Fetching the paper…
Reading the bibliography…
Differential privacy is widely accepted as the de facto method for preventing data leakage in ML, and conventional wisdom suggests that it offers strong protection against privacy attacks.
Minimum variance estimation without regularity assumptions
Chapman, D. G. and Robbins, H · 1951
Earlier work this paper cites.
On measures of entropy and information
Rényi, A · 1961
Earlier work this paper cites.
The fisher information and convexity (corresp.)
Cohen, M · 1968
Earlier work this paper cites.
Fundamentals of statistical signal processing: estimation theory
Kay, S. M · 1993
Earlier work this paper cites.
Gradient-based learning applied to document recognition
LeCun, Y., Bottou, L., Bengio, Y., and Haffner, P · 1998
Earlier work this paper cites.
A proof of the fisher information inequality via a data processing argument
Zamir, R · 1998
Earlier work this paper cites.
Detection, estimation, and modulation theory, part I: detection, estimation, and linear modulation theory
Van Trees, H. L · 2004
Earlier work this paper cites.
Learning multiple layers of features from tiny images
Krizhevsky, A., Hinton, G., et al · 2009
Earlier work this paper cites.
Channel coding rate in the finite blocklength regime
Polyanskiy, Y., Poor, H. V., and Verdú, S · 2010
Earlier work this paper cites.
Differentially private empirical risk minimization
Chaudhuri, K., Monteleoni, C., and Sarwate, A. D · 2011
Earlier work this paper cites.
What can we learn privately?
Kasiviswanathan, S. P., Lee, H. K., Nissim, K., Raskhodnikova, S., and Smith, A · 2011
Earlier work this paper cites.
Stochastic gradient descent with differentially private updates
Song, S., Chaudhuri, K., and Sarwate, A. D · 2013
Earlier work this paper cites.
The algorithmic foundations of differential privacy
Dwork, C., Roth, A., et al · 2014
Earlier work this paper cites.
Privacy in pharmacogenetics: An end-to-end case study of personalized warfarin dosing
Fredrikson, M., Lantz, E., Jha, S., Lin, S., Page, D., and Ristenpart, T · 2014
Earlier work this paper cites.
Model inversion attacks that exploit confidence information and basic countermeasures
Fredrikson, M., Jha, S., and Ristenpart, T · 2015
Cited alongside, same era.
High dimensional statistics
Rigollet, P. and Hütter, J.-C · 2015
Cited alongside, same era.
Deep learning with differential privacy
Abadi, M., Chu, A., Goodfellow, I., McMahan, H. B., Mironov, I., Talwar, K., and Zhang, L · 2016
Cited alongside, same era.
Gaussian error linear units (gelus)
Hendrycks, D. and Gimpel, K · 2016
Cited alongside, same era.
f f -divergence inequalities
Sason, I. and Verdú, S · 2016
Cited alongside, same era.
Rényi differential privacy
Mironov, I · 2017
Cited alongside, same era.
R \ \backslash ’enyi differential privacy of the sampled gaussian mechanism
Mironov, I., Talwar, K., and Zhang, L · 2019
Later among the works it cites.
Pytorch: An imperative style, high-performance deep learning library
Paszke, A., Gross, S., Massa, F., Lerer, A., Bradbury, J., Chanan, G., Killeen, T., Lin, Z., Gimelshein, N., Antiga, L., et al · 2019
Later among the works it cites.
Subsampled rényi differential privacy and analytical moments accountant
Wang, Y.-X., Balle, B., and Kasiviswanathan, S. P · 2019
Later among the works it cites.
Does learning require memorization? a short tale about a long tail
Feldman, V · 2020
Later among the works it cites.
Differentially private learning does not bound membership inference
Humphries, T., Rafuse, M., Tulloch, L., Oya, S., Goldberg, I., Hengartner, U., and Kerschbaum, F · 2020
Later among the works it cites.
alphaXiv searches the wider corpus for related work and actual follow-ups.
alphaXiv is searching for related work…
Membership inference attacks against machine learning models
Shokri, R., Stronati, M., Song, C., and Shmatikov, V · 2017
Cited alongside, same era.
Improving the gaussian mechanism for differential privacy: Analytical calibration and optimal denoising
Balle, B. and Wang, Y.-X · 2018
Cited alongside, same era.
JAX: composable transformations of Python+NumPy programs, 2018
Bradbury, J., Frostig, R., Hawkins, P., Johnson, M. J., Leary, C., Maclaurin, D., Necula, G., Paszke, A., VanderPlas, J., Wanderman-Milne, S., and Zhang, Q · 2018
Cited alongside, same era.
Salem, A., Zhang, Y., Humbert, M., Berrang, P., Fritz, M., and Backes, M · 2018
Cited alongside, same era.
Privacy risk in machine learning: Analyzing the connection to overfitting
Yeom, S., Giacomelli, I., Fredrikson, M., and Jha, S · 2018
Cited alongside, same era.
The secret sharer: Evaluating and testing unintended memorization in neural networks
Carlini, N., Liu, C., Erlingsson, Ú., Kos, J., and Song, D · 2019
Cited alongside, same era.
Tempered sigmoid activations for deep learning with differential privacy
Papernot, N., Thakurta, A., Song, S., Chien, S., and Erlingsson, U · 2020
Later among the works it cites.
Information theoretic methods in statistics and computer science, 2020
Polyanskiy, Y · 2020
Later among the works it cites.
Differentially private learning needs better features (or much more data)
Tramèr, F. and Boneh, D · 2020
Later among the works it cites.
The secret revealer: Generative model-inversion attacks against deep neural networks
Zhang, Y., Jia, R., Pei, H., Wang, W., Li, B., and Song, D · 2020
Later among the works it cites.
Three variants of differential privacy: Lossless conversion and applications
Asoodeh, S., Liao, J., Calmon, F. P., Kosut, O., and Sankar, L · 2021
Later among the works it cites.
Extracting training data from large language models
Carlini, N., Tramer, F., Wallace, E., Jagielski, M., Herbert-Voss, A., Lee, K., Roberts, A., Brown, T., Song, D., Erlingsson, U., et al · 2021
Later among the works it cites.
Measuring data leakage in machine-learning models with fisher information
Hannun, A., Guo, C., and van der Maaten, L · 2021
Later among the works it cites.
functorch: Jax-like composable function transforms for pytorch
Horace He, R. Z · 2021
Later among the works it cites.
Reconstructing training data with informed adversaries
Balle, B., Cherubin, G., and Hayes, J · 2022
Closest in time.