year":"2023","unstructured":"T\u00e2nia Carvalho, Nuno Moniz, and Lu\u00eds Antunes. 2023. A three-way knot: Privacy, fairness, and predictive performance dynamics. In Proceedings of the Progress in Artificial Intelligence. Nuno Moniz, Zita Vale, Jos\u00e9 Cascalho, Catarina Silva, and Raquel Sebasti\u00e3o (Eds.), Springer Nature Switzerland, Cham, 55\u201366. DOI:10.1007\/978-3-031-49008-8_5"},{"key":"e_1_3_1_13_2","first-page":"1","volume-title":"Proceedings of the 2021 IEEE International Workshop on Information Forensics and Security (WIFS)","author":"Chen Dongjie","year":"2021","unstructured":"Dongjie Chen, Sen-ching Samson Cheung, Chen-Nee Chuah, and Sally Ozonoff. 2021. Differentially private generative adversarial networks with model inversion. In Proceedings of the 2021 IEEE International Workshop on Information Forensics and Security (WIFS). IEEE, Montpellier, France, 1\u20136. DOI:10.1109\/WIFS53200.2021.9648378"},{"key":"e_1_3_1_14_2","first-page":"12673","volume-title":"Proceedings of the 34th International Conference on Neural Information Processing Systems (NIPS\u201920)","author":"Chen Dingfan","year":"2020","unstructured":"Dingfan Chen, Tribhuvanesh Orekondy, and Mario Fritz. 2020. GS-WGAN: A gradient-sanitized approach for learning differentially private generators. In Proceedings of the 34th International Conference on Neural Information Processing Systems (NIPS\u201920). Curran Associates Inc., Red Hook, NY, USA, 12673\u201312684."},{"key":"e_1_3_1_15_2","doi-asserted-by":"crossref","first-page":"343","DOI":"10.1145\/3372297.3417238","volume-title":"Proceedings of the 2020 ACM SIGSAC Conference on Computer and Communications Security","author":"Chen Dingfan","year":"2020","unstructured":"Dingfan Chen, Ning Yu, Yang Zhang, and Mario Fritz. 2020. GAN-leaks: A taxonomy of membership inference attacks against generative models. In Proceedings of the 2020 ACM SIGSAC Conference on Computer and Communications Security. ACM, Virtual Event USA, 343\u2013362. DOI:10.1145\/3372297.3417238"},{"key":"e_1_3_1_16_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.neucom.2022.05.039"},{"key":"e_1_3_1_17_2","first-page":"1651","volume-title":"Proceedings of the 2018 IEEE\/CVF Conference on Computer Vision and Pattern Recognition Workshops (CVPRW)","author":"Chen Jiawei","year":"2018","unstructured":"Jiawei Chen, Janusz Konrad, and Prakash Ishwar. 2018. VGAN-based image representation learning for privacy-preserving facial expression recognition. In Proceedings of the 2018 IEEE\/CVF Conference on Computer Vision and Pattern Recognition Workshops (CVPRW). IEEE, Salt Lake City, UT, USA, 1651\u2013165109. DOI:10.1109\/CVPRW.2018.00207"},{"key":"e_1_3_1_18_2","first-page":"127","volume-title":"Proceedings of the 27th ACM SIGKDD Conference on Knowledge Discovery and Data Mining","author":"Chen Junjie","year":"2021","unstructured":"Junjie Chen, Wendy Hui Wang, Hongchang Gao, and Xinghua Shi. 2021. PAR-GAN: Improving the generalization of generative adversarial networks against membership inference attacks. In Proceedings of the 27th ACM SIGKDD Conference on Knowledge Discovery and Data Mining. ACM, Virtual Event Singapore, 127\u2013137. DOI:10.1145\/3447548.3467445"},{"key":"e_1_3_1_19_2","first-page":"10833","volume-title":"Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition","author":"Chen Tianwei","year":"2024","unstructured":"Tianwei Chen, Yusuke Hirota, Mayu Otani, Noa Garcia, and Yuta Nakashima. 2024. Would deep generative models amplify bias in future models?. In Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition. IEEE, Seattle Convention Center, 10833\u201310843. Retrieved from https:\/\/openaccess.thecvf.com\/content\/CVPR2024\/html\/Chen_Would_Deep_Generative_Models_Amplify_Bias_in_Future_Models_CVPR_2024_paper.html"},{"key":"e_1_3_1_20_2","doi-asserted-by":"crossref","first-page":"149","DOI":"10.1145\/3442188.3445879","volume-title":"Proceedings of the 2021 ACM Conference on Fairness, Accountability, and Transparency","author":"Cheng Victoria","year":"2021","unstructured":"Victoria Cheng, Vinith M. Suriyakumar, Natalie Dullerud, Shalmali Joshi, and Marzyeh Ghassemi. 2021. Can you fake it until you make it?: Impacts of differentially private synthetic data on downstream classification fairness. In Proceedings of the 2021 ACM Conference on Fairness, Accountability, and Transparency. ACM, Virtual Event Canada, 149\u2013160. DOI:10.1145\/3442188.3445879"},{"key":"e_1_3_1_21_2","first-page":"286","volume-title":"Proceedings of the Machine Learning for Healthcare Conference","author":"Choi Edward","year":"2017","unstructured":"Edward Choi, Siddharth Biswal, Bradley Malin, Jon Duke, Walter F. Stewart, and Jimeng Sun. 2017. Generating multi-label discrete patient records using generative adversarial networks. In Proceedings of the Machine Learning for Healthcare Conference. PMLR, PMLR, Boston, Massachusetts, USA, 286\u2013305."},{"key":"e_1_3_1_22_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.future.2021.11.032"},{"key":"e_1_3_1_23_2","first-page":"1","volume-title":"Proceedings of the International Conference on Learning Representations (ICLR) 2024","author":"Ding Youlong","year":"2024","unstructured":"Youlong Ding, Xueyang Wu, Yining Meng, Yonggang Luo, Hao Wang, and Weike Pan. 2024. Delving into differentially private transformer. In Proceedings of the International Conference on Learning Representations (ICLR) 2024. OpenReview.net, Online, 1\u201318. Retrieved from https:\/\/openreview.net\/forum?id=FzyMdAm2fZ"},{"key":"e_1_3_1_24_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.ecolind.2012.12.025"},{"key":"e_1_3_1_25_2","first-page":"1","article-title":"Differentially private diffusion models","author":"Dockhorn Tim","year":"2023","unstructured":"Tim Dockhorn, Tianshi Cao, Arash Vahdat, and Karsten Kreis. 2023. Differentially private diffusion models. Transactions on Machine Learning Research(2023), 1\u201344. Retrieved from https:\/\/openreview.net\/forum?id=ZPpQk7FJXF","journal-title":"Transactions on Machine Learning Research"},{"key":"e_1_3_1_26_2","first-page":"1","article-title":"Do membership inference attacks work on large language models?","author":"Duan Michael","year":"2024","unstructured":"Michael Duan, Anshuman Suri, Niloofar Mireshghallah, Sewon Min, Weijia Shi, Luke Zettlemoyer, Yulia Tsvetkov, Yejin Choi, David Evans, and Hannaneh Hajishirzi. 2024. Do membership inference attacks work on large language models? First Conference on Language Modeling(2024), 1\u201333. Retrieved from https:\/\/openreview.net\/forum?id=av0D19pSkU","journal-title":"First Conference on Language Modeling"},{"key":"e_1_3_1_27_2","first-page":"1","volume-title":"Proceedings of the Theory and Applications of Models of Computation (Lecture Notes in Computer Science)","author":"Dwork Cynthia","year":"2008","unstructured":"Cynthia Dwork. 2008. Differential privacy: A survey of results. In Proceedings of the Theory and Applications of Models of Computation (Lecture Notes in Computer Science). Manindra Agrawal, Dingzhu Du, Zhenhua Duan, and Angsheng Li (Eds.), Springer, Berlin,1\u201319. DOI:10.1007\/978-3-540-79228-4_1"},{"key":"e_1_3_1_28_2","first-page":"8","volume-title":"Proceedings of the AAAI Workshop on Privacy-Preserving Artificial Intelligence","author":"Fan Liyue","year":"2020","unstructured":"Liyue Fan. 2020. A survey of differentially private generative adversarial networks. In Proceedings of the AAAI Workshop on Privacy-Preserving Artificial Intelligence. AAAI, New York, USA, 8."},{"key":"e_1_3_1_29_2","first-page":"1322","volume-title":"Proceedings of the 22nd ACM SIGSAC Conference on Computer and Communications Security (CCS\u201915)","author":"Fredrikson Matt","year":"2015","unstructured":"Matt Fredrikson, Somesh Jha, and Thomas Ristenpart. 2015. Model inversion attacks that exploit confidence information and basic countermeasures. In Proceedings of the 22nd ACM SIGSAC Conference on Computer and Communications Security (CCS\u201915). Association for Computing Machinery, New York, NY, USA, 1322\u20131333. DOI:10.1145\/2810103.2813677"},{"key":"e_1_3_1_30_2","series-title":"IFIP Advances in Information and Communication Technology","doi-asserted-by":"crossref","first-page":"151","DOI":"10.1007\/978-3-030-22312-0_11","volume-title":"Proceedings of the ICT Systems Security and Privacy Protection.","author":"Frigerio Lorenzo","year":"2019","unstructured":"Lorenzo Frigerio, Anderson Santana de Oliveira, Laurent Gomez, and Patrick Duverger. 2019. Differentially private generative adversarial networks for time series, continuous, and discrete open data. In Proceedings of the ICT Systems Security and Privacy Protection.Gurpreet Dhillon, Fredrik Karlsson, Karin Hedstr\u00f6m, and Andr\u00e9 Z\u00faquete (Eds.), IFIP Advances in Information and Communication Technology, Springer International Publishing, Cham, 151\u2013164. DOI:10.1007\/978-3-030-22312-0_11"},{"key":"e_1_3_1_31_2","first-page":"9378","volume-title":"Proceedings of the IEEE\/CVF International Conference on Computer Vision","author":"Gafni Oran","year":"2019","unstructured":"Oran Gafni, Lior Wolf, and Yaniv Taigman. 2019. Live face de-identification in video. In Proceedings of the IEEE\/CVF International Conference on Computer Vision. IEEE, Seattle, Washington, USA, 9378\u20139387. Retrieved from https:\/\/openaccess.thecvf.com\/content_ICCV_2019\/html\/Gafni_Live_Face_De-Identification_in_Video_ICCV_2019_paper.html"},{"key":"e_1_3_1_32_2","unstructured":"Georgi Ganev. 2021. DP-SGD vs PATE: Which Has Less Disparate Impact on GANs? arXiv:2111.13617v1. Retrieved from https:\/\/arxiv.org\/abs\/2111.13617v1"},{"key":"e_1_3_1_33_2","first-page":"6944","volume-title":"Proceedings of the 39th International Conference on Machine Learning","author":"Ganev Georgi","year":"2022","unstructured":"Georgi Ganev, Bristena Oprisanu, and Emiliano De Cristofaro. 2022. Robin hood and Matthew effects: Differential privacy has disparate impact on synthetic data. In Proceedings of the 39th International Conference on Machine Learning. PMLR, Baltimore, Maryland, USA, 6944\u20136959. Retrieved from https:\/\/proceedings.mlr.press\/v162\/ganev22a.html"},{"key":"e_1_3_1_34_2","unstructured":"Georgi Ganev Kai Xu and Emiliano De Cristofaro. 2023. Graphical vs. Deep Generative Models: Measuring the Impact of Differentially Private Mechanisms and Budgets on Utility. arXiv:2305.10994v2. Retrieved from https:\/\/arxiv.org\/abs\/2305.10994v2"},{"key":"e_1_3_1_35_2","doi-asserted-by":"publisher","DOI":"10.56553\/popets-2023-0055"},{"key":"e_1_3_1_36_2","doi-asserted-by":"publisher","DOI":"10.1186\/s12874-020-00977-1"},{"key":"e_1_3_1_37_2","doi-asserted-by":"crossref","unstructured":"Chen Gong Kecen Li Zinan Lin and Tianhao Wang. 2025. DPImageBench: A unified benchmark for differentially private image synthesis. arXiv:2503.14681. Retrieved from https:\/\/arxiv.org\/abs\/2503.14681","DOI":"10.1145\/3719027.3765045"},{"key":"e_1_3_1_38_2","doi-asserted-by":"publisher","DOI":"10.1145\/3422622"},{"key":"e_1_3_1_39_2","first-page":"20","article-title":"Improved training of wasserstein gans","volume":"30","author":"Gulrajani Ishaan","year":"2017","unstructured":"Ishaan Gulrajani, Faruk Ahmed, Martin Arjovsky, Vincent Dumoulin, and Aaron C. Courville. 2017. Improved training of wasserstein gans. Advances in Neural Information Processing Systems 30 (2017), 20 pages.","journal-title":"Advances in Neural Information Processing Systems"},{"key":"e_1_3_1_40_2","first-page":"64","volume-title":"Proceedings of the 2020 2nd IEEE International Conference on Trust, Privacy and Security in Intelligent Systems and Applications (TPS-ISA)","author":"Gupta Saurabh","year":"2020","unstructured":"Saurabh Gupta, Arun Balaji Buduru, and Ponnurangam Kumaraguru. 2020. imdpGAN: Generating private and specific data with generative adversarial networks. In Proceedings of the 2020 2nd IEEE International Conference on Trust, Privacy and Security in Intelligent Systems and Applications (TPS-ISA). IEEE, Atlanta, GA, USA, 64\u201372. DOI:10.1109\/TPS-ISA50397.2020.00019"},{"key":"e_1_3_1_41_2","doi-asserted-by":"crossref","first-page":"196","DOI":"10.1145\/3243734.3243741","volume-title":"Proceedings of the 2018 ACM SIGSAC Conference on Computer and Communications Security","author":"Gursoy Mehmet Emre","year":"2018","unstructured":"Mehmet Emre Gursoy, Ling Liu, Stacey Truex, Lei Yu, and Wenqi Wei. 2018. Utility-aware synthesis of differentially private and attack-resilient location traces. In Proceedings of the 2018 ACM SIGSAC Conference on Computer and Communications Security. ACM, Toronto Canada, 196\u2013211. DOI:10.1145\/3243734.3243741"},{"key":"e_1_3_1_42_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2021.102322"},{"key":"e_1_3_1_43_2","doi-asserted-by":"crossref","first-page":"1949","DOI":"10.1145\/3576915.3623128","volume-title":"Proceedings of the 2023 ACM SIGSAC Conference on Computer and Communications Security","author":"Haney Samuel","year":"2023","unstructured":"Samuel Haney, Michael Shoemate, Grace Tian, Salil Vadhan, Andrew Vyrros, Vicki Xu, and Wanrong Zhang. 2023. Concurrent composition for interactive differential privacy with adaptive privacy-loss parameters. In Proceedings of the 2023 ACM SIGSAC Conference on Computer and Communications Security. ACM, Copenhagen Denmark, 1949\u20131963. DOI:10.1145\/3576915.3623128"},{"key":"e_1_3_1_44_2","doi-asserted-by":"publisher","DOI":"10.3389\/frai.2025.1530397"},{"key":"e_1_3_1_45_2","doi-asserted-by":"publisher","DOI":"10.2478\/popets-2019-0008"},{"key":"e_1_3_1_46_2","unstructured":"Martin Heusel Hubert Ramsauer Thomas Unterthiner Bernhard Nessler and Sepp Hochreiter. 2018. GANs Trained by a Two Time-Scale Update Rule Converge to a Local Nash Equilibrium. arXiv:1706.08500. Retrieved from https:\/\/arxiv.org\/abs\/1706.08500"},{"issue":"4","key":"e_1_3_1_47_2","doi-asserted-by":"crossref","first-page":"232","DOI":"10.2478\/popets-2019-0067","article-title":"Monte Carlo and reconstruction membership inference attacks against generative models.","volume":"2019","author":"Hilprecht Benjamin","year":"2019","unstructured":"Benjamin Hilprecht, Martin H\u00e4rterich, and Daniel Bernau. 2019. Monte Carlo and reconstruction membership inference attacks against generative models. Proceedings on Privacy Enhancing Technologies 2019, 4 (2019), 232\u2013249.","journal-title":"Proceedings on Privacy Enhancing Technologies"},{"key":"e_1_3_1_48_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.jnca.2021.103066"},{"key":"e_1_3_1_49_2","first-page":"2096","volume-title":"Proceedings of the 2021 ACM SIGSAC Conference on Computer and Communications Security (CCS\u201921)","author":"Hu Aoting","year":"2021","unstructured":"Aoting Hu, Renjie Xie, Zhigang Lu, Aiqun Hu, and Minhui Xue. 2021. TableGAN-MCA: Evaluating membership collisions of GAN-synthesized tabular data releasing. In Proceedings of the 2021 ACM SIGSAC Conference on Computer and Communications Security (CCS\u201921). Association for Computing Machinery, New York, NY, USA, 2096\u20132112. DOI:10.1145\/3460120.3485251"},{"key":"e_1_3_1_50_2","first-page":"2387","volume-title":"Proceedings of the 2021 ACM SIGSAC Conference on Computer and Communications Security","author":"Hu Hailong","year":"2021","unstructured":"Hailong Hu and Jun Pang. 2021. Membership inference attacks against GANs by leveraging over-representation regions. In Proceedings of the 2021 ACM SIGSAC Conference on Computer and Communications Security. ACM, Virtual Event Republic of Korea, 2387\u20132389. DOI:10.1145\/3460120.3485338"},{"key":"e_1_3_1_51_2","unstructured":"Hailong Hu and Jun Pang. 2021. Model extraction and defenses on generative adversarial networks. arXiv:2101.02069. Retrieved from https:\/\/arxiv.org\/abs\/2101.02069"},{"key":"e_1_3_1_52_2","first-page":"4064","volume-title":"Proceedings of the 31st ACM International Conference on Information and Knowledge Management (CIKM\u201922)","author":"Hyeong Jihyeon","year":"2022","unstructured":"Jihyeon Hyeong, Jayoung Kim, Noseong Park, and Sushil Jajodia. 2022. An empirical study on the membership inference attack against tabular data synthesis models. In Proceedings of the 31st ACM International Conference on Information and Knowledge Management (CIKM\u201922). Association for Computing Machinery, New York, NY, USA, 4064\u20134068. DOI:10.1145\/3511808.3557546"},{"key":"e_1_3_1_53_2","first-page":"1","volume-title":"Proceedings of the 2021 International Conference on Computer Communications and Networks (ICCCN)","author":"Imtiaz Sana","year":"2021","unstructured":"Sana Imtiaz, Muhammad Arsalan, Vladimir Vlassov, and Ramin Sadre. 2021. Synthetic and private smart health care data generation using GANs. In Proceedings of the 2021 International Conference on Computer Communications and Networks (ICCCN). IEEE, Athens, Greece, 1\u20137. DOI:10.1109\/ICCCN52240.2021.9522203"},{"key":"e_1_3_1_54_2","first-page":"937","volume-title":"Proceedings of the 33rd USENIX Security Symposium (USENIX Security 2024)","author":"Ji Tianxi","year":"2024","unstructured":"Tianxi Ji and Pan Li. 2024. Less is more: Revisiting the gaussian mechanism for differential privacy. In Proceedings of the 33rd USENIX Security Symposium (USENIX Security 2024). USENIX Association, Boston, MA, USA, 937\u2013954. Retrieved from https:\/\/www.usenix.org\/conference\/usenixsecurity24\/presentation\/ji"},{"key":"e_1_3_1_55_2","unstructured":"Dihong Jiang Guojun Zhang Mahdi Karami Xi Chen Yunfeng Shao and Yaoliang Yu. 2022. DP$\u23032$-VAE: Differentially Private Pre-trained Variational Autoencoders. arXiv:2208.03409v2. Retrieved from https:\/\/arxiv.org\/abs\/2208.03409v2"},{"key":"e_1_3_1_56_2","first-page":"37947","article-title":"Pruning\u2019s effect on generalization through the lens of training and regularization","author":"Jin Tian","year":"2022","unstructured":"Tian Jin, Michael Carbin, Dan Roy, Jonathan Frankle, and Gintare Karolina Dziugaite. 2022. Pruning\u2019s effect on generalization through the lens of training and regularization. Advances in Neural Information Processing Systems 35 (2022), 37947\u201337961. Retrieved from https:\/\/proceedings.neurips.cc\/paper_files\/paper\/2022\/hash\/f7ede9414083fceab9e63d9100a80b36-Abstract-Conference.html","journal-title":"Advances in Neural Information Processing Systems"},{"key":"e_1_3_1_57_2","first-page":"21","volume-title":"Proceedings of the ICLR 2019","author":"Jordon James","year":"2022","unstructured":"James Jordon, Jinsung Yoon, and Mihaela van der Schaar. 2022. PATE-GAN: Generating synthetic data with differential privacy guarantees. In Proceedings of the ICLR 2019. OpenReview, New Orleans, LA, USA, 21 pages. Retrieved from https:\/\/openreview.net\/forum?id=S1zk9iRqF7"},{"key":"e_1_3_1_58_2","unstructured":"Tero Karras Timo Aila Samuli Laine and Jaakko Lehtinen. 2018. Progressive Growing of GANs for Improved Quality Stability and Variation. arXiv:1710.10196. Retrieved from https:\/\/arxiv.org\/abs\/1710.10196"},{"key":"e_1_3_1_59_2","first-page":"1506","volume-title":"Proceedings of the Web Conference 2021 (WWW\u201921)","author":"Kim Jayoung","year":"2021","unstructured":"Jayoung Kim, Jinsung Jeon, Jaehoon Lee, Jihyeon Hyeong, and Noseong Park. 2021. OCT-GAN: Neural ODE-based conditional tabular GANs. In Proceedings of the Web Conference 2021 (WWW\u201921). Association for Computing Machinery, New York, NY, USA, 1506\u20131515. DOI:10.1145\/3442381.3449999"},{"key":"e_1_3_1_60_2","unstructured":"Soyeon Kim Yuji Roh Geon Heo and Steven Euijong Whang. 2025. PFGuard: A Generative Framework with Privacy and Fairness Safeguards. arXiv:2410.02246. Retrieved from https:\/\/arxiv.org\/abs\/2410.02246"},{"key":"e_1_3_1_61_2","first-page":"121","volume-title":"Proceedings of the 2nd International Conference on Learning Representations, ICLR","author":"Kingma Diederik P.","year":"2014","unstructured":"Diederik P. Kingma and Max Welling. 2014. Stochastic gradient VB and the variational auto-encoder. In Proceedings of the 2nd International Conference on Learning Representations, ICLR. ICLR, Alberta, Canada, 121."},{"key":"e_1_3_1_62_2","unstructured":"Aditya Kunar Robert Birke Zilong Zhao and Lydia Chen. 2021. DTGAN: Differential Private Training for Tabular GANs. arXiv:2107.02521v3. Retrieved from https:\/\/arxiv.org\/abs\/2107.02521v3"},{"key":"e_1_3_1_63_2","first-page":"4263","volume-title":"Proceedings of the Advances in Neural Information Processing Systems","author":"LEE JAEHOON","year":"2021","unstructured":"JAEHOON LEE, Jihyeon Hyeong, Jinsung Jeon, Noseong Park, and Jihoon Cho. 2021. Invertible Tabular GANs: Killing two birds with one stone for tabular data synthesis. In Proceedings of the Advances in Neural Information Processing Systems. Curran Associates, Inc., online, 4263\u20134273. Retrieved from https:\/\/proceedings.neurips.cc\/paper\/2021\/hash\/22456f4b545572855c766df5eefc9832-Abstract.html"},{"key":"e_1_3_1_64_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.jesp.2013.03.013"},{"key":"e_1_3_1_65_2","doi-asserted-by":"publisher","DOI":"10.1371\/journal.pone.0183250"},{"key":"e_1_3_1_66_2","unstructured":"Keyi Li Sen Yang Travis M. Sullivan Randall S. Burd and Ivan Marsic. 2022. Generating privacy-preserving process data with deep generative models. arXiv:2203.07949. Retrieved from https:\/\/arxiv.org\/abs\/2203.07949"},{"key":"e_1_3_1_67_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.neucom.2019.07.039"},{"key":"e_1_3_1_68_2","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v35i17.17743"},{"key":"e_1_3_1_69_2","first-page":"459","volume-title":"Proceedings of the 2019 IEEE International Conference on Data Mining (ICDM)","author":"Liu Kin Sum","year":"2019","unstructured":"Kin Sum Liu, Chaowei Xiao, Bo Li, and Jie Gao. 2019. Performing Co-membership attacks against deep generative models. In Proceedings of the 2019 IEEE International Conference on Data Mining (ICDM). IEEE, Beijing, China, 459\u2013467. DOI:10.1109\/ICDM.2019.00056"},{"key":"e_1_3_1_70_2","article-title":"Differentially private latent diffusion models","author":"Liu Michael F.","year":"2024","unstructured":"Michael F. Liu, Saiyue Lyu, Margarita Vinaroz, and Mijung Park. 2024. Differentially private latent diffusion models. Transactions on Machine Learning Research(2024), 31. Retrieved from https:\/\/openreview.net\/forum?id=AkdQ266kHj","journal-title":"Transactions on Machine Learning Research"},{"key":"e_1_3_1_71_2","first-page":"591","volume-title":"Proceedings of the 15th International Learning Analytics and Knowledge Conference","author":"Liu Qinyi","year":"2025","unstructured":"Qinyi Liu, Oscar Deho, Farhad Vadiee, Mohammad Khalil, Srecko Joksimovic, and George Siemens. 2025. Can synthetic data be fair and private? a comparative study of synthetic data generation and fairness algorithms. In Proceedings of the 15th International Learning Analytics and Knowledge Conference. ACM, Dublin Ireland, 591\u2013600. DOI:10.1145\/3706468.3706546"},{"key":"e_1_3_1_72_2","first-page":"985","volume-title":"Proceedings of the 2019 IEEE 25th International Conference on Parallel and Distributed Systems (ICPADS)","author":"Liu Yi","year":"2019","unstructured":"Yi Liu, Jialiang Peng, James J. Q. Yu, and Yi Wu. 2019. PPGAN: Privacy-preserving generative adversarial network. In Proceedings of the 2019 IEEE 25th International Conference on Parallel and Distributed Systems (ICPADS). IEEE, Tianjin, China, 985\u2013989. DOI:10.1109\/ICPADS47876.2019.00150"},{"key":"e_1_3_1_73_2","first-page":"2965","volume-title":"Proceedings of the Advances in Neural Information Processing Systems","author":"Long Yunhui","year":"2021","unstructured":"Yunhui Long, Boxin Wang, Zhuolin Yang, Bhavya Kailkhura, Aston Zhang, Carl Gunter, and Bo Li. 2021. G-PATE: Scalable differentially private data generator via private aggregation of teacher discriminators. In Proceedings of the Advances in Neural Information Processing Systems. Curran Associates, Inc., online, 2965\u20132977. Retrieved from https:\/\/proceedings.neurips.cc\/paper\/2021\/hash\/171ae1bbb81475eb96287dd78565b38b-Abstract.html"},{"key":"e_1_3_1_74_2","first-page":"2547","volume-title":"Proceedings of the 2017 ACM SIGSAC Conference on Computer and Communications Security","author":"Lu Pei-Hsuan","year":"2017","unstructured":"Pei-Hsuan Lu and Chia-Mu Yu. 2017. POSTER: A unified framework of differentially private synthetic data release with generative adversarial network. In Proceedings of the 2017 ACM SIGSAC Conference on Computer and Communications Security. ACM, Dallas Texas USA, 2547\u20132549. DOI:10.1145\/3133956.3138823"},{"key":"e_1_3_1_75_2","unstructured":"Yingzhou Lu Minjie Shen Huazheng Wang Xiao Wang Capucine van Rechem Tianfan Fu and Wenqi Wei. 2024. Machine Learning for Synthetic Data Generation: A Review. arXiv:2302.04062. Retrieved from https:\/\/arxiv.org\/abs\/2302.04062"},{"key":"e_1_3_1_76_2","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2022.3233580"},{"key":"e_1_3_1_77_2","doi-asserted-by":"crossref","unstructured":"Cleo Matzken Steffen Eger and Ivan Habernal. 2023. Trade-Offs Between Fairness and Privacy in Language Modeling. arXiv:2305.14936. Retrieved from https:\/\/arxiv.org\/abs\/2305.14936","DOI":"10.18653\/v1\/2023.findings-acl.434"},{"key":"e_1_3_1_78_2","doi-asserted-by":"crossref","first-page":"5446","DOI":"10.1109\/CVPR42600.2020.00549","volume-title":"Proceedings of the 2020 IEEE\/CVF Conference on Computer Vision and Pattern Recognition (CVPR)","author":"Maximov Maxim","year":"2020","unstructured":"Maxim Maximov, Ismail Elezi, and Laura Leal-Taix\u00e9. 2020. CIAGAN: Conditional identity anonymization generative adversarial networks. In Proceedings of the 2020 IEEE\/CVF Conference on Computer Vision and Pattern Recognition (CVPR). IEEE, Seattle, Washington, USA, 5446\u20135455. DOI:10.1109\/CVPR42600.2020.00549ISSN: 2575-7075."},{"key":"e_1_3_1_79_2","doi-asserted-by":"crossref","first-page":"912","DOI":"10.1109\/SLT54892.2023.10022601","volume-title":"Proceedings of the 2022 IEEE Spoken Language Technology Workshop (SLT)","author":"Meyer Sarina","year":"2023","unstructured":"Sarina Meyer, Pascal Tilli, Pavel Denisov, Florian Lux, Julia Koch, and Ngoc Thang Vu. 2023. Anonymizing speech with generative adversarial networks to preserve speaker privacy. In Proceedings of the 2022 IEEE Spoken Language Technology Workshop (SLT). IEEE, Doha, Qatar, 912\u2013919. DOI:10.1109\/SLT54892.2023.10022601"},{"key":"e_1_3_1_80_2","unstructured":"Lu Mi Macheng Shen and Jingzhao Zhang. 2018. A Probe Towards Understanding GAN and VAE Models. arXiv:1812.05676. Retrieved from https:\/\/arxiv.org\/abs\/1812.05676"},{"key":"e_1_3_1_81_2","doi-asserted-by":"crossref","first-page":"263","DOI":"10.1109\/CSF.2017.11","volume-title":"Proceedings of the 2017 IEEE 30th Computer Security Foundations Symposium (CSF)","author":"Mironov Ilya","year":"2017","unstructured":"Ilya Mironov. 2017. R\u00e9nyi differential privacy. In Proceedings of the 2017 IEEE 30th Computer Security Foundations Symposium (CSF). IEEE, California, USA, 263\u2013275. DOI:10.1109\/CSF.2017.11ISSN: 2374-8303."},{"key":"e_1_3_1_82_2","unstructured":"Mehdi Mirza and Simon Osindero. 2014. Conditional Generative Adversarial Nets. arXiv:1411.1784. Retrieved from https:\/\/arxiv.org\/abs\/1411.1784"},{"key":"e_1_3_1_83_2","first-page":"26","volume-title":"Proceedings of the 6th International Conference on Learning Representations, ICLR","author":"Miyato Takeru","year":"2018","unstructured":"Takeru Miyato, Toshiki Kataoka, Masanori Koyama, and Yuichi Yoshida. 2018. Spectral normalization for generative adversarial networks. In Proceedings of the 6th International Conference on Learning Representations, ICLR. OpenReview, Vancouver Convention Centre, Vancouver, Canada, 26 pages. Retrieved from https:\/\/openreview.net\/pdf?id=B1QRgziT-&"},{"key":"e_1_3_1_84_2","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2021.3124844"},{"key":"e_1_3_1_85_2","unstructured":"Md Mahadi Hasan Nahid and Sadid Bin Hasan. 2024. SafeSynthDP: Leveraging large language models for privacy-preserving synthetic data generation using differential privacy. arXiv:2412.20641. Retrieved from https:\/\/arxiv.org\/abs\/2412.20641"},{"key":"e_1_3_1_86_2","doi-asserted-by":"publisher","DOI":"10.2478\/popets-2022-0058"},{"key":"e_1_3_1_87_2","unstructured":"Jasmine Chiat Ling Ong Yilin Ning Mingxuan Liu Yian Ma Zhao Liang Kuldev Singh Robert T. Chang Silke Vogel John C. W. Lim Iris Siu Kwan Tan et\u00a0al. 2025. Regulatory Science Innovation for Generative AI and Large Language Models in Health and Medicine: A Global Call for Action. arXiv:2502.07794. Retrieved from https:\/\/arxiv.org\/abs\/2502.07794"},{"key":"e_1_3_1_88_2","first-page":"18","volume-title":"Proceedings of the 2022 Network and Distributed System Security Symposium","author":"Oprisanu Bristena","year":"2022","unstructured":"Bristena Oprisanu, Georgi Ganev, and Emiliano De Cristofaro. 2022. On utility and privacy in synthetic genomic data. In Proceedings of the 2022 Network and Distributed System Security Symposium. Internet Society, San Diego, CA, USA, 18 pages. DOI:10.14722\/ndss.2022.24092"},{"key":"e_1_3_1_89_2","volume-title":"Navigating Risks and Rewards of Generative Model-based Synthetic Datasets: A Regulatory Perspective","author":"Padariya Debalina","year":"2024","unstructured":"Debalina Padariya, Isabel Wagner, Aboozar Taherkhani, and Eerke Boiten. 2024. Navigating Risks and Rewards of Generative Model-based Synthetic Datasets: A Regulatory Perspective. Workshop Paper. 2nd ICML Workshop on Generative AI and Law (GenLaw 2024), Vienna, Austria. Retrieved from https:\/\/blog.genlaw.org\/pdfs\/genlaw_icml2024\/24.pdf"},{"key":"e_1_3_1_90_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.knosys.2023.110576"},{"key":"e_1_3_1_91_2","first-page":"34","volume-title":"Proceedings of the Sixth International Conference on Learning Representations","author":"Papernot Nicolas","year":"2018","unstructured":"Nicolas Papernot, Shuang Song, Ilya Mironov, Ananth Raghunathan, Kunal Talwar, and Ulfar Erlingsson. 2018. Scalable private learning with PATE. In Proceedings of the Sixth International Conference on Learning Representations. OpenReview, Vancouver, British Columbia, Canada, 34 pages. Retrieved from https:\/\/www.researchgate.net\/profile\/Shuang-Song-2\/publication\/323411073_Scalable_Private_Learning_with_PATE\/links\/5f4584ee458515b72953fc9f\/Scalable-Private-Learning-with-PATE.pdf"},{"key":"e_1_3_1_92_2","doi-asserted-by":"publisher","DOI":"10.14778\/3231751.3231757"},{"key":"e_1_3_1_93_2","first-page":"21","volume-title":"Proceedings of the 4th Workshop on Privacy in Natural Language Processing","author":"Ponomareva Natalia","year":"2022","unstructured":"Natalia Ponomareva, Jasmijn Bastings, and Sergei Vassilvitskii. 2022. Training text-to-text transformers with privacy guarantees. In Proceedings of the 4th Workshop on Privacy in Natural Language Processing. Oluwaseyi Feyisetan, Sepideh Ghanavati, Patricia Thaine, Ivan Habernal, and Fatemehsadat Mireshghallah (Eds.), Association for Computational Linguistics, Seattle, United States, 21\u201321. DOI:10.18653\/v1\/2022.privatenlp-1.4"},{"key":"e_1_3_1_94_2","doi-asserted-by":"crossref","first-page":"358","DOI":"10.1007\/978-3-031-72913-3_20","volume-title":"Proceedings of the Computer Vision\u2014ECCV 2024","author":"Qiang Yao","year":"2025","unstructured":"Yao Qiang, Chengyin Li, Prashant Khanduri, and Dongxiao Zhu. 2025. Fairness-aware vision transformer via debiased self-attention. In Proceedings of the Computer Vision\u2014ECCV 2024. Ale\u0161 Leonardis, Elisa Ricci, Stefan Roth, Olga Russakovsky, Torsten Sattler, and G\u00fcl Varol (Eds.), Springer Nature Switzerland, Cham, 358\u2013376. DOI:10.1007\/978-3-031-72913-3_20"},{"key":"e_1_3_1_95_2","first-page":"9","volume-title":"Proceedings of the Advances in Neural Information Processing Systems","author":"Salimans Tim","year":"2016","unstructured":"Tim Salimans, Ian Goodfellow, Wojciech Zaremba, Vicki Cheung, Alec Radford, Xi Chen, and Xi Chen. 2016. Improved techniques for training GANs. In Proceedings of the Advances in Neural Information Processing Systems. Curran Associates, Inc., Barcelona, Spain, 9 pages. Retrieved from https:\/\/proceedings.neurips.cc\/paper\/2016\/hash\/8a3363abe792db2d8761d6403605aeb7-Abstract.html"},{"key":"e_1_3_1_96_2","first-page":"042","volume-title":"Proceedings of the 2021 International Conference on Artificial Intelligence in Information and Communication (ICAIIC)","author":"Sasada Taisho","year":"2021","unstructured":"Taisho Sasada, Masataka Kawai, Yuzo Taenaka, Doudou Fall, and Youki Kadobayashi. 2021. Differentially-private text generation via text preprocessing to reduce utility loss. In Proceedings of the 2021 International Conference on Artificial Intelligence in Information and Communication (ICAIIC). IEEE, Jeju Island, Korea (South), 042\u2013047. DOI:10.1109\/ICAIIC51459.2021.9415242"},{"key":"e_1_3_1_97_2","doi-asserted-by":"publisher","DOI":"10.1007\/s11831-022-09778-9"},{"key":"e_1_3_1_98_2","doi-asserted-by":"crossref","first-page":"3","DOI":"10.1109\/SP.2017.41","volume-title":"Proceedings of the 2017 IEEE Symposium on Security and Privacy (SP)","author":"Shokri Reza","year":"2017","unstructured":"Reza Shokri, Marco Stronati, Congzheng Song, and Vitaly Shmatikov. 2017. Membership inference attacks against machine learning models. In Proceedings of the 2017 IEEE Symposium on Security and Privacy (SP). IEEE, California, USA, 3\u201318."},{"key":"e_1_3_1_99_2","first-page":"1451","volume-title":"Proceedings of the 31st USENIX Security Symposium (USENIX Security 22)","author":"Stadler Theresa","year":"2022","unstructured":"Theresa Stadler, Bristena Oprisanu, and Carmela Troncoso. 2022. Synthetic data\u2014anonymisation groundhog day. In Proceedings of the 31st USENIX Security Symposium (USENIX Security 22). USENIX Association, Massachusetts, USA, 1451\u20131468. Retrieved from https:\/\/www.usenix.org\/conference\/usenixsecurity22\/presentation\/stadler"},{"key":"e_1_3_1_100_2","doi-asserted-by":"publisher","DOI":"10.1109\/TKDE.2021.3130903"},{"key":"e_1_3_1_101_2","first-page":"169","volume-title":"Proceedings of the 2021 IEEE 37th International Conference on Data Engineering (ICDE)","author":"Takagi Shun","year":"2021","unstructured":"Shun Takagi, Tsubasa Takahashi, Yang Cao, and Masatoshi Yoshikawa. 2021. P3GM: Private high-dimensional data release via privacy preserving phased generative model. In Proceedings of the 2021 IEEE 37th International Conference on Data Engineering (ICDE). IEEE, Chania, Greece, 169\u2013180. DOI:10.1109\/ICDE51399.2021.00022"},{"key":"e_1_3_1_102_2","volume-title":"Proceedings of the ICLR 2025 Workshop on Navigating and Addressing Data Problems for Foundation Models","author":"Tan Bowen","year":"2025","unstructured":"Bowen Tan, Zheng Xu, Eric P. Xing, Zhiting Hu, and Shanshan Wu. 2025. Synthesizing privacy-preserving text data via finetuning *without* finetuning billion-scale LLMs. In Proceedings of the ICLR 2025 Workshop on Navigating and Addressing Data Problems for Foundation Models. OpenReview.net, Singapore. Retrieved from https:\/\/openreview.net\/forum?id=CpXhMOJOQ6"},{"key":"e_1_3_1_103_2","first-page":"168","volume-title":"Proceedings of the 2024 IEEE 14th International Conference on Control System, Computing and Engineering (ICCSCE)","author":"Tan Yue Hern","year":"2024","unstructured":"Yue Hern Tan, Hui Na Chua, Yeh-Ching Low, and Muhammed Basheer Jasser. 2024. Current landscape of generative AI: Models, applications, regulations and challenges. In Proceedings of the 2024 IEEE 14th International Conference on Control System, Computing and Engineering (ICCSCE). 168\u2013173. DOI:10.1109\/ICCSCE61582.2024.10696569"},{"key":"e_1_3_1_104_2","first-page":"1","volume-title":"Proceedings of the 2021 12th International Conference on Information, Intelligence, Systems and Applications (IISA)","author":"Tantipongpipat Uthaipon Tao","year":"2021","unstructured":"Uthaipon Tao Tantipongpipat, Chris Waites, Digvijay Boob, Amaresh Ankit Siva, and Rachel Cummings. 2021. Differentially private synthetic mixed-type data generation for unsupervised learning. In Proceedings of the 2021 12th International Conference on Information, Intelligence, Systems and Applications (IISA). IEEE, Chania Crete, Greece, 1\u20139. DOI:10.1109\/IISA52424.2021.9555521"},{"key":"e_1_3_1_105_2","unstructured":"Christopher T. H. Teo and Ngai-Man Cheung. 2021. Measuring Fairness in Generative Models. arXiv:2107.07754. Retrieved from https:\/\/arxiv.org\/abs\/2107.07754"},{"key":"e_1_3_1_106_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2022.102902"},{"key":"e_1_3_1_107_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.ins.2021.12.018"},{"key":"e_1_3_1_108_2","first-page":"98","volume-title":"Proceedings of the 2019 IEEE\/CVF Conference on Computer Vision and Pattern Recognition Workshops (CVPRW)","author":"Torkzadehmahani Reihaneh","year":"2019","unstructured":"Reihaneh Torkzadehmahani, Peter Kairouz, and Benedict Paten. 2019. DP-CGAN: Differentially private synthetic data and label generation. In Proceedings of the 2019 IEEE\/CVF Conference on Computer Vision and Pattern Recognition Workshops (CVPRW). IEEE, Long Beach, CA, USA, 98\u2013104. DOI:10.1109\/CVPRW.2019.00018"},{"key":"e_1_3_1_109_2","unstructured":"Gianluca Truda. 2023. Generating Tabular Datasets Under Differential Privacy. arXiv:2308.14784. Retrieved from https:\/\/arxiv.org\/abs\/2308.14784"},{"key":"e_1_3_1_110_2","first-page":"22221","volume-title":"Proceedings of the Advances in Neural Information Processing Systems","author":"Breugel Boris van","year":"2021","unstructured":"Boris van Breugel, Trent Kyono, Jeroen Berrevoets, and Mihaela van der Schaar. 2021. DECAF: Generating fair synthetic data using causally-aware generative networks. In Proceedings of the Advances in Neural Information Processing Systems. Curran Associates, Inc., Virtual Conference, 22221\u201322233. Retrieved from https:\/\/proceedings.neurips.cc\/paper\/2021\/hash\/ba9fab001f67381e56e410575874d967-Abstract.html"},{"key":"e_1_3_1_111_2","volume-title":"Proceedings of the Advances in Neural Information Processing Systems","author":"Vaswani Ashish","year":"2017","unstructured":"Ashish Vaswani, Noam Shazeer, Niki Parmar, Jakob Uszkoreit, Llion Jones, Aidan N. Gomez, \u0141 ukasz Kaiser, and Illia Polosukhin. 2017. Attention is all you need. In Proceedings of the Advances in Neural Information Processing Systems. Curran Associates, Inc. Retrieved from https:\/\/proceedings.neurips.cc\/paper\/2017\/hash\/3f5ee243547dee91fbd053c1c4a845aa-Abstract.html"},{"key":"e_1_3_1_112_2","doi-asserted-by":"publisher","DOI":"10.1145\/3020003"},{"key":"e_1_3_1_113_2","doi-asserted-by":"crossref","first-page":"225","DOI":"10.1007\/978-3-030-00305-0_17","volume-title":"Proceedings of the Data Privacy Management, Cryptocurrencies and Blockchain Technology","author":"Wagner Isabel","year":"2018","unstructured":"Isabel Wagner and Eerke Boiten. 2018. Privacy risk assessment: From art to science, by metrics. In Proceedings of the Data Privacy Management, Cryptocurrencies and Blockchain Technology. Joaquin Garcia-Alfaro, Jordi Herrera-Joancomart\u00ed, Giovanni Livraga, and Ruben Rios (Eds.), Springer International Publishing, Cham, 225\u2013241. DOI:10.1007\/978-3-030-00305-0_17"},{"key":"e_1_3_1_114_2","doi-asserted-by":"publisher","DOI":"10.1145\/3168389"},{"key":"e_1_3_1_115_2","doi-asserted-by":"publisher","DOI":"10.1145\/3439405"},{"key":"e_1_3_1_116_2","doi-asserted-by":"crossref","first-page":"263","DOI":"10.1109\/ICPR48806.2021.9413067","volume-title":"Proceedings of the 2020 25th International Conference on Pattern Recognition (ICPR)","author":"Webster Ryan","year":"2021","unstructured":"Ryan Webster, Julien Rabin, Loic Simon, and Frederic Jurie. 2021. Generating private data surrogates for vision related tasks. In Proceedings of the 2020 25th International Conference on Pattern Recognition (ICPR). IEEE, Milan, Italy, 263\u2013269. DOI:10.1109\/ICPR48806.2021.9413067"},{"key":"e_1_3_1_117_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.neucom.2022.06.039"},{"key":"e_1_3_1_118_2","first-page":"1","volume-title":"Proceedings of the 2019 International Joint Conference on Neural Networks (IJCNN)","author":"Wong Kwan Yeung","year":"2019","unstructured":"Kwan Yeung Wong and Fu-lai Chung. 2019. Visualizing time series data with temporal matching based t-SNE. In Proceedings of the 2019 International Joint Conference on Neural Networks (IJCNN). IEEE, Budapest, Hungary, 1\u20138. DOI:10.1109\/IJCNN.2019.8851847ISSN: 2161-4407."},{"key":"e_1_3_1_119_2","first-page":"54531","volume-title":"Proceedings of the 41st International Conference on Machine Learning","author":"Xie Chulin","year":"2024","unstructured":"Chulin Xie, Zinan Lin, Arturs Backurs, Sivakanth Gopi, Da Yu, Huseyin A. Inan, Harsha Nori, Haotian Jiang, Huishuai Zhang, Yin Tat Lee, et\u00a0al. 2024. Differentially private synthetic data via foundation model APIs 2: Text. In Proceedings of the 41st International Conference on Machine Learning. PMLR, Vienna, Austria, 54531\u201354560. Retrieved from https:\/\/proceedings.mlr.press\/v235\/xie24g.html"},{"key":"e_1_3_1_120_2","unstructured":"Liyang Xie Kaixiang Lin Shu Wang Fei Wang and Jiayu Zhou. 2018. Differentially Private Generative Adversarial Network. arXiv:1802.06739. Retrieved from https:\/\/arxiv.org\/abs\/1802.06739"},{"key":"e_1_3_1_121_2","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2019.2897874"},{"key":"e_1_3_1_122_2","first-page":"570","volume-title":"Proceedings of the 2018 IEEE International Conference on Big Data (Big Data)","author":"Xu Depeng","year":"2018","unstructured":"Depeng Xu, Shuhan Yuan, Lu Zhang, and Xintao Wu. 2018. FairGAN: Fairness-aware generative adversarial networks. In Proceedings of the 2018 IEEE International Conference on Big Data (Big Data). IEEE, Seattle, Washington, USA, 570\u2013575. DOI:10.1109\/BigData.2018.8622525"},{"key":"e_1_3_1_123_2","first-page":"7335","article-title":"Modeling tabular data using conditional gan","volume":"32","author":"Xu Lei","year":"2019","unstructured":"Lei Xu, Maria Skoularidou, Alfredo Cuesta-Infante, and Kalyan Veeramachaneni. 2019. Modeling tabular data using conditional gan. Advances in Neural Information Processing Systems 32 (2019), 7335\u20137345.","journal-title":"Advances in Neural Information Processing Systems"},{"key":"e_1_3_1_124_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.neucom.2019.12.136"},{"key":"e_1_3_1_125_2","volume-title":"Proceedings of the 2025 IEEE European Symposium on Security and Privacy Workshops (EuroS&PW)","author":"Yamamoto Juko","year":"2025","unstructured":"Juko Yamamoto, Takayuki Miura, Rina Okada, Masanobu Kii, and Atsunori Ichikawa. 2025. Explaining and visualizing synthetic data quality using statistical distances. In Proceedings of the 2025 IEEE European Symposium on Security and Privacy Workshops (EuroS&PW). IEEE, Venice, Italy."},{"key":"e_1_3_1_126_2","unstructured":"Ruikang Yang Jianfeng Ma Yinbin Miao and Xindi Ma. 2022. Privacy-preserving generative framework against membership inference attacks. arXiv:2202.05469. Retrieved from https:\/\/arxiv.org\/abs\/2202.05469"},{"key":"e_1_3_1_127_2","first-page":"1688","volume-title":"Proceedings of the 2020 IEEE 19th International Conference on Trust, Security and Privacy in Computing and Communications (TrustCom)","author":"Yang Ren","year":"2020","unstructured":"Ren Yang, Xuebin Ma, Xiangyu Bai, and Xiangdong Su. 2020. Differential privacy images protection based on generative adversarial network. In Proceedings of the 2020 IEEE 19th International Conference on Trust, Security and Privacy in Computing and Communications (TrustCom). IEEE, Guangzhou, China, 1688\u20131695. DOI:10.1109\/TrustCom50675.2020.00232ISSN: 2324-9013."},{"key":"e_1_3_1_128_2","doi-asserted-by":"publisher","DOI":"10.1109\/JBHI.2020.2980262"},{"key":"e_1_3_1_129_2","article-title":"Selective pre-training for private fine-tuning","author":"Yu Da","year":"2024","unstructured":"Da Yu, Sivakanth Gopi, Janardhan Kulkarni, Zinan Lin, Saurabh Naik, Tomasz Lukasz Religa, Jian Yin, and Huishuai Zhang. 2024. Selective pre-training for private fine-tuning. Transactions on Machine Learning Research(2024), 19. Retrieved from https:\/\/openreview.net\/forum?id=y3u8OpPHxz","journal-title":"Transactions on Machine Learning Research"},{"key":"e_1_3_1_130_2","doi-asserted-by":"publisher","DOI":"10.1145\/3615336"},{"key":"e_1_3_1_131_2","doi-asserted-by":"crossref","first-page":"993","DOI":"10.1145\/3604915.3608860","volume-title":"Proceedings of the 17th ACM Conference on Recommender Systems","author":"Zhang Jizhi","year":"2023","unstructured":"Jizhi Zhang, Keqin Bao, Yang Zhang, Wenjie Wang, Fuli Feng, and Xiangnan He. 2023. Is ChatGPT fair for recommendation? evaluating fairness in large language model recommendation. In Proceedings of the 17th ACM Conference on Recommender Systems. ACM, Singapore Singapore, 993\u2013999. DOI:10.1145\/3604915.3608860"},{"key":"e_1_3_1_132_2","first-page":"44","volume-title":"Proceedings of the 3rd ACM International Conference on AI in Finance (ICAIF\u201922)","author":"Zhang Wei","year":"2022","unstructured":"Wei Zhang, Brian Barr, and John Paisley. 2022. Understanding counterfactual generation using maximum mean discrepancy. In Proceedings of the 3rd ACM International Conference on AI in Finance (ICAIF\u201922). Association for Computing Machinery, New York, NY, USA, 44\u201352. DOI:10.1145\/3533271.3561759"},{"key":"e_1_3_1_133_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.knosys.2023.111021"},{"key":"e_1_3_1_134_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.jbi.2021.103977"},{"key":"e_1_3_1_135_2","doi-asserted-by":"publisher","DOI":"10.1145\/3651153"},{"key":"e_1_3_1_136_2","doi-asserted-by":"publisher","DOI":"10.1109\/TMC.2018.2830359"},{"key":"e_1_3_1_137_2","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2020.2980271"},{"key":"e_1_3_1_138_2","doi-asserted-by":"publisher","DOI":"10.3389\/fdata.2023.1296508"},{"key":"e_1_3_1_139_2","first-page":"17","volume-title":"Proceedings of the NDSS 2022","author":"Zhou Junhao","year":"2022","unstructured":"Junhao Zhou, Yufei Chen, Chao Shen, and Yang Zhang. 2022. Property inference attacks against GANs. In Proceedings of the NDSS 2022. OpenReview.net, San Diego, California, 17 pages. Retrieved from https:\/\/www.ndss-symposium.org\/wp-content\/uploads\/2022-19-paper.pdf"},{"key":"e_1_3_1_140_2","doi-asserted-by":"publisher","DOI":"10.1109\/TBDATA.2022.3216566"}],"container-title":["ACM Computing Surveys"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3815777","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,6,23]],"date-time":"2026-06-23T10:45:43Z","timestamp":1782211543000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3815777"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,6,23]]},"references-count":139,"journal-issue":{"issue":"13","published-print":{"date-parts":[[2026,10,31]]}},"alternative-id":["10.1145\/3815777"],"URL":"https:\/\/doi.org\/10.1145\/3815777","relation":{},"ISSN":["0360-0300","1557-7341"],"issn-type":[{"value":"0360-0300","type":"print"},{"value":"1557-7341","type":"electronic"}],"subject":[],"published":{"date-parts":[[2026,6,23]]},"assertion":[{"value":"2024-11-01","order":0,"name":"received","label":"Received","group":{"name":"publication_history","label":"Publication History"}},{"value":"2026-04-26","order":2,"name":"accepted","label":"Accepted","group":{"name":"publication_history","label":"Publication History"}},{"value":"2026-06-23","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}