{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,31]],"date-time":"2026-07-31T15:42:11Z","timestamp":1785512531789,"version":"3.56.0"},"reference-count":72,"publisher":"Association for Computing Machinery (ACM)","issue":"6","content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["Proc. VLDB Endow."],"published-print":{"date-parts":[[2024,2]]},"abstract":"<jats:p>Machine learning models are known to memorize private data to reduce their training loss, which can be inadvertently exploited by privacy attacks such as model inversion and membership inference. To protect against these attacks, differential privacy (DP) has become the de facto standard for privacy-preserving machine learning, particularly those popular training algorithms using stochastic gradient descent, such as DPSGD. Nonetheless, DPSGD still suffers from severe utility loss due to its slow convergence. This is partially caused by the random sampling, which brings bias and variance to the gradient, and partially by the Gaussian noise, which leads to fluctuation of gradient updates.<\/jats:p>\n          <jats:p>Our key idea to address these issues is to apply selective updates to the model training, while discarding those useless or even harmful updates. Motivated by this, this paper proposes DPSUR, a Differentially Private training framework based on Selective Updates and Release, where the gradient from each iteration is evaluated based on a validation test, and only those updates leading to convergence are applied to the model. As such, DPSUR ensures the training in the right direction and thus can achieve faster convergence than DPSGD. The main challenges lie in two aspects --- privacy concerns arising from gradient evaluation, and gradient selection strategy for model update. To address the challenges, DPSUR introduces a clipping strategy for update randomization and a threshold mechanism for gradient selection. Experiments conducted on MNIST, FMNIST, CIFAR-10, and IMDB datasets show that DPSUR significantly outperforms previous works in terms of convergence speed and model utility.<\/jats:p>","DOI":"10.14778\/3648160.3648164","type":"journal-article","created":{"date-parts":[[2024,5,3]],"date-time":"2024-05-03T21:52:53Z","timestamp":1714773173000},"page":"1200-1213","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":25,"title":["DPSUR: Accelerating Differentially Private Stochastic Gradient Descent Using Selective Update and Release"],"prefix":"10.14778","volume":"17","author":[{"given":"Jie","family":"Fu","sequence":"first","affiliation":[{"name":"East China Normal University, Hong Kong Polytechnic University"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Qingqing","family":"Ye","sequence":"additional","affiliation":[{"name":"Hong Kong Polytechnic University"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Haibo","family":"Hu","sequence":"additional","affiliation":[{"name":"Hong Kong Polytechnic University"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Zhili","family":"Chen","sequence":"additional","affiliation":[{"name":"Shanghai Key Laboratory of Trustworthy Computing, East China, Normal University"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Lulu","family":"Wang","sequence":"additional","affiliation":[{"name":"East China Normal University"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Kuncan","family":"Wang","sequence":"additional","affiliation":[{"name":"East China Normal University"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Xun","family":"Ran","sequence":"additional","affiliation":[{"name":"Hong Kong Polytechnic University"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2024,5,3]]},"reference":[{"key":"e_1_2_1_1_1","doi-asserted-by":"publisher","DOI":"10.1145\/2976749.2978318"},{"key":"e_1_2_1_2_1","first-page":"17455","article-title":"Differentially private learning with adaptive clipping","volume":"34","author":"Andrew Galen","year":"2021","unstructured":"Galen Andrew, Om Thakkar, Brendan McMahan, and Swaroop Ramaswamy. 2021. Differentially private learning with adaptive clipping. Advances in Neural Information Processing Systems 34 (2021), 17455--17466.","journal-title":"Advances in Neural Information Processing Systems"},{"key":"e_1_2_1_3_1","volume-title":"International Conference on Artificial Intelligence and Statistics. PMLR, 2496--2506","author":"Balle Borja","year":"2020","unstructured":"Borja Balle, Gilles Barthe, Marco Gaboardi, Justin Hsu, and Tetsuya Sato. 2020. Hypothesis testing interpretations and renyi differential privacy. In International Conference on Artificial Intelligence and Statistics. PMLR, 2496--2506."},{"key":"e_1_2_1_4_1","volume-title":"International Conference on Machine Learning. PMLR, 394--403","author":"Balle Borja","year":"2018","unstructured":"Borja Balle and YuXiang Wang. 2018. Improving the gaussian mechanism for differential privacy: Analytical calibration and optimal denoising. In International Conference on Machine Learning. PMLR, 394--403."},{"key":"e_1_2_1_5_1","volume-title":"Private empirical risk minimization: Efficient algorithms and tight error bounds. In 2014 IEEE 55th annual symposium on foundations of computer science","author":"Bassily Raef","unstructured":"Raef Bassily, Adam Smith, and Abhradeep Thakurta. 2014. Private empirical risk minimization: Efficient algorithms and tight error bounds. In 2014 IEEE 55th annual symposium on foundations of computer science. IEEE, 464--473."},{"key":"e_1_2_1_6_1","volume-title":"Proceedings of the symposium on learning and data science","volume":"8","author":"Bottou Leon","year":"2009","unstructured":"Leon Bottou. 2009. Curiously fast convergence of some stochastic gradient descent algorithms. In Proceedings of the symposium on learning and data science, Paris, Vol. 8. Citeseer, 2624--2633."},{"key":"e_1_2_1_7_1","volume-title":"Deep learning with gaussian differential privacy. Harvard data science review","author":"Bu Zhiqi","year":"2020","unstructured":"Zhiqi Bu, Jinshuo Dong, Qi Long, and Weijie J Su. 2020. Deep learning with gaussian differential privacy. Harvard data science review 2020, 23 (2020), 10--1162."},{"key":"e_1_2_1_8_1","doi-asserted-by":"crossref","unstructured":"Mark Bun and Thomas Steinke. 2016. Concentrated differential privacy: Simplifications extensions and lower bounds. 635--658.","DOI":"10.1007\/978-3-662-53641-4_24"},{"key":"e_1_2_1_9_1","volume-title":"28th USENIX Security Symposium (USENIX Security 19)","author":"Carlini Nicholas","year":"2019","unstructured":"Nicholas Carlini, Chang Liu, Ulfar Erlingsson, Jernej Kos, and Dawn Song. 2019. The secret sharer: Evaluating and testing unintended memorization in neural networks. In 28th USENIX Security Symposium (USENIX Security 19). 267--284."},{"key":"e_1_2_1_10_1","doi-asserted-by":"publisher","DOI":"10.1145\/3292500.3330723"},{"key":"e_1_2_1_11_1","volume-title":"FAT'18: Proceedings of the Conference on Fairness, Accountability, and Transparency. 20","author":"Cummings Rachel","year":"2018","unstructured":"Rachel Cummings and Deven Desai. 2018. The role of differential privacy in gdpr compliance. In FAT'18: Proceedings of the Conference on Fairness, Accountability, and Transparency. 20."},{"key":"e_1_2_1_12_1","volume-title":"Unlocking high-accuracy differentially private image classification through scale. arXiv preprint arXiv:2204.13650","author":"De Soham","year":"2022","unstructured":"Soham De, Leonard Berrada, Jamie Hayes, Samuel L Smith, and Borja Balle. 2022. Unlocking high-accuracy differentially private image classification through scale. arXiv preprint arXiv:2204.13650 (2022)."},{"key":"e_1_2_1_13_1","volume-title":"Proceedings of the IEEE International Conference on Data Engineering.","author":"Du Rong","year":"2023","unstructured":"Rong Du, Qingqing Ye, Yue Fu, Haibo Hu, Jin Li, Chengfang Fang, and Jie Shi. 2023. Differential Aggregation against General Colluding Attackers. In Proceedings of the IEEE International Conference on Data Engineering."},{"key":"e_1_2_1_14_1","volume-title":"2022 IEEE 38th International Conference on Data Engineering (ICDE). IEEE, 407--419","author":"Duan Jiawei","year":"2022","unstructured":"Jiawei Duan, Qingqing Ye, and Haibo Hu. 2022. Utility analysis and enhancement of LDP mechanisms in high-dimensional space. In 2022 IEEE 38th International Conference on Data Engineering (ICDE). IEEE, 407--419."},{"key":"e_1_2_1_15_1","doi-asserted-by":"publisher","DOI":"10.1145\/1866739.1866758"},{"key":"e_1_2_1_16_1","doi-asserted-by":"publisher","DOI":"10.1007\/11681878_14"},{"key":"e_1_2_1_17_1","first-page":"3","article-title":"The Algorithmic Foundations of Differential Privacy","volume":"9","author":"Dwork Cynthia","year":"2014","unstructured":"Cynthia Dwork and Aaron Roth. 2014. The Algorithmic Foundations of Differential Privacy. Theoretical Computer Science 9, 3-4 (2014), 211--407.","journal-title":"Theoretical Computer Science"},{"key":"e_1_2_1_18_1","doi-asserted-by":"publisher","DOI":"10.1145\/3357713.3384290"},{"key":"e_1_2_1_19_1","doi-asserted-by":"publisher","DOI":"10.1145\/2810103.2813677"},{"key":"e_1_2_1_20_1","volume-title":"Conference on learning theory. PMLR, 797--842","author":"Ge Rong","year":"2015","unstructured":"Rong Ge, Furong Huang, Chi Jin, and Yang Yuan. 2015. Escaping from saddle points---online stochastic gradient for tensor decomposition. In Conference on learning theory. PMLR, 797--842."},{"key":"e_1_2_1_21_1","volume-title":"Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition. 8376--8386","author":"Golatkar Aditya","year":"2022","unstructured":"Aditya Golatkar, Alessandro Achille, YuXiang Wang, Aaron Roth, Michael Kearns, and Stefano Soatto. 2022. Mixed differential privacy in computer vision. In Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition. 8376--8386."},{"key":"e_1_2_1_22_1","doi-asserted-by":"publisher","DOI":"10.1007\/s10107-019-01440-w"},{"key":"e_1_2_1_23_1","volume-title":"28th USENIX Security Symposium (USENIX Security 19)","author":"Jayaraman Bargav","year":"2019","unstructured":"Bargav Jayaraman and David Evans. 2019. Evaluating differentially private machine learning in practice. In 28th USENIX Security Symposium (USENIX Security 19). 1895--1912."},{"key":"e_1_2_1_24_1","volume-title":"International conference on machine learning. PMLR, 2525--2534","author":"Katharopoulos Angelos","year":"2018","unstructured":"Angelos Katharopoulos and Francois Fleuret. 2018. Not all samples are created equal: Deep learning with importance sampling. In International conference on machine learning. PMLR, 2525--2534."},{"key":"e_1_2_1_25_1","volume-title":"Adam: A method for stochastic optimization.","author":"Kingma Diederik P","year":"2014","unstructured":"Diederik P Kingma and Jimmy Ba. 2014. Adam: A method for stochastic optimization."},{"key":"e_1_2_1_26_1","volume-title":"C Daniel Gelatt Jr, and Mario P Vecchi","author":"Kirkpatrick Scott","year":"1983","unstructured":"Scott Kirkpatrick, C Daniel Gelatt Jr, and Mario P Vecchi. 1983. Optimization by simulated annealing. science 220, 4598 (1983), 671--680."},{"key":"e_1_2_1_27_1","unstructured":"Antti Koskela and Antti Honkela. 2018. Learning rate adaptation for differentially private stochastic gradient descent."},{"key":"e_1_2_1_28_1","unstructured":"Alex Krizhevsky Geoffrey Hinton et al. 2009. Learning multiple layers of features from tiny images. (2009)."},{"key":"e_1_2_1_29_1","volume-title":"MNIST handwritten digit database. ATT Labs [Online]. Available: http:\/\/yann.lecun.com\/exdb\/mnist 2","author":"LeCun Yann","year":"2010","unstructured":"Yann LeCun, Corinna Cortes, and CJ Burges. 2010. MNIST handwritten digit database. ATT Labs [Online]. Available: http:\/\/yann.lecun.com\/exdb\/mnist 2 (2010)."},{"key":"e_1_2_1_30_1","volume-title":"Proceedings of the 24th ACM SIGKDD International Conference on Knowledge Discovery & Data Mining. 1656--1665","author":"Lee Jaewoo","year":"2018","unstructured":"Jaewoo Lee and Daniel Kifer. 2018. Concentrated differentially private gradient descent with adaptive per-iteration privacy budget. In Proceedings of the 24th ACM SIGKDD International Conference on Knowledge Discovery & Data Mining. 1656--1665."},{"key":"e_1_2_1_31_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.zemedi.2018.11.002"},{"key":"e_1_2_1_32_1","doi-asserted-by":"publisher","DOI":"10.5555\/2002472.2002491"},{"key":"e_1_2_1_33_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2019.00029"},{"key":"e_1_2_1_34_1","doi-asserted-by":"publisher","DOI":"10.2172\/4390578"},{"key":"e_1_2_1_35_1","volume-title":"R\u00e9nyi differential privacy. In 2017 IEEE 30th computer security foundations symposium (CSF)","author":"Mironov Ilya","unstructured":"Ilya Mironov. 2017. R\u00e9nyi differential privacy. In 2017 IEEE 30th computer security foundations symposium (CSF). IEEE, 263--275."},{"key":"e_1_2_1_36_1","volume-title":"R\u00e9nyi Differential Privacy of the Sampled Gaussian Mechanism. arXiv: Learning","author":"Mironov Ilya","year":"2019","unstructured":"Ilya Mironov, Kunal Talwar, and Li Zhang. 2019. R\u00e9nyi Differential Privacy of the Sampled Gaussian Mechanism. arXiv: Learning (2019)."},{"key":"e_1_2_1_37_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2019.00065"},{"key":"e_1_2_1_38_1","volume-title":"SEMI-SUPERVISED KNOWLEDGE TRANSFER FOR DEEP LEARNING FROM PRIVATE TRAINING DATA. stat 1050","author":"Papernot Nicolas","year":"2017","unstructured":"Nicolas Papernot, Martin Abadi, Ulfar Erlingsson, Ian Goodfellow, and Kunal Talwar. 2017. SEMI-SUPERVISED KNOWLEDGE TRANSFER FOR DEEP LEARNING FROM PRIVATE TRAINING DATA. stat 1050 (2017), 3."},{"key":"e_1_2_1_39_1","volume-title":"Scalable Private Learning with PATE. In International Conference on Learning Representations.","author":"Papernot Nicolas","year":"2018","unstructured":"Nicolas Papernot, Shuang Song, Ilya Mironov, Ananth Raghunathan, Kunal Talwar, and Ulfar Erlingsson. 2018. Scalable Private Learning with PATE. In International Conference on Learning Representations."},{"key":"e_1_2_1_40_1","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v35i10.17123"},{"key":"e_1_2_1_41_1","volume-title":"2017 IEEE international conference on data mining (ICDM). IEEE, 385--394","author":"Phan NhatHai","year":"2017","unstructured":"NhatHai Phan, Xintao Wu, Han Hu, and Dejing Dou. 2017. Adaptive laplace mechanism: Differential privacy preservation in deep learning. In 2017 IEEE international conference on data mining (ICDM). IEEE, 385--394."},{"key":"e_1_2_1_42_1","volume-title":"Applications and Techniques in Information Security: 8th International Conference, ATIS 2017, Auckland, New Zealand, July 6--7, 2017, Proceedings. Springer, 100--110","author":"Phong Le Trieu","year":"2017","unstructured":"Le Trieu Phong, Yoshinori Aono, Takuya Hayashi, Lihua Wang, and Shiho Moriai. 2017. Privacy-preserving deep learning: Revisited and enhanced. In Applications and Techniques in Information Security: 8th International Conference, ATIS 2017, Auckland, New Zealand, July 6--7, 2017, Proceedings. Springer, 100--110."},{"key":"e_1_2_1_43_1","volume-title":"Felix X Yu, Sashank J Reddi, and Sanjiv Kumar.","author":"Pichapati Venkatadheeraj","year":"2019","unstructured":"Venkatadheeraj Pichapati, Ananda Theertha Suresh, Felix X Yu, Sashank J Reddi, and Sanjiv Kumar. 2019. AdaCliP: Adaptive clipping for private SGD. arXiv preprint arXiv:1908.07643 (2019)."},{"key":"e_1_2_1_44_1","unstructured":"Automatic Differentiation In Pytorch. 2018. Pytorch."},{"key":"e_1_2_1_45_1","volume-title":"ML-Leaks: Model and Data Independent Membership Inference Attacks and Defenses on Machine Learning Models. In Network and Distributed Systems Security Symposium","author":"Salem Ahmed","year":"2019","unstructured":"Ahmed Salem, Yang Zhang, Mathias Humbert, Mario Fritz, and Michael Backes. 2019. ML-Leaks: Model and Data Independent Membership Inference Attacks and Defenses on Machine Learning Models. In Network and Distributed Systems Security Symposium 2019. Internet Society."},{"key":"e_1_2_1_46_1","volume-title":"Proceedings of the 22nd ACM SIGSAC conference on computer and communications security. 1310--1321","author":"Shokri Reza","year":"2015","unstructured":"Reza Shokri and Vitaly Shmatikov. 2015. Privacy-preserving deep learning. In Proceedings of the 22nd ACM SIGSAC conference on computer and communications security. 1310--1321."},{"key":"e_1_2_1_47_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.41"},{"key":"e_1_2_1_48_1","doi-asserted-by":"crossref","unstructured":"Congzheng Song Thomas Ristenpart and Vitaly Shmatikov. 2017. Machine learning models that remember too much. (2017) 587--601.","DOI":"10.1145\/3133956.3134077"},{"key":"e_1_2_1_49_1","volume-title":"Stochastic gradient descent with differentially private updates. In 2013 IEEE global conference on signal and information processing","author":"Song Shuang","unstructured":"Shuang Song, Kamalika Chaudhuri, and Anand D Sarwate. 2013. Stochastic gradient descent with differentially private updates. In 2013 IEEE global conference on signal and information processing. IEEE, 245--248."},{"key":"e_1_2_1_50_1","volume-title":"Defending against Reconstruction Attacks with R\u00e9nyi Differential Privacy. arXiv e-prints","author":"Stock Pierre","year":"2022","unstructured":"Pierre Stock, Igor Shilov, Ilya Mironov, and Alexandre Sablayrolles. 2022. Defending against Reconstruction Attacks with R\u00e9nyi Differential Privacy. arXiv e-prints (2022), arXiv-2202."},{"key":"e_1_2_1_51_1","volume-title":"Overview of deep learning in medical imaging. Radiological physics and technology 10, 3","author":"Suzuki Kenji","year":"2017","unstructured":"Kenji Suzuki. 2017. Overview of deep learning in medical imaging. Radiological physics and technology 10, 3 (2017), 257--273."},{"key":"e_1_2_1_52_1","volume-title":"International Conference on Learning Representations.","author":"Tramer Florian","year":"2020","unstructured":"Florian Tramer and Dan Boneh. 2020. Differentially Private Learning Needs Better Features (or Much More Data). In International Conference on Learning Representations."},{"key":"e_1_2_1_53_1","unstructured":"Koen Lennart van der Veen Ruben Seggers Peter Bloem and Giorgio Patrini. 2018. Three tools for practical differential privacy."},{"key":"e_1_2_1_54_1","doi-asserted-by":"publisher","DOI":"10.1109\/TIT.2014.2320500"},{"key":"e_1_2_1_55_1","doi-asserted-by":"publisher","DOI":"10.1109\/INFOCOM.2019.8737416"},{"key":"e_1_2_1_56_1","volume-title":"Proceedings of the 2022 ACM SIGSAC Conference on Computer and Communications Security. 2885--2899","author":"Wei Jianxin","year":"2022","unstructured":"Jianxin Wei, Ergute Bao, Xiaokui Xiao, and Yin Yang. 2022. Dpis: An enhanced mechanism for differentially private sgd with importance sampling. In Proceedings of the 2022 ACM SIGSAC Conference on Computer and Communications Security. 2885--2899."},{"key":"e_1_2_1_57_1","unstructured":"Shaomei Wu Hermes Pique and Jeffrey Wieland. 2016. Using artificial intelligence to help blind people 'see'facebook."},{"key":"e_1_2_1_58_1","doi-asserted-by":"publisher","DOI":"10.1109\/INFOCOM.2019.8737494"},{"key":"e_1_2_1_59_1","volume-title":"Fashion-MNIST: a Novel Image Dataset for Benchmarking Machine Learning Algorithms. arXiv e-prints","author":"Xiao Han","year":"2017","unstructured":"Han Xiao, Kashif Rasul, and Roland Vollgraf. 2017. Fashion-MNIST: a Novel Image Dataset for Benchmarking Machine Learning Algorithms. arXiv e-prints (2017), arXiv-1708."},{"key":"e_1_2_1_60_1","doi-asserted-by":"publisher","DOI":"10.1109\/INFOCOM41043.2020.9155359"},{"key":"e_1_2_1_61_1","volume-title":"arXiv preprint arXiv:2206.13033","author":"Yang Xiaodong","year":"2022","unstructured":"Xiaodong Yang, Huishuai Zhang, Wei Chen, and TieYan Liu. 2022. Normalized\/clipped sgd with perturbation for differentially private non-convex optimization. arXiv preprint arXiv:2206.13033 (2022)."},{"key":"e_1_2_1_62_1","volume-title":"IEEE INFOCOM 2023-IEEE Conference on Computer Communications. IEEE, 1--10","author":"Ye Qingqing","year":"2023","unstructured":"Qingqing Ye, Haibo Hu, Kai Huang, Man Ho Au, and Qiao Xue. 2023. Stateful switch: Optimized time series release with local differential privacy. In IEEE INFOCOM 2023-IEEE Conference on Computer Communications. IEEE, 1--10."},{"key":"e_1_2_1_63_1","doi-asserted-by":"publisher","DOI":"10.1109\/tdsc.2021.3107512"},{"key":"e_1_2_1_64_1","volume-title":"International Conference on Learning Representations.","author":"Yu Da","year":"2020","unstructured":"Da Yu, Huishuai Zhang, Wei Chen, and TieYan Liu. 2020. Do not Let Privacy Overbill Utility: Gradient Embedding Perturbation for Private Learning. In International Conference on Learning Representations."},{"key":"e_1_2_1_65_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2019.00019"},{"key":"e_1_2_1_66_1","volume-title":"International Conference on Machine Learning. PMLR, 11307--11316","author":"Zhang Jianyi","year":"2020","unstructured":"Jianyi Zhang, Yang Zhao, and Changyou Chen. 2020. Variance reduction in stochastic particle-optimization sampling. In International Conference on Machine Learning. PMLR, 11307--11316."},{"key":"e_1_2_1_67_1","volume-title":"echnical Report). arXiv e-prints","author":"Zhang Xinyang","year":"2018","unstructured":"Xinyang Zhang, Shouling Ji, and Ting Wang. 2018. Differentially Private Releasing via Deep Generative Model (Technical Report). arXiv e-prints (2018), arXiv-1801."},{"key":"e_1_2_1_68_1","doi-asserted-by":"publisher","DOI":"10.14778\/3603581.3603597"},{"key":"e_1_2_1_69_1","doi-asserted-by":"publisher","DOI":"10.1109\/JPROC.2021.3054390"},{"key":"e_1_2_1_70_1","volume-title":"Bypassing the Ambient Dimension: Private SGD with Gradient Subspace Identification. In International Conference on Learning Representations.","author":"Zhou Yingxue","year":"2020","unstructured":"Yingxue Zhou, Steven Wu, and Arindam Banerjee. 2020. Bypassing the Ambient Dimension: Private SGD with Gradient Subspace Identification. In International Conference on Learning Representations."},{"key":"e_1_2_1_71_1","volume-title":"Deep leakage from gradients. Advances in Neural Information Processing Systems 32","author":"Zhu Ligeng","year":"2019","unstructured":"Ligeng Zhu, Zhijian Liu, and Song Han. 2019. Deep leakage from gradients. Advances in Neural Information Processing Systems 32 (2019)."},{"key":"e_1_2_1_72_1","volume-title":"Differential Privacy and Applications","author":"Zhu Tianqing","unstructured":"Tianqing Zhu, Gang Li, Wanlei Zhou, and S Yu Philip. 2017. Differential Privacy and Applications. Vol. 69. Springer."}],"container-title":["Proceedings of the VLDB Endowment"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.14778\/3648160.3648164","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2024,5,3]],"date-time":"2024-05-03T22:01:35Z","timestamp":1714773695000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.14778\/3648160.3648164"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024,2]]},"references-count":72,"journal-issue":{"issue":"6","published-print":{"date-parts":[[2024,2]]}},"alternative-id":["10.14778\/3648160.3648164"],"URL":"https:\/\/doi.org\/10.14778\/3648160.3648164","relation":{},"ISSN":["2150-8097"],"issn-type":[{"value":"2150-8097","type":"print"}],"subject":[],"published":{"date-parts":[[2024,2]]},"assertion":[{"value":"2024-05-03","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}