{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,3,21]],"date-time":"2026-03-21T19:25:29Z","timestamp":1774121129013,"version":"3.50.1"},"reference-count":65,"publisher":"Privacy Enhancing Technologies Symposium Advisory Board","issue":"1","license":[{"start":{"date-parts":[[2021,11,20]],"date-time":"2021-11-20T00:00:00Z","timestamp":1637366400000},"content-version":"unspecified","delay-in-days":0,"URL":"http:\/\/creativecommons.org\/licenses\/by-nc-nd\/3.0"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2022,1,1]]},"abstract":"<jats:title>Abstract<\/jats:title><jats:p>In this study, we aim to bridge the gap between the theoretical understanding of attacks against collaborative machine learning workflows and their practical ramifications by considering the effects of model architecture, learning setting and hyperparameters on the resilience against attacks. We refer to such mitigations as<jats:italic>model adaptation<\/jats:italic>. Through extensive experimentation on both, benchmark and real-life datasets, we establish a more practical threat model for collaborative learning scenarios. In particular, we evaluate the impact of model adaptation by implementing a range of attacks belonging to the broader categories of model inversion and membership inference. Our experiments yield two noteworthy outcomes: they demonstrate the difficulty of actually conducting successful attacks under realistic settings when model adaptation is employed and they highlight the challenge inherent in successfully combining model adaptation and formal privacy-preserving techniques to retain the optimal balance between model utility and attack resilience.<\/jats:p>","DOI":"10.2478\/popets-2022-0014","type":"journal-article","created":{"date-parts":[[2021,11,21]],"date-time":"2021-11-21T02:45:34Z","timestamp":1637462734000},"page":"274-290","source":"Crossref","is-referenced-by-count":6,"title":["Zen and the art of model adaptation: Low-utility-cost attack mitigations in collaborative machine learning"],"prefix":"10.56553","volume":"2022","author":[{"given":"Dmitrii","family":"Usynin","sequence":"first","affiliation":[{"name":"Department of Computing , Imperial College London ; Department of Diagnostic and Interventional Radiology , Technical University of Munich"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Daniel","family":"Rueckert","sequence":"additional","affiliation":[{"name":"Institute for Artificial Intelligence in Medicine , Technical University of Munich ; Department of Computing , Imperial College London"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Jonathan","family":"Passerat-Palmbach","sequence":"additional","affiliation":[{"name":"Department of Computing , Imperial College London ; ConsenSys Health, New York , NY, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Georgios","family":"Kaissis","sequence":"additional","affiliation":[{"name":"Institute for Artificial Intelligence in Medicine , Technical University of Munich ; Department of Computing , Imperial College London , Germany"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"35752","published-online":{"date-parts":[[2021,11,20]]},"reference":[{"key":"2022062314365754808_j_popets-2022-0014_ref_001","unstructured":"[1] \u201cMELLODDY consortium.\u201d https:\/\/cordis.europa.eu\/project\/rcn\/223634\/factsheet\/en. Accessed: November 21, 2020."},{"key":"2022062314365754808_j_popets-2022-0014_ref_002","unstructured":"[2] T. Yang, G. Andrew, H. Eichner, H. Sun, W. Li, N. Kong, D. Ramage, and F. Beaufays, \u201cApplied federated learning: Improving google keyboard query suggestions,\u201d arXiv preprint arXiv:1812.02903, 2018."},{"key":"2022062314365754808_j_popets-2022-0014_ref_003","unstructured":"[3] L. Mu\u00f1oz-Gonz\u00e1lez, K. T. Co, and E. C. Lupu, \u201cByzantine-Robust Federated Machine Learning through Adaptive Model Averaging,\u201d arXiv preprint arXiv:1909.05125, 2019."},{"key":"2022062314365754808_j_popets-2022-0014_ref_004","doi-asserted-by":"crossref","unstructured":"[4] M. Nasr, R. Shokri, and A. Houmansadr, \u201cComprehensive privacy analysis of deep learning: Passive and active white-box inference attacks against centralized and federated learning,\u201d in 2019 IEEE Symposium on Security and Privacy (SP), pp. 739\u2013753, IEEE, 2019.10.1109\/SP.2019.00065","DOI":"10.1109\/SP.2019.00065"},{"key":"2022062314365754808_j_popets-2022-0014_ref_005","doi-asserted-by":"crossref","unstructured":"[5] R. Shokri, M. Stronati, C. Song, and V. Shmatikov, \u201cMembership inference attacks against machine learning models,\u201d in 2017 IEEE Symposium on Security and Privacy (SP), pp. 3\u201318, IEEE, 2017.10.1109\/SP.2017.41","DOI":"10.1109\/SP.2017.41"},{"key":"2022062314365754808_j_popets-2022-0014_ref_006","doi-asserted-by":"crossref","unstructured":"[6] Z. He, T. Zhang, and R. B. Lee, \u201cModel inversion attacks against collaborative inference,\u201d in Proceedings of the 35th Annual Computer Security Applications Conference, pp. 148\u2013162, 2019.10.1145\/3359789.3359824","DOI":"10.1145\/3359789.3359824"},{"key":"2022062314365754808_j_popets-2022-0014_ref_007","unstructured":"[7] E. Bagdasaryan, A. Veit, Y. Hua, D. Estrin, and V. Shmatikov, \u201cHow to backdoor federated learning,\u201d in International Conference on Artificial Intelligence and Statistics, pp. 2938\u20132948, PMLR, 2020."},{"key":"2022062314365754808_j_popets-2022-0014_ref_008","unstructured":"[8] A. Team, \u201cLearning with privacy at scale,\u201d Apple Mach. Learn. J, vol. 1, no. 9, 2017."},{"key":"2022062314365754808_j_popets-2022-0014_ref_009","unstructured":"[9] P. Kairouz, K. Bonawitz, and D. Ramage, \u201cDiscrete distribution estimation under local privacy,\u201d arXiv preprint arXiv:1602.07387, 2016."},{"key":"2022062314365754808_j_popets-2022-0014_ref_010","unstructured":"[10] E. Hesamifard, H. Takabi, and M. Ghasemi, \u201cCryptodl: Deep neural networks over encrypted data,\u201d arXiv preprint arXiv:1711.05189, 2017."},{"key":"2022062314365754808_j_popets-2022-0014_ref_011","doi-asserted-by":"crossref","unstructured":"[11] O. Goldreich, S. Micali, and A. Wigderson, \u201cHow to play any mental game, or a completeness theorem for protocols with honest majority,\u201d in Providing Sound Foundations for Cryptography: On the Work of Shafi Goldwasser and Silvio Micali, pp. 307\u2013328, 2019.10.1145\/3335741.3335755","DOI":"10.1145\/3335741.3335755"},{"key":"2022062314365754808_j_popets-2022-0014_ref_012","doi-asserted-by":"crossref","unstructured":"[12] L. Song, R. Shokri, and P. Mittal, \u201cMembership inference attacks against adversarially robust deep learning models,\u201d in 2019 IEEE Security and Privacy Workshops (SPW), pp. 50\u201356, IEEE, 2019.10.1109\/SPW.2019.00021","DOI":"10.1109\/SPW.2019.00021"},{"key":"2022062314365754808_j_popets-2022-0014_ref_013","doi-asserted-by":"crossref","unstructured":"[13] Y. Zhang, R. Jia, H. Pei, W. Wang, B. Li, and D. Song, \u201cThe Secret Revealer: Generative Model-Inversion Attacks Against Deep Neural Networks,\u201d arXiv preprint arXiv:1911.07135, 2019.","DOI":"10.1109\/CVPR42600.2020.00033"},{"key":"2022062314365754808_j_popets-2022-0014_ref_014","unstructured":"[14] N. Carlini, C. Liu, \u00da. Erlingsson, J. Kos, and D. Song, \u201cThe secret sharer: Evaluating and testing unintended memorization in neural networks,\u201d in 28th {USENIX} Security Symposium ({USENIX} Security 19), pp. 267\u2013284, 2019."},{"key":"2022062314365754808_j_popets-2022-0014_ref_015","unstructured":"[15] J. Geiping, H. Bauermeister, H. Dr\u00f6ge, and M. Moeller, \u201cInverting Gradients\u2013How easy is it to break privacy in federated learning?,\u201d arXiv preprint arXiv:2003.14053, 2020."},{"key":"2022062314365754808_j_popets-2022-0014_ref_016","unstructured":"[16] N. Papernot, S. Chien, S. Song, A. Thakurta, and U. Erlingsson, \u201cMaking the shoe fit: Architectures, initializations, and tuning for learning with privacy,\u201d 2020."},{"key":"2022062314365754808_j_popets-2022-0014_ref_017","doi-asserted-by":"crossref","unstructured":"[17] L. Lyu, H. Yu, and Q. Yang, \u201cThreats to federated learning: A survey,\u201d arXiv preprint arXiv:2003.02133, 2020.","DOI":"10.1007\/978-3-030-63076-8_1"},{"key":"2022062314365754808_j_popets-2022-0014_ref_018","unstructured":"[18] E. De Cristofaro, \u201cAn Overview of Privacy in Machine Learning,\u201d arXiv preprint arXiv:2005.08679, 2020."},{"key":"2022062314365754808_j_popets-2022-0014_ref_019","unstructured":"[19] Y. Kaya, S. Hong, and T. Dumitras, \u201cOn the Effectiveness of Regularization Against Membership Inference Attacks,\u201d arXiv preprint arXiv:2006.05336, 2020."},{"key":"2022062314365754808_j_popets-2022-0014_ref_020","doi-asserted-by":"crossref","unstructured":"[20] G. Kaissis, A. Ziller, J. Passerat-Palmbach, T. Ryffel, D. Usynin, A. Trask, I. Lima, J. Mancuso, F. Jungmann, M.-M. Steinborn, A. Saleh, M. Makowski, D. Rueckert, and R. Braren, \u201cEnd-to-end privacy preserving deep learning on multi-institutional medical imaging,\u201d Nature Machine Intelligence, May 2021.10.1038\/s42256-021-00337-8","DOI":"10.1038\/s42256-021-00337-8"},{"key":"2022062314365754808_j_popets-2022-0014_ref_021","doi-asserted-by":"crossref","unstructured":"[21] S. Hidano, T. Murakami, S. Katsumata, S. Kiyomoto, and G. Hanaoka, \u201cModel inversion attacks for prediction systems: Without knowledge of non-sensitive attributes,\u201d in 2017 15th Annual Conference on Privacy, Security and Trust (PST), pp. 115\u201311509, IEEE, 2017.10.1109\/PST.2017.00023","DOI":"10.1109\/PST.2017.00023"},{"key":"2022062314365754808_j_popets-2022-0014_ref_022","doi-asserted-by":"crossref","unstructured":"[22] Z. Wang, M. Song, Z. Zhang, Y. Song, Q. Wang, and H. Qi, \u201cBeyond inferring class representatives: User-level privacy leakage from federated learning,\u201d in IEEE INFOCOM 2019-IEEE Conference on Computer Communications, pp. 2512\u20132520, IEEE, 2019.","DOI":"10.1109\/INFOCOM.2019.8737416"},{"key":"2022062314365754808_j_popets-2022-0014_ref_023","unstructured":"[23] L. Zhu, Z. Liu, and S. Han, \u201cDeep leakage from gradients,\u201d in Advances in Neural Information Processing Systems, pp. 14747\u201314756, 2019."},{"key":"2022062314365754808_j_popets-2022-0014_ref_024","unstructured":"[24] B. Zhao, K. R. Mopuri, and H. Bilen, \u201ciDLG: Improved Deep Leakage from Gradients,\u201d arXiv preprint arXiv:2001.02610, 2020."},{"key":"2022062314365754808_j_popets-2022-0014_ref_025","unstructured":"[25] T. Orekondy, S. J. Oh, Y. Zhang, B. Schiele, and M. Fritz, \u201cGradient-leaks: Understanding and controlling deanonymization in federated learning,\u201d arXiv preprint arXiv:1805.05838, 2018."},{"key":"2022062314365754808_j_popets-2022-0014_ref_026","unstructured":"[26] N. Papernot, A. Thakurta, S. Song, S. Chien, and \u00da. Erlingsson, \u201cTempered sigmoid activations for deep learning with differential privacy,\u201d arXiv preprint arXiv:2007.14191, 2020."},{"key":"2022062314365754808_j_popets-2022-0014_ref_027","doi-asserted-by":"crossref","unstructured":"[27] B. Avent, J. Gonzalez, T. Diethe, A. Paleyes, and B. Balle, \u201cAutomatic discovery of privacy-utility pareto fronts,\u201d arXiv preprint arXiv:1905.10862, 2019.","DOI":"10.2478\/popets-2020-0060"},{"key":"2022062314365754808_j_popets-2022-0014_ref_028","unstructured":"[28] A. Chakraborty, M. Alam, V. Dey, A. Chattopadhyay, and D. Mukhopadhyay, \u201cAdversarial attacks and defences: A survey,\u201d arXiv preprint arXiv:1810.00069, 2018."},{"key":"2022062314365754808_j_popets-2022-0014_ref_029","unstructured":"[29] X. Chen, C. Liu, B. Li, K. Lu, and D. Song, \u201cTargeted back-door attacks on deep learning systems using data poisoning,\u201d arXiv preprint arXiv:1712.05526, 2017."},{"key":"2022062314365754808_j_popets-2022-0014_ref_030","doi-asserted-by":"crossref","unstructured":"[30] M. Lecuyer, V. Atlidakis, R. Geambasu, D. Hsu, and S. Jana, \u201cCertified robustness to adversarial examples with differential privacy,\u201d in 2019 IEEE Symposium on Security and Privacy (SP), pp. 656\u2013672, IEEE, 2019.10.1109\/SP.2019.00044","DOI":"10.1109\/SP.2019.00044"},{"key":"2022062314365754808_j_popets-2022-0014_ref_031","doi-asserted-by":"crossref","unstructured":"[31] M. Mozaffari-Kermani, S. Sur-Kolay, A. Raghunathan, and N. K. Jha, \u201cSystematic poisoning attacks on and defenses for machine learning in healthcare,\u201d IEEE journal of biomedical and health informatics, vol. 19, no. 6, pp. 1893\u20131905, 2014.","DOI":"10.1109\/JBHI.2014.2344095"},{"key":"2022062314365754808_j_popets-2022-0014_ref_032","doi-asserted-by":"crossref","unstructured":"[32] G. A. Kaissis, M. R. Makowski, D. R\u00fcckert, and R. F. Braren, \u201cSecure, privacy-preserving and federated machine learning in medical imaging,\u201d Nature Machine Intelligence, pp. 1\u20137, 2020.10.1038\/s42256-020-0186-1","DOI":"10.1038\/s42256-020-0186-1"},{"key":"2022062314365754808_j_popets-2022-0014_ref_033","doi-asserted-by":"crossref","unstructured":"[33] S. G. Finlayson, J. D. Bowers, J. Ito, J. L. Zittrain, A. L. Beam, and I. S. Kohane, \u201cAdversarial attacks on medical machine learning,\u201d Science, vol. 363, no. 6433, pp. 1287\u20131289, 2019.","DOI":"10.1126\/science.aaw4399"},{"key":"2022062314365754808_j_popets-2022-0014_ref_034","unstructured":"[34] M. Fredrikson, E. Lantz, S. Jha, S. Lin, D. Page, and T. Ristenpart, \u201cPrivacy in pharmacogenetics: An end-to-end case study of personalized warfarin dosing,\u201d in 23rd {USENIX} Security Symposium ({USENIX} Security 14), pp. 17\u201332, 2014."},{"key":"2022062314365754808_j_popets-2022-0014_ref_035","unstructured":"[35] P. Kairouz, H. B. McMahan, B. Avent, A. Bellet, M. Bennis, A. N. Bhagoji, K. Bonawitz, Z. Charles, G. Cormode, R. Cummings, et al., \u201cAdvances and Open Problems in Federated Learning,\u201d arXiv preprint arXiv:1912.04977, 2019."},{"key":"2022062314365754808_j_popets-2022-0014_ref_036","unstructured":"[36] A. Hard, K. Rao, R. Mathews, S. Ramaswamy, F. Beaufays, S. Augenstein, H. Eichner, C. Kiddon, and D. Ramage, \u201cFederated learning for mobile keyboard prediction,\u201d arXiv preprint arXiv:1811.03604, 2018."},{"key":"2022062314365754808_j_popets-2022-0014_ref_037","unstructured":"[37] T. Li, A. K. Sahu, M. Zaheer, M. Sanjabi, A. Talwalkar, and V. Smith, \u201cFederated optimization in heterogeneous networks,\u201d arXiv preprint arXiv:1812.06127, 2018."},{"key":"2022062314365754808_j_popets-2022-0014_ref_038","unstructured":"[38] P. Vepakomma, O. Gupta, T. Swedish, and R. Raskar, \u201cSplit learning for health: Distributed deep learning without sharing raw patient data,\u201d arXiv preprint arXiv:1812.00564, 2018."},{"key":"2022062314365754808_j_popets-2022-0014_ref_039","doi-asserted-by":"crossref","unstructured":"[39] C. Dwork and A. Roth, \u201cThe algorithmic foundations of differential privacy,\u201d Foundations and Trends\u00ae in Theoretical Computer Science, vol. 9, no. 3-4, pp. 211\u2013407, 2013.10.1561\/0400000042","DOI":"10.1561\/0400000042"},{"key":"2022062314365754808_j_popets-2022-0014_ref_040","doi-asserted-by":"crossref","unstructured":"[40] M. Abadi, A. Chu, I. Goodfellow, H. B. McMahan, I. Mironov, K. Talwar, and L. Zhang, \u201cDeep learning with differential privacy,\u201d Proceedings of the 2016 ACM SIGSAC Conference on Computer and Communications Security, Oct 2016.10.1145\/2976749.2978318","DOI":"10.1145\/2976749.2978318"},{"key":"2022062314365754808_j_popets-2022-0014_ref_041","unstructured":"[41] \u201cPyTorch-DP.\u201d https:\/\/github.com\/facebookresearch\/pytorch-dp. Accessed: June 29, 2020."},{"key":"2022062314365754808_j_popets-2022-0014_ref_042","unstructured":"[42] B. Kulynych and M. Yaghini, \u201cmia: A library for running membership inference attacks against ML models,\u201d Sept. 2018."},{"key":"2022062314365754808_j_popets-2022-0014_ref_043","doi-asserted-by":"crossref","unstructured":"[43] E. Hesamifard, H. Takabi, M. Ghasemi, and R. N. Wright, \u201cPrivacy-preserving machine learning as a service,\u201d Proceedings on Privacy Enhancing Technologies, vol. 2018, no. 3, pp. 123\u2013142, 2018.","DOI":"10.1515\/popets-2018-0024"},{"key":"2022062314365754808_j_popets-2022-0014_ref_044","doi-asserted-by":"crossref","unstructured":"[44] Q. Li, Y. Diao, Q. Chen, and B. He, \u201cFederated learning on non-iid data silos: An experimental study,\u201d 2021.","DOI":"10.1109\/ICDE53745.2022.00077"},{"key":"2022062314365754808_j_popets-2022-0014_ref_045","doi-asserted-by":"crossref","unstructured":"[45] Y. Le Cun, L. D. Jackel, B. Boser, J. S. Denker, H. P. Graf, I. Guyon, D. Henderson, R. E. Howard, and W. Hubbard, \u201cHandwritten digit recognition: Applications of neural network chips and automatic learning,\u201d IEEE Communications Magazine, vol. 27, no. 11, pp. 41\u201346, 1989.10.1109\/35.41400","DOI":"10.1109\/35.41400"},{"key":"2022062314365754808_j_popets-2022-0014_ref_046","unstructured":"[46] A. Krizhevsky, I. Sutskever, and G. E. Hinton, \u201cImagenet classification with deep convolutional neural networks,\u201d in Advances in neural information processing systems, pp. 1097\u20131105, 2012."},{"key":"2022062314365754808_j_popets-2022-0014_ref_047","doi-asserted-by":"crossref","unstructured":"[47] A. Hore and D. Ziou, \u201cImage quality metrics: Psnr vs. ssim,\u201d in 2010 20th international conference on pattern recognition, pp. 2366\u20132369, IEEE, 2010.","DOI":"10.1109\/ICPR.2010.579"},{"key":"2022062314365754808_j_popets-2022-0014_ref_048","doi-asserted-by":"crossref","unstructured":"[48] D. S. Kermany, M. Goldbaum, W. Cai, C. C. Valentim, H. Liang, S. L. Baxter, A. McKeown, G. Yang, X. Wu, F. Yan, et al., \u201cIdentifying medical diagnoses and treatable diseases by image-based deep learning,\u201d Cell, vol. 172, no. 5, pp. 1122\u20131131, 2018.","DOI":"10.1016\/j.cell.2018.02.010"},{"key":"2022062314365754808_j_popets-2022-0014_ref_049","unstructured":"[49] S. Wagh, D. Gupta, and N. Chandran, \u201cSecureNN: Efficient and Private Neural Network Training,\u201d p. 44."},{"key":"2022062314365754808_j_popets-2022-0014_ref_050","unstructured":"[50] T. Ryffel, D. Pointcheval, and F. Bach, \u201cARIANN: Low-Interaction Privacy-Preserving Deep Learning via Function Secret Sharing,\u201d arXiv:2006.04593 [cs, stat], June 2020. arXiv: 2006.04593."},{"key":"2022062314365754808_j_popets-2022-0014_ref_051","doi-asserted-by":"crossref","unstructured":"[51] I. Chillotti, M. Joye, and P. Paillier, \u201cProgrammable bootstrapping enables efficient homomorphic inference of deep neural networks.\u201d Cryptology ePrint Archive, Report 2021\/091, 2021. https:\/\/eprint.iacr.org\/2021\/091.10.1007\/978-3-030-78086-9_1","DOI":"10.1007\/978-3-030-78086-9_1"},{"key":"2022062314365754808_j_popets-2022-0014_ref_052","doi-asserted-by":"crossref","unstructured":"[52] A. Salem, Y. Zhang, M. Humbert, P. Berrang, M. Fritz, and M. Backes, \u201cMl-leaks: Model and data independent membership inference attacks and defenses on machine learning models,\u201d arXiv preprint arXiv:1806.01246, 2018.","DOI":"10.14722\/ndss.2019.23119"},{"key":"2022062314365754808_j_popets-2022-0014_ref_053","unstructured":"[53] A. Sablayrolles, M. Douze, C. Schmid, Y. Ollivier, and H. J\u00e9gou, \u201cWhite-box vs black-box: Bayes optimal strategies for membership inference,\u201d in International Conference on Machine Learning, pp. 5558\u20135567, PMLR, 2019."},{"key":"2022062314365754808_j_popets-2022-0014_ref_054","unstructured":"[54] M. A. Rahman, T. Rahman, R. Lagani\u00e8re, N. Mohammed, and Y. Wang, \u201cMembership Inference Attack against Differentially Private Deep Learning Model,\u201d Transactions on Data Privacy, vol. 11, no. 1, pp. 61\u201379, 2018."},{"key":"2022062314365754808_j_popets-2022-0014_ref_055","unstructured":"[55] S. Truex, L. Liu, M. E. Gursoy, L. Yu, and W. Wei, \u201cDemystifying Membership Inference Attacks in Machine Learning as a Service,\u201d IEEE Transactions on Services Computing, 2019."},{"key":"2022062314365754808_j_popets-2022-0014_ref_056","unstructured":"[56] C. A. C. Choo, F. Tramer, N. Carlini, and N. Papernot, \u201cLabel-only membership inference attacks,\u201d arXiv preprint arXiv:2007.14321, 2020."},{"key":"2022062314365754808_j_popets-2022-0014_ref_057","unstructured":"[57] Y. Park and M. Kang, \u201cMembership Inference Attacks Against Object Detection Models,\u201d arXiv:2001.04011 [cs], Jan. 2020. arXiv: 2001.04011."},{"key":"2022062314365754808_j_popets-2022-0014_ref_058","unstructured":"[58] R. Gilad-Bachrach, N. Dowlin, K. Laine, K. Lauter, M. Naehrig, and J. Wernsing, \u201cCryptonets: Applying neural networks to encrypted data with high throughput and accuracy,\u201d in International Conference on Machine Learning, pp. 201\u2013210, 2016."},{"key":"2022062314365754808_j_popets-2022-0014_ref_059","doi-asserted-by":"crossref","unstructured":"[59] B. D. Rouhani, M. S. Riazi, and F. Koushanfar, \u201cDeepse-cure: Scalable provably-secure deep learning,\u201d in Proceedings of the 55th Annual Design Automation Conference, p. 2, ACM, 2018.10.1145\/3195970.3196023","DOI":"10.1145\/3195970.3196023"},{"key":"2022062314365754808_j_popets-2022-0014_ref_060","doi-asserted-by":"crossref","unstructured":"[60] M. Barni, C. Orlandi, and A. Piva, \u201cA privacy-preserving protocol for neural-network-based computation,\u201d in Proceedings of the 8th workshop on Multimedia and security, pp. 146\u2013151, ACM, 2006.10.1145\/1161366.1161393","DOI":"10.1145\/1161366.1161393"},{"key":"2022062314365754808_j_popets-2022-0014_ref_061","doi-asserted-by":"crossref","unstructured":"[61] P. Mohassel and Y. Zhang, \u201cSecureML: A system for scalable privacy-preserving machine learning,\u201d in 2017 IEEE Symposium on Security and Privacy (SP), pp. 19\u201338, IEEE, 2017.10.1109\/SP.2017.12","DOI":"10.1109\/SP.2017.12"},{"key":"2022062314365754808_j_popets-2022-0014_ref_062","doi-asserted-by":"crossref","unstructured":"[62] S. L. Garfinkel, J. M. Abowd, and S. Powazek, \u201cIssues encountered deploying differential privacy,\u201d in Proceedings of the 2018 Workshop on Privacy in the Electronic Society, pp. 133\u2013137, 2018.10.1145\/3267323.3268949","DOI":"10.1145\/3267323.3268949"},{"key":"2022062314365754808_j_popets-2022-0014_ref_063","doi-asserted-by":"crossref","unstructured":"[63] J. Lee and C. Clifton, \u201cHow much is enough? choosing \u201c for differential privacy,\u201d in International Conference on Information Security, pp. 325\u2013340, Springer, 2011.10.1007\/978-3-642-24861-0_22","DOI":"10.1007\/978-3-642-24861-0_22"},{"key":"2022062314365754808_j_popets-2022-0014_ref_064","doi-asserted-by":"crossref","unstructured":"[64] T. Farrand, F. Mireshghallah, S. Singh, and A. Trask, \u201cNeither private nor fair: Impact of data imbalance on utility and fairness in differential privacy,\u201d arXiv preprint arXiv:2009.06389, 2020.","DOI":"10.1145\/3411501.3419419"},{"key":"2022062314365754808_j_popets-2022-0014_ref_065","unstructured":"[65] J. Zhao, T. Wang, T. Bai, K.-Y. Lam, Z. Xu, S. Shi, X. Ren, X. Yang, Y. Liu, and H. Yu, \u201cReviewing and improving the gaussian mechanism for differential privacy,\u201d arXiv preprint arXiv:1911.12060, 2019."}],"container-title":["Proceedings on Privacy Enhancing Technologies"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.sciendo.com\/pdf\/10.2478\/popets-2022-0014","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2023,1,15]],"date-time":"2023-01-15T22:43:43Z","timestamp":1673822623000},"score":1,"resource":{"primary":{"URL":"https:\/\/petsymposium.org\/popets\/2022\/popets-2022-0014.php"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2021,11,20]]},"references-count":65,"journal-issue":{"issue":"1","published-online":{"date-parts":[[2021,11,20]]},"published-print":{"date-parts":[[2022,1,1]]}},"alternative-id":["10.2478\/popets-2022-0014"],"URL":"https:\/\/doi.org\/10.2478\/popets-2022-0014","relation":{},"ISSN":["2299-0984"],"issn-type":[{"value":"2299-0984","type":"electronic"}],"subject":[],"published":{"date-parts":[[2021,11,20]]}}}