Fetching the paper…
Reading the bibliography…
Differentially private stochastic gradient descent (DP-SGD) is the canonical approach to private deep learning.
Backpropagation applied to handwritten zip code recognition
Y. LeCun, B. Boser, J. S. Denker, D. Henderson, R. E. Howard, W. Hubbard, and L. D. Jackel · 1989
Earlier work this paper cites.
The mnist database of handwritten digits
Y. LeCun · 1998
Earlier work this paper cites.
Calibrating noise to sensitivity in private data analysis
C. Dwork, F. McSherry, K. Nissim, and A. Smith · 2006
Earlier work this paper cites.
Learning multiple layers of features from tiny images
A. Krizhevsky, G. Hinton, et al · 2009
Earlier work this paper cites.
What can we learn privately?
S. P. Kasiviswanathan, H. K. Lee, K. Nissim, S. Raskhodnikova, and A. Smith · 2011
Earlier work this paper cites.
The eu proposal for a general data protection regulation and the roots of the ‘right to be forgotten’
A. Mantelero · 2013
Earlier work this paper cites.
Stochastic gradient descent with differentially private updates
S. Song, K. Chaudhuri, and A. D. Sarwate · 2013
Earlier work this paper cites.
Private empirical risk minimization: Efficient algorithms and tight error bounds
R. Bassily, A. Smith, and A. Thakurta · 2014
Earlier work this paper cites.
Bounds on the sample complexity for private learning and private data release
A. Beimel, H. Brenner, S. P. Kasiviswanathan, and K. Nissim · 2014
Earlier work this paper cites.
The algorithmic foundations of differential privacy
C. Dwork, A. Roth, et al · 2014
Earlier work this paper cites.
Rényi divergence and kullback-leibler divergence
T. Van Erven and P. Harremos · 2014
Earlier work this paper cites.
Towards making systems forget with machine unlearning
Y. Cao and J. Yang · 2015
Earlier work this paper cites.
Deep learning with differential privacy
M. Abadi, A. Chu, I. Goodfellow, H. B. McMahan, I. Mironov, K. Talwar, and L. Zhang · 2016
Earlier work this paper cites.
Deep residual learning for image recognition
K. He, X. Zhang, S. Ren, and J. Sun · 2016
Earlier work this paper cites.
Rényi differential privacy
I. Mironov · 2017
Cited alongside, same era.
The secret sharer: Evaluating and testing unintended memorization in neural networks
N. Carlini, C. Liu, Ú. Erlingsson, J. Kos, and D. Song · 2019
Cited alongside, same era.
Making ai forget you: Data deletion in machine learning
A. Ginart, M. Guan, G. Valiant, and J. Y. Zou · 2019
Cited alongside, same era.
Certified data removal from machine learning models
C. Guo, T. Goldstein, A. Hannun, and L. Van Der Maaten · 2019
Cited alongside, same era.
R \ \backslash ’enyi differential privacy of the sampled gaussian mechanism
I. Mironov, K. Talwar, and L. Zhang · 2019
Cited alongside, same era.
Per-instance differential privacy
Proof-of-learning: Definitions and practice
H. Jia, M. Yaghini, C. A. Choquette-Choo, N. Dullerud, A. Thudi, V. Chandrasekaran, and N. Papernot · 2021
Later among the works it cites.
Adversary instantiation: Lower bounds for differentially private machine learning, 2021
M. Nasr, S. Song, A. Thakurta, N. Papernot, and N. Carlini · 2021
Later among the works it cites.
Manipulating sgd with data ordering attacks
I. Shumailov, Z. Shumaylov, D. Kazhdan, Y. Zhao, N. Papernot, M. A. Erdogdu, and R. J. Anderson · 2021
Later among the works it cites.
Privacy of noisy stochastic gradient descent: More iterations without more privacy loss
J. Altschuler and K. Talwar · 2022
Later among the works it cites.
Bounding training data reconstruction in private (deep) learning
C. Guo, B. Karrer, K. Chaudhuri, and L. van der Maaten · 2022
Later among the works it cites.
Forgeability and membership inference attacks
Z. Kong, A. Roy Chowdhury, and K. Chaudhuri · 2022
alphaXiv searches the wider corpus for related work and actual follow-ups.
alphaXiv is searching for related work…
Y.-X. Wang · 2019
Cited alongside, same era.
Identity crisis: Memorization and generalization under extreme overparameterization
C. Zhang, S. Bengio, M. Hardt, M. C. Mozer, and Y. Singer · 2019
Cited alongside, same era.
Does learning require memorization? a short tale about a long tail
V. Feldman · 2020
Cited alongside, same era.
What neural networks memorize and why: Discovering the long tail via influence estimation
V. Feldman and C. Zhang · 2020
Cited alongside, same era.
Auditing differentially private machine learning: How private is private SGD?
M. Jagielski, J. Ullman, and A. Oprea · 2020
Cited alongside, same era.
Machine unlearning
L. Bourtoule, V. Chandrasekaran, C. A. Choquette-Choo, H. Jia, A. Travers, B. Zhang, D. Lie, and N. Papernot · 2021
Cited alongside, same era.
Individual privacy accounting via a renyi filter
V. Feldman and T. Zrnic · 2021
Cited alongside, same era.
Later among the works it cites.
Individual privacy accounting with gaussian differential privacy
A. Koskela, M. Tobaben, and A. Honkela · 2022
Later among the works it cites.
What you see is what you get: Principled deep learning via distributional generalization
B. Kulynych, Y.-Y. Yang, Y. Yu, J. Błasiok, and P. Nakkiran · 2022
Later among the works it cites.
Optimal membership inference bounds for adaptive composition of sampled gaussian mechanisms
S. Mahloujifar, A. Sablayrolles, G. Cormode, and S. Jha · 2022
Later among the works it cites.
Memorization without overfitting: Analyzing the training dynamics of large language models
K. Tirumala, A. Markosyan, L. Zettlemoyer, and A. Aghajanyan · 2022
Later among the works it cites.
Individual privacy accounting for differentially private stochastic gradient descent
D. Yu, G. Kamath, J. Kulkarni, T.-Y. Liu, J. Yin, and H. Zhang · 2022
Later among the works it cites.
Bayesian estimation of differential privacy
S. Zanella-Béguelin, L. Wutschitz, S. Tople, A. Salem, V. Rühle, A. Paverd, M. Naseri, and B. Köpf · 2022
Later among the works it cites.
Proof-of-learning is currently more broken than you think
C. Fang, H. Jia, A. Thudi, M. Yaghini, C. A. Choquette-Choo, N. Dullerud, V. Chandrasekaran, and N. Papernot · 2023
Closest in time.
Tight auditing of differentially private machine learning
M. Nasr, J. Hayes, T. Steinke, B. Balle, F. Tramèr, M. Jagielski, N. Carlini, and A. Terzis · 2023
Closest in time.