{"id":"https://openalex.org/W4410609096","doi":"https://doi.org/10.1109/satml64287.2025.00060","title":"Avoiding Pitfalls for Privacy Accounting of Subsampled Mechanisms Under Composition","display_name":"Avoiding Pitfalls for Privacy Accounting of Subsampled Mechanisms Under Composition","publication_year":2025,"publication_date":"2025-04-09","ids":{"openalex":"https://openalex.org/W4410609096","doi":"https://doi.org/10.1109/satml64287.2025.00060"},"language":"en","primary_location":{"id":"doi:10.1109/satml64287.2025.00060","is_oa":false,"landing_page_url":"https://doi.org/10.1109/satml64287.2025.00060","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"2025 IEEE Conference on Secure and Trustworthy Machine Learning (SaTML)","raw_type":"proceedings-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":true,"oa_status":"green","oa_url":"https://hal.science/hal-05240803","any_repository_has_fulltext":true},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5099031174","display_name":"Christian Janos Lebeda","orcid":null},"institutions":[{"id":"https://openalex.org/I1326498283","display_name":"Institut national de recherche en informatique et en automatique","ror":"https://ror.org/02kvxyf05","country_code":"FR","type":"funder","lineage":["https://openalex.org/I1326498283"]},{"id":"https://openalex.org/I19894307","display_name":"Universit\u00e9 de Montpellier","ror":"https://ror.org/051escj72","country_code":"FR","type":"education","lineage":["https://openalex.org/I19894307"]}],"countries":["FR"],"is_corresponding":true,"raw_author_name":"Christian Janos Lebeda","raw_affiliation_strings":["Inria, University of Montpellier"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"Inria, University of Montpellier","institution_ids":["https://openalex.org/I1326498283","https://openalex.org/I19894307"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5068653967","display_name":"Matthew Regehr","orcid":"https://orcid.org/0009-0005-3710-6233"},"institutions":[{"id":"https://openalex.org/I151746483","display_name":"University of Waterloo","ror":"https://ror.org/01aff2v68","country_code":"CA","type":"education","lineage":["https://openalex.org/I151746483"]}],"countries":["CA"],"is_corresponding":false,"raw_author_name":"Matthew Regehr","raw_affiliation_strings":["University of Waterloo","University of Waterloo [Waterloo] (200 University Avenue West, Waterloo, ON, Canada N2L 3G1 - Canada)"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"University of Waterloo","institution_ids":["https://openalex.org/I151746483"]},{"raw_affiliation_string":"University of Waterloo [Waterloo] (200 University Avenue West, Waterloo, ON, Canada N2L 3G1 - Canada)","institution_ids":["https://openalex.org/I151746483"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5047778197","display_name":"Gautam Kamath","orcid":"https://orcid.org/0000-0003-0048-2559"},"institutions":[{"id":"https://openalex.org/I4210127509","display_name":"Vector Institute","ror":"https://ror.org/03kqdja62","country_code":"CA","type":"facility","lineage":["https://openalex.org/I4210127509"]},{"id":"https://openalex.org/I151746483","display_name":"University of Waterloo","ror":"https://ror.org/01aff2v68","country_code":"CA","type":"education","lineage":["https://openalex.org/I151746483"]}],"countries":["CA"],"is_corresponding":false,"raw_author_name":"Gautam Kamath","raw_affiliation_strings":["University of Waterloo","University of Waterloo [Waterloo] (200 University Avenue West, Waterloo, ON, Canada N2L 3G1 - Canada)","Vector Institute (Canada)"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"University of Waterloo","institution_ids":["https://openalex.org/I151746483"]},{"raw_affiliation_string":"University of Waterloo [Waterloo] (200 University Avenue West, Waterloo, ON, Canada N2L 3G1 - Canada)","institution_ids":["https://openalex.org/I151746483"]},{"raw_affiliation_string":"Vector Institute (Canada)","institution_ids":["https://openalex.org/I4210127509"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5090438638","display_name":"Thomas Steinke","orcid":"https://orcid.org/0000-0002-0338-8042"},"institutions":[{"id":"https://openalex.org/I1291425158","display_name":"Google (United States)","ror":"https://ror.org/00njsd438","country_code":"US","type":"company","lineage":["https://openalex.org/I1291425158","https://openalex.org/I4210128969"]},{"id":"https://openalex.org/I4210090411","display_name":"DeepMind (United Kingdom)","ror":"https://ror.org/00971b260","country_code":"GB","type":"company","lineage":["https://openalex.org/I4210090411","https://openalex.org/I4210128969"]},{"id":"https://openalex.org/I4210113297","display_name":"Google (United Kingdom)","ror":"https://ror.org/024bc3e07","country_code":"GB","type":"company","lineage":["https://openalex.org/I1291425158","https://openalex.org/I4210113297","https://openalex.org/I4210128969"]}],"countries":["GB","US"],"is_corresponding":false,"raw_author_name":"Thomas Steinke","raw_affiliation_strings":["Google DeepMind","Google DeepMind (Londres - United Kingdom)"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"Google DeepMind","institution_ids":["https://openalex.org/I1291425158","https://openalex.org/I4210090411"]},{"raw_affiliation_string":"Google DeepMind (Londres - United Kingdom)","institution_ids":["https://openalex.org/I4210113297","https://openalex.org/I4210090411"]}]}],"institutions":[],"countries_distinct_count":4,"institutions_distinct_count":4,"corresponding_author_ids":["https://openalex.org/A5099031174"],"corresponding_institution_ids":["https://openalex.org/I1326498283","https://openalex.org/I19894307"],"apc_list":null,"apc_paid":null,"fwci":0.0,"has_fulltext":false,"cited_by_count":0,"citation_normalized_percentile":{"value":0.04835772,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":null,"biblio":{"volume":null,"issue":null,"first_page":"996","last_page":"1006"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T10764","display_name":"Privacy-Preserving Technologies in Data","score":0.9998999834060669,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T10764","display_name":"Privacy-Preserving Technologies in Data","score":0.9998999834060669,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10237","display_name":"Cryptography and Data Security","score":0.9948999881744385,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.9912999868392944,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/composition","display_name":"Composition (language)","score":0.66372150182724},{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.5322154760360718},{"id":"https://openalex.org/keywords/accounting","display_name":"Accounting","score":0.4962502121925354},{"id":"https://openalex.org/keywords/business","display_name":"Business","score":0.20402780175209045}],"concepts":[{"id":"https://openalex.org/C40231798","wikidata":"https://www.wikidata.org/wiki/Q1333743","display_name":"Composition (language)","level":2,"score":0.66372150182724},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.5322154760360718},{"id":"https://openalex.org/C121955636","wikidata":"https://www.wikidata.org/wiki/Q4116214","display_name":"Accounting","level":1,"score":0.4962502121925354},{"id":"https://openalex.org/C144133560","wikidata":"https://www.wikidata.org/wiki/Q4830453","display_name":"Business","level":0,"score":0.20402780175209045},{"id":"https://openalex.org/C138885662","wikidata":"https://www.wikidata.org/wiki/Q5891","display_name":"Philosophy","level":0,"score":0.0},{"id":"https://openalex.org/C41895202","wikidata":"https://www.wikidata.org/wiki/Q8162","display_name":"Linguistics","level":1,"score":0.0}],"mesh":[],"locations_count":2,"locations":[{"id":"doi:10.1109/satml64287.2025.00060","is_oa":false,"landing_page_url":"https://doi.org/10.1109/satml64287.2025.00060","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"2025 IEEE Conference on Secure and Trustworthy Machine Learning (SaTML)","raw_type":"proceedings-article"},{"id":"pmh:oai:HAL:hal-05240803v1","is_oa":true,"landing_page_url":"https://hal.science/hal-05240803","pdf_url":null,"source":{"id":"https://openalex.org/S4306402512","display_name":"HAL (Le Centre pour la Communication Scientifique Directe)","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I1294671590","host_organization_name":"Centre National de la Recherche Scientifique","host_organization_lineage":["https://openalex.org/I1294671590"],"host_organization_lineage_names":[],"type":"repository"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":"https://ieeexplore.ieee.org/xpl/conhome/10992312/proceeding","raw_type":"Conference papers"}],"best_oa_location":{"id":"pmh:oai:HAL:hal-05240803v1","is_oa":true,"landing_page_url":"https://hal.science/hal-05240803","pdf_url":null,"source":{"id":"https://openalex.org/S4306402512","display_name":"HAL (Le Centre pour la Communication Scientifique Directe)","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I1294671590","host_organization_name":"Centre National de la Recherche Scientifique","host_organization_lineage":["https://openalex.org/I1294671590"],"host_organization_lineage_names":[],"type":"repository"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":"https://ieeexplore.ieee.org/xpl/conhome/10992312/proceeding","raw_type":"Conference papers"},"sustainable_development_goals":[],"awards":[{"id":"https://openalex.org/G4422840520","display_name":null,"funder_award_id":"16582","funder_id":"https://openalex.org/F4320310490","funder_display_name":"Villum Fonden"}],"funders":[{"id":"https://openalex.org/F4320310490","display_name":"Villum Fonden","ror":"https://ror.org/007ww2d15"},{"id":"https://openalex.org/F4320334593","display_name":"Natural Sciences and Engineering Research Council of Canada","ror":"https://ror.org/01h531d29"}],"has_content":{"pdf":false,"grobid_xml":false},"content_urls":null,"referenced_works_count":26,"referenced_works":["https://openalex.org/W1873763122","https://openalex.org/W1985511977","https://openalex.org/W1992926795","https://openalex.org/W2167372639","https://openalex.org/W2473418344","https://openalex.org/W2594311007","https://openalex.org/W2898778923","https://openalex.org/W2963062476","https://openalex.org/W2963699739","https://openalex.org/W3037491300","https://openalex.org/W3167530662","https://openalex.org/W4213278605","https://openalex.org/W4249192582","https://openalex.org/W4293783401","https://openalex.org/W4310895557","https://openalex.org/W4385187849","https://openalex.org/W6697139857","https://openalex.org/W6751920018","https://openalex.org/W6752985224","https://openalex.org/W6766757622","https://openalex.org/W6770123878","https://openalex.org/W6784500870","https://openalex.org/W6796579654","https://openalex.org/W6801929890","https://openalex.org/W6810003945","https://openalex.org/W6852120998"],"related_works":["https://openalex.org/W4391375266","https://openalex.org/W2899084033","https://openalex.org/W2748952813","https://openalex.org/W2390279801","https://openalex.org/W4391913857","https://openalex.org/W2358668433","https://openalex.org/W4396701345","https://openalex.org/W2376932109","https://openalex.org/W2001405890","https://openalex.org/W4396696052"],"abstract_inverted_index":{"We":[0,71,96],"consider":[1],"the":[2,10,22,50,54,64,68,99,108],"problem":[3],"of":[4,12,42,56,118],"computing":[5],"tight":[6],"privacy":[7,23,46,51,89,100],"guarantees":[8,52,90,101],"for":[9,53,67,127,136,142,150],"composition":[11,55],"subsampled":[13,58],"differentially":[14],"private":[15],"mechanisms.":[16],"Recent":[17],"algorithms":[18],"can":[19],"numerically":[20],"compute":[21],"parameters":[24,144],"to":[25,37,86,92],"arbitrary":[26],"precision":[27],"but":[28],"must":[29],"be":[30,148],"carefully":[31],"applied.":[32],"Our":[33],"main":[34],"contribution":[35],"is":[36,75,83],"address":[38],"two":[39,109],"common":[40],"points":[41],"confusion.":[43],"First,":[44],"some":[45,143],"accountants":[47],"assume":[48],"that":[49,73,98,120,145],"a":[57],"mechanism":[59],"are":[60],"determined":[61],"by":[62],"self-composing":[63],"worst-case":[65],"datasets":[66],"uncomposed":[69],"mechanism.":[70],"show":[72,97],"this":[74],"not":[76],"true":[77],"in":[78,103,122],"general.":[79],"Second,":[80],"Poisson":[81,128],"subsampling":[82,129],"sometimes":[84],"assumed":[85],"have":[87],"similar":[88],"compared":[91],"sampling":[93,110,137],"without":[94,138],"replacement.":[95,139],"may":[102],"fact":[104],"differ":[105],"significantly":[106],"between":[107],"schemes.":[111],"In":[112],"particular,":[113],"we":[114],"give":[115],"an":[116],"example":[117],"hyperparameters":[119],"result":[121],"<tex":[123,131],"xmlns:mml=\"http://www.w3.org/1998/Math/MathML\"":[124,132],"xmlns:xlink=\"http://www.w3.org/1999/xlink\">$\\varepsilon\\approx":[125],"1$</tex>":[126],"and":[130],"xmlns:xlink=\"http://www.w3.org/1999/xlink\">$\\varepsilon":[133],"&gt;":[134],"10$</tex>":[135],"This":[140],"occurs":[141],"could":[146],"realistically":[147],"chosen":[149],"DP-SGD.":[151]},"counts_by_year":[],"updated_date":"2026-05-17T08:19:37.847499","created_date":"2025-10-10T00:00:00"}
