Quantifying identifiability to choose and audit epsilon in differentially private deep learning
Summary: Recasts (ε,δ)-DP guarantees as Bayesian posterior and membership-identifiability bounds, including multidimensional composition, with tight practical estimates. Provides an auditing implementation that empirically measures identifiability and effective (ε,δ) for trained deep-learning models. (summarized by gpt-5.6-luna on Jul 24 2026)
Incoming Non-self Citations Over Time
Authors
- 1. Daniel Bernau (SAP)
- 2. Günther Eibl (Salzburg University of Applied Sciences)
- 3. Philip W. Grassal (University of Heidelberg)
- 4. Hannah Keller (SAP)
- 5. Florian Kerschbaum (University of Waterloo)
BibTeX Citation
@article{bernau_vldb21,
title = {{Quantifying identifiability to choose and audit epsilon in differentially private deep learning}},
author = {Bernau, Daniel and Eibl, Günther and Grassal, Philip W. and Keller, Hannah and Kerschbaum, Florian},
journal = {PVLDB},
series = {{VLDB} '21},
volume = {14},
number = {13},
pages = {3335--3347},
doi = {10.14778/3484224.3484231},
url = {https://doi.org/10.14778/3484224.3484231},
year = {2021}
}
Incoming Citations (Sorted by Pagerank)
Showing 2 of 2 citing papers.
| Rank | Citing Paper | Year | Venue | Pagerank |
|---|---|---|---|---|
| 8,908 | Privacy and Accuracy-Aware AI/ML Model Deduplication | 2025 | SIGMOD | 5.3483178e-05 |
| 10,550 | Understanding Disclosure Risk in Differential Privacy with Applications to Noise Calibration and Auditing | 2026 | VLDB | 5.093636e-05 |
Previous
Page 1 / 1
Next
Outgoing Citations (Sorted by Pagerank)
Showing 0 of 0 cited papers.
Citations counted here include only citations to other VLDB/SIGMOD/CIDR/PODS papers in this database.
| Rank | Cited Paper | Year | Venue | Pagerank |
|---|
Previous
Page 1 / 1
Next
Semantically Similar Papers
| # | Overall Rank | Paper | Year | Venue |
|---|---|---|---|---|
| 1 | 5,613 | Differential Privacy in the Wild: A Tutorial on Current Practices & Open Challenges | 2017 | SIGMOD |
| 2 | 8,784 | Data Publishing against Realistic Adversaries | 2009 | VLDB |
| 3 | 10,550 | Understanding Disclosure Risk in Differential Privacy with Applications to Noise Calibration and Auditing | 2026 | VLDB |
| 4 | 8,908 | Privacy and Accuracy-Aware AI/ML Model Deduplication | 2025 | SIGMOD |
| 5 | 2,856 | Publishing Set-Valued Data via Differential Privacy | 2011 | VLDB |
| 6 | 6,441 | Differential Privacy in Data Publication and Analysis | 2012 | SIGMOD |
| 7 | 10,335 | A General Framework for Per-record Differential Privacy | 2026 | SIGMOD |
| 8 | 10,451 | Enhancing Local Differential Privacy Accuracy by Exploiting Inherent Uncertainty | 2026 | SIGMOD |
| 9 | 3,016 | Plausible Deniability for Privacy-Preserving Data Synthesis | 2017 | VLDB |
| 10 | 3,375 | Bayesian Differential Privacy on Correlated Data | 2015 | SIGMOD |