activity
20192022
most citedDifferentially private training of residual networks with scale normalisation

13 citations · 27 across the 11 of their papers we have counts for

collaborators

12 papers

cs.CR2022

How Do Input Attributes Impact the Privacy Loss in Differential Privacy?

Tamara T. Mueller, Stefan Kolek, Friederike Jungmann +5

Differential privacy (DP) is typically formulated as a worst-case privacy guarantee over all individuals in a database. More recently, extensions to individual subjects or their at…

cs.CR2022

Generalised Likelihood Ratio Testing Adversaries through the Differential Privacy Lens

Georgios Kaissis, Alexander Ziller, Stefan Kolek Martinez de Azagra +1

Differential Privacy (DP) provides tight upper bounds on the capabilities of optimal adversaries, but such adversaries are rarely encountered in practice. Under the hypothesis test…

cs.CV20223 cited

SmoothNets: Optimizing CNN architecture design for differentially private deep learning

Nicolas W. Remerscheid, Alexander Ziller, Daniel Rueckert +1

The arguably most widely employed algorithm to train deep neural networks with Differential Privacy is DPSGD, which requires clipping and noising of per-sample gradients. This intr…

cs.CR2022

Privacy: An axiomatic approach

Alexander Ziller, Tamara Mueller, Rickmer Braren +2

The increasing prevalence of large-scale data collection in modern society represents a potential threat to individual privacy. Addressing this threat, for example through privacy-…

cs.LG202213 cited

Differentially private training of residual networks with scale normalisation

Helena Klause, Alexander Ziller, Daniel Rueckert +2

The training of neural networks with Differentially Private Stochastic Gradient Descent offers formal Differential Privacy guarantees but introduces accuracy trade-offs. In this wo…

cs.CR2021

A unified interpretation of the Gaussian mechanism for differential privacy through the sensitivity index

Georgios Kaissis, Moritz Knolle, Friederike Jungmann +3

The Gaussian mechanism (GM) represents a universally employed tool for achieving differential privacy (DP), and a large body of work has been devoted to its analysis. We argue that…