1. Martin Abadi and et al. 2016. Deep Learning with Differential Privacy. In Pro-ceedings of the 2016 ACM SIGSAC Conference on Computer and Communications Security.
2. Is Private Learning Possible with Instance Encoding?
3. Nicholas Carlini, Sanjam Garg, Somesh Jha, Saeed Mahloujifar, Mohammad Mahmoody, and Florian Tramèr. 2021. NeuraCrypt is not private. CoRR abs/2108.07256 (2021). arXiv:2108.07256 https://arxiv.org/abs/2108.07256
4. Yangsibo Huang, Zhao Song, Kai Li, and Sanjeev Arora. 2020. InstaHide: Instance-hiding Schemes for Private Distributed Learning. In Proceedings of the 37th International Conference on Machine Learning, Vol. 119. PMLR, 4507--4518.