Pith. sign in

REVIEW 4 major objections 4 minor 70 references

SoK: What Makes Private Learning Unfair?

T0 review · 4 major / 4 minor · reviewed 2026-08-10 · deepseek-v4-flash

Pith's one-line read Private learning's unfairness traces to two data conditions

desk verdict A useful SoK with a clean taxonomy, but the headline joint-sufficiency claim in Section V-B does not follow from the surveyed evidence and should be softened or reworked. read the letter →

arxiv 2501.14414 v1 pith:73RZ72GR submitted 2025-01-24 cs.LG cs.CR

classification cs.LGcs.CR
keywords differentialprivacymachinelearningfairnessdisparateimpactDP-SGDcausalnecessitytaxonomygroup
verification ladder T0 review T1 audit T2 compute T3 formal

The pith

A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.

The reading

This survey asks why differentially private machine learning hurts some demographic groups more than others. Reviewing 20 studies, the authors build a four-layer taxonomy of contributing factors and analyze which are causally necessary. They conclude that, besides the noise addition intrinsic to differential privacy, only two factors are likely necessary: a small training dataset and differences between groups in distance to the model's decision boundary. The paper further suggests that these two factors together are likely sufficient to trigger disparate impact. If correct, efforts to make private learning fair should focus on data and distribution, not only on the privacy algorithm.

What carries the argument

The central organizing object is a four-layer taxonomy: DP technique, ML algorithm and hyperparameters, training dataset, and underlying distribution. The analysis applies a necessity-and-sufficiency test to each factor in the taxonomy, pooling evidence across the 20 surveyed studies. The key mechanisms are the inverse relationship between dataset size and DP sensitivity, which controls how much noise is needed, and the role of the Hessian and confidence margin in linking group distance to the decision boundary to noise-induced error.

What would settle it

Run DP-SGD on synthetic data that independently controls total dataset size and group distance to the decision boundary: if disparate impact appears when the dataset is small but group distances are equal, then group distance is not necessary; if disparate impact does not appear when both a small dataset and unequal distances are present, the joint-sufficiency claim fails.

Watch

Extended reading notes

Core claim

The paper's central claim is that the exacerbation of performance disparities by differential privacy is not caused by the specific DP mechanism, such as DP-SGD's gradient clipping or the choice of algorithm. The authors argue that DP noise addition is necessary because perturbing the decision boundary is the essence of differential privacy, while clipping and algorithm choice are not necessary. Based on cross-study evidence, they identify dataset size and group distance to the decision boundary as the only other factors likely necessary, and they infer that the joint presence of these two factors is likely sufficient for disparate impact to manifest. This redirects attention from the internals of DP algorithms to the dataset and distribution layers of the machine learning pipeline.

Load-bearing premise

The causal conclusions pool evidence from 20 studies that use different fairness notions, datasets, and DP algorithms, treating a counterexample in one setting as proof that a factor is not necessary in general and treating the observed necessity of two factors as evidence of their joint sufficiency even though no study varies them together.

Editorial extensions

If this is right

  • Mitigation strategies that only modify the DP algorithm cannot eliminate disparate impact if the dataset and distribution factors remain unfavorable.
  • For large datasets, DP's disparity amplification is predicted to fade toward the non-private baseline, so small-data domains such as medicine and niche applications need special care.
  • Measuring or reducing differences in group distance to the decision boundary becomes a practical fairness lever, for example through decision-boundary regularization.
  • Evaluations of new DP algorithms should report dataset size and group boundary distances, or cross-study comparisons will remain contradictory.
  • If the joint-sufficiency claim holds, a small dataset with unequal group boundary distances is a red-flag condition for disparate impact regardless of which DP algorithm is used.

Reading between the lines

Editorial extensions of the paper, not claims the author makes directly.

  • Because the model itself helps determine the decision boundary, a testable extension is to vary model capacity on the same data and observe whether boundary-distance differences mediate the disparate effect.
  • No surveyed study varies dataset size and group boundary distance together, so the sufficiency claim is an extrapolation that a synthetic-data experiment manipulating both factors independently could settle.
  • If the claim generalizes, fairness audits of private models should measure dataset size and group boundary distances before DP is applied, not only after.
  • The taxonomy suggests that interventions at the data and distribution layers, such as collecting more samples from underrepresented groups, may be more cost-effective than DP-layer fixes, but this remains untested.
Share X Bluesky LinkedIn Reddit HN

Editorial analysis

A structured set of objections, weighed in public.

Desk editor's note, referee report, and a circularity audit.

Referee Report

4 major / 4 minor

Summary. This SoK paper surveys the literature on how differential privacy (DP) exacerbates performance disparities across demographic groups in supervised machine learning. The authors propose a four-layer taxonomy of contributing factors (DP technique, ML algorithm and hyperparameters, training dataset, underlying distribution), review 20 in-scope studies, and conduct a causal analysis that assigns each factor a judgment of necessity or non-necessity for the exacerbation effect. The paper concludes in Section V-B that, besides DP noise addition, small dataset size and disparate group distance to the decision boundary are the only likely necessary factors, and that their joint presence is likely sufficient for the issue to manifest. The survey also reviews mitigation strategies and identifies open research directions. The central contribution is the taxonomy and the systematization of a heterogeneous body of literature, but the main causal conclusion—the sufficiency claim—is not supported by the evidence presented.

Significance. If the causal conclusions were justified, the paper would redirect research and mitigation efforts away from DP-specific mechanisms toward dataset size and distributional geometry, which would be a valuable contribution to a maturing field. The survey is well organized: it is the first to my knowledge to systematically categorize contributing factors across the ML pipeline, it documents the experimental details of the 20 surveyed studies in Table IV, and it is appropriately cautious in several places, explicitly acknowledging in Section VII-A the lack of ablation studies and the non-comparability of existing experimental settings. The paper also correctly emphasizes under-explored lower-layer factors and the need for multi-notion fairness evaluation. However, the central sufficiency claim exceeds what the surveyed evidence can support, and the causal inference methodology has structural weaknesses that the paper itself partially concedes.

major comments (4)
  1. [Section V-B] The central conclusion that the simultaneous presence of small dataset size and group distance disparity is 'likely to be sufficient' does not follow from the preceding necessity claims. Necessity of A and necessity of B do not imply sufficiency of their conjunction, and no reviewed study varies both factors together. Section VII-A also concedes that the literature lacks scaled analyses and interaction studies. This inference is load-bearing because it is the paper's main novel conclusion; it should be removed or substantially weakened to a hypothesis, not presented as a causal finding.
  2. [Section V-A, dataset size paragraph] The necessity judgment for small dataset size is not crisply falsifiable because no threshold for 'small' is ever defined, and the supporting theory is asymptotic ('noise decreases with n'). The cited theoretical results in [17] and [22] provide upper bounds on disparity or sufficient conditions for approximate fairness, not lower bounds showing that small n necessarily produces exacerbation. Thus the evidence supports an attenuation effect of large datasets, but not a necessity claim for small ones.
  3. [Section V-A, noise addition paragraph] The claim that noise addition is necessary 'by definition' is presented as a logical argument, but the premise that 'if the decision boundary was not perturbed, there would be no exacerbation effect' conflates the mechanism with the phenomenon. DP-induced disparity could in principle arise through other channels (e.g., clipping-induced gradient misalignment, as reviewed for [11]), and the paper itself treats clipping as non-necessary but contributing. The necessity of noise addition should be reframed as a definitional assumption, not a result of the causal analysis.
  4. [Appendix B and Section V] The cross-study causal inference assumes that counterexamples from heterogeneous settings can rule out necessity in general, and that convergence of findings across different fairness notions supports necessity claims. The paper acknowledges this diversity but does not address the risk that differences in datasets, models, and fairness metrics make the findings non-comparable. For example, a counterexample to group-imbalance necessity on one dataset is treated as proof that group imbalance is not necessary for the exacerbation issue at all, without a formal or even informal argument that the counterexample setting is representative. This weakens all the '⊗' and 'H#' judgments in Table I.
minor comments (4)
  1. [Section III] The description of the Google Scholar search and the selection of 20 papers is not accompanied by a PRISMA-style flow diagram or a list of excluded papers; adding a table of exclusion reasons would improve reproducibility.
  2. [Section II-C] Equation (3) defines unfairness as M(hθ;A) − M(hθ;B), but it is not specified which direction corresponds to 'unfairness' in the surveyed studies; the text later refers to 'against B' but the sign convention is ambiguous across metrics.
  3. [Table IV] The table marks cells with checkmarks but does not indicate the magnitude or direction of effects; a reader cannot tell which studies found exacerbation versus mitigation, which would help assess the strength of the causal evidence.
  4. [Section IV-D] The justification for placing 'group distance to the decision boundary' in the distribution layer rather than the model layer is reasonable, but the paper should acknowledge that this factor is operationally defined only after a model is trained, since the decision boundary is a function of the model; this affects whether it can be considered a pre-existing distributional property.

Circularity Check

0 steps flagged · score 2.0 of 10

No significant circularity; the causal synthesis is independent of the surveyed evidence, with only a minor non-load-bearing self-citation.

full rationale

This paper is a SoK survey that synthesizes 20 external studies, so its causal claims are meta-analytic rather than derived from the authors' own fitted parameters or equations. I checked the claimed derivation chain in Section V: the necessity judgments for dataset size and group distance to the decision boundary rest on cited external empirical and theoretical results (Mangold et al., Cummings et al., Tran et al.), and the taxonomy in Section IV is an organizational contribution rather than a prediction. The only author self-citation is [46] (Juarez and Korolova), used in a passing remark about Randomized Response utility; it is not load-bearing. The main logical weakness, in Section V-B, is that the conjunction of two individually necessary factors is asserted to be 'likely sufficient,' which is an invalid inference rather than a circular reduction; the paper itself hedges with 'likely' and Section VII-A concedes that the evidence base lacks ablation or scaled analyses. No step reduces by construction to its input, no fitted quantity is renamed as a prediction, and no load-bearing result is imported solely from the authors' prior work. Therefore, no significant circularity is present.

Assumptions & free parameters 0 free parameters · 4 assumptions · 0 invented entities

The survey itself introduces no fitted parameters or postulated entities. Its causal conclusions rest on the assumptions above, most of which are methodological rather than mathematical.

assumptions (4)
  • domain assumption DP is achieved fundamentally through noise addition, so any DP-induced effect requires decision-boundary perturbation.
    Used in Section V-A to mark noise addition as necessary and to infer that group distance to the boundary is necessary.
  • domain assumption Evidence from studies with different fairness metrics, DP mechanisms, and datasets can be pooled to infer causal necessity of a factor when at least one counterexample exists.
    This underpins all the 'not necessary' conclusions in Table I and Appendix B, where variation across settings is treated as a natural experiment.
  • domain assumption The 20 papers returned by the Google Scholar query constitute the relevant literature for causal conclusions.
    The selection is disclosed but its completeness is asserted, not established, in Section III and Appendix A.
  • ad hoc to paper The four-layer taxonomy is complete because it exhausts the ML pipeline stages.
    Claimed in Section IV with no formal argument; completeness is definitional over their chosen stages.

how reviews work

0 comments
Cite this review

Pith. "Pith review of SoK: What Makes Private Learning Unfair?." pith.science (2026). https://pith.science/paper/73RZ72GR

@misc{pith2026250114414,
  author       = {Pith},
  title        = {Pith review of: SoK: What Makes Private Learning Unfair?},
  year         = {2026},
  howpublished = {\url{https://pith.science/paper/73RZ72GR}},
  note         = {Machine review of arXiv:2501.14414}
}
read the original abstract

Differential privacy has emerged as the most studied framework for privacy-preserving machine learning. However, recent studies show that enforcing differential privacy guarantees can not only significantly degrade the utility of the model, but also amplify existing disparities in its predictive performance across demographic groups. Although there is extensive research on the identification of factors that contribute to this phenomenon, we still lack a complete understanding of the mechanisms through which differential privacy exacerbates disparities. The literature on this problem is muddled by varying definitions of fairness, differential privacy mechanisms, and inconsistent experimental settings, often leading to seemingly contradictory results. This survey provides the first comprehensive overview of the factors that contribute to the disparate effect of training models with differential privacy guarantees. We discuss their impact and analyze their causal role in such a disparate effect. Our analysis is guided by a taxonomy that categorizes these factors by their position within the machine learning pipeline, allowing us to draw conclusions about their interaction and the feasibility of potential mitigation strategies. We find that factors related to the training dataset and the underlying distribution play a decisive role in the occurrence of disparate impact, highlighting the need for research on these factors to address the issue.

Figures

Figures reproduced from arXiv: 2501.14414 by the authors.

Figure 1
Figure 1. Taxonomy of factors contributing to DP’s exacerbation of unfairness [PITH_FULL_IMAGE:figures/full_fig_p004_1.png] view at source ↗

Discussion (0). Continue with ORCID to comment.

Reference graph

Works this paper leans on

70 extracted references · 46 canonical work pages

  1. [17]

    Differential privacy has bounded impact on fairness in classification,

    P. Mangold, M. Perrot, A. Bellet, and M. Tommasi, “Differential privacy has bounded impact on fairness in classification,” 2023

  2. [22]

    On the compatibility of privacy and fairness,

    R. Cummings, V . Gupta, D. Kimpara, and J. Morgenstern, “On the compatibility of privacy and fairness,” in Adjunct publication of the 27th conference on user modeling, adaptation and personalization , 2019, pp. 309–315

  3. [11]

    Disparate impact in differential privacy from gradient misalignment,

    M. S. Esipova, A. A. Ghomi, Y . Luo, and J. C. Cresswell, “Disparate impact in differential privacy from gradient misalignment,” in The Eleventh International Conference on Learning Representations , 2023. [Online]. Available: https://openreview.net/forum?id=qLOaeRvteqbx

  4. [1]

    Differential privacy,

    C. Dwork, “Differential privacy,” in International colloquium on au- tomata, languages, and programming . Springer, 2006, pp. 1–12

  5. [2]

    Deep learning with differential privacy,

    M. Abadi, A. Chu, I. Goodfellow, H. B. McMahan, I. Mironov, K. Talwar, and L. Zhang, “Deep learning with differential privacy,” in Proceedings of the 2016 ACM SIGSAC conference on computer and communications security, 2016, pp. 308–318

  6. [3]

    Differential privacy has disparate impact on model accuracy,

    E. Bagdasaryan, O. Poursaeed, and V . Shmatikov, “Differential privacy has disparate impact on model accuracy,” Advances in neural informa- tion processing systems , vol. 32, 2019

  7. [4]

    Gender shades: Intersectional accuracy disparities in commercial gender classification,

    J. Buolamwini and T. Gebru, “Gender shades: Intersectional accuracy disparities in commercial gender classification,” in Conference on fair- ness, accountability and transparency . PMLR, 2018, pp. 77–91

  8. [5]

    The risk of racial bias in hate speech detection,

    M. Sap, D. Card, S. Gabriel, Y . Choi, and N. A. Smith, “The risk of racial bias in hate speech detection,” in Proceedings of the 57th annual meeting of the association for computational linguistics, 2019, pp. 1668– 1678

Show all 70 references
  1. [6]

    Sources of bias in artificial intelligence that perpetuate healthcare disparities—a global review,

    L. A. Celi, J. Cellini, M.-L. Charpignon, E. C. Dee, F. Dernoncourt, R. Eber, W. G. Mitchell, L. Moukheiber, J. Schirmer, J. Situ et al. , “Sources of bias in artificial intelligence that perpetuate healthcare disparities—a global review,” PLOS Digital Health , vol. 1, no. 3, ...

  2. [7]

    A survey on bias and fairness in machine learning,

    N. Mehrabi, F. Morstatter, N. Saxena, K. Lerman, and A. Galstyan, “A survey on bias and fairness in machine learning,” ACM computing surveys (CSUR), vol. 54, no. 6, pp. 1–35, 2021

  3. [8]

    Big data’s disparate impact,

    S. Barocas and A. D. Selbst, “Big data’s disparate impact,” Calif. L. Rev., vol. 104, p. 671, 2016

  4. [9]

    Removing disparate impact on model accuracy in differentially private stochastic gradient descent,

    D. Xu, W. Du, and X. Wu, “Removing disparate impact on model accuracy in differentially private stochastic gradient descent,” in Proceedings of the 27th ACM SIGKDD Conference on Knowledge Discovery & Data Mining , ser. KDD ’21. New York, NY , USA: Association for Computing Mac...

  5. [10]

    Differentially private empirical risk minimization under the fairness lens,

    C. Tran, M. Dinh, and F. Fioretto, “Differentially private empirical risk minimization under the fairness lens,” Advances in Neural Information Processing Systems, vol. 34, pp. 27 555–27 565, 2021

  6. [12]

    De-amplifying bias from differential privacy in language model fine-tuning,

    S. Srivastava, P. Mardziel, Z. Zhang, A. Ahlawat, A. Datta, and J. C. Mitchell, “De-amplifying bias from differential privacy in language model fine-tuning,” arXiv preprint arXiv:2402.04489 , 2024

  7. [13]

    Mitigating disparate impact on model accuracy in differentially private learning,

    W. Liu, X. Wang, H. Zheng, B. Jin, X. Wang, and H. Zha, “Mitigating disparate impact on model accuracy in differentially private learning,” Information Sciences, vol. 616, pp. 108–126, 2022

  8. [14]

    Dp-sgd vs pate: Which has less disparate impact on model accuracy?

    A. Uniyal, R. Naidu, S. Kotti, S. Singh, P. J. Kenfack, F. Mireshghallah, and A. Trask, “Dp-sgd vs pate: Which has less disparate impact on model accuracy?” arXiv preprint arXiv:2106.12576 , 2021

  9. [15]

    Achieving differential privacy and fairness in logistic regression,

    D. Xu, S. Yuan, and X. Wu, “Achieving differential privacy and fairness in logistic regression,” in Companion proceedings of The 2019 world wide web conference , 2019, pp. 594–599

  10. [16]

    Randomized response has no disparate impact on model accuracy,

    A. N. Carey, K. Bhaila, and X. Wu, “Randomized response has no disparate impact on model accuracy,” in 2023 IEEE International Conference on Big Data (BigData) . IEEE, 2023, pp. 5460–5465

  11. [18]

    On the impact of multi-dimensional local differential privacy on fairness,

    K. Makhlouf, H. H. Arcolezi, S. Zhioua, G. B. Brahim, and C. Palamidessi, “On the impact of multi-dimensional local differential privacy on fairness,” in Submitted to ECML (Journal Track) , 2024

  12. [19]

    Exploring the unfairness of dp- sgd across settings,

    F. Noe, R. Herskind, and A. Søgaard, “Exploring the unfairness of dp- sgd across settings,” arXiv preprint arXiv:2202.12058 , 2022

  13. [20]

    A systematic and formal study of the impact of local differential privacy on fairness: Preliminary results,

    K. Makhlouf, T. Stefanovi ´c, H. H. Arcolezi, and C. Palamidessi, “A systematic and formal study of the impact of local differential privacy on fairness: Preliminary results,” in 2024 IEEE 37th Computer Security Foundations Symposium (CSF). IEEE, 2024, pp. 1–16

  14. [21]

    An empirical analysis of fairness notions under differential privacy,

    A. S. de Oliveira, C. Kaplan, K. Mallat, and T. Chakraborty, “An empirical analysis of fairness notions under differential privacy,” in PPAI 2023-Fourth AAAI Workshop on Privacy-Preserving Artificial Intelligence, 2023

  15. [23]

    Preserving fairness and diagnostic accuracy in private large-scale ai models for medical imaging,

    S. Tayebi Arasteh, A. Ziller, C. Kuhl, M. Makowski, S. Nebelung, R. Braren, D. Rueckert, D. Truhn, and G. Kaissis, “Preserving fairness and diagnostic accuracy in private large-scale ai models for medical imaging,” Communications Medicine, vol. 4, no. 1, p. 46, 2024

  16. [24]

    How unfair is private learning?

    A. Sanyal, Y . Hu, and F. Yang, “How unfair is private learning?” in Uncertainty in Artificial Intelligence . PMLR, 2022, pp. 1738–1748

  17. [25]

    Neither private nor fair: Impact of data imbalance on utility and fairness in differential privacy,

    T. Farrand, F. Mireshghallah, S. Singh, and A. Trask, “Neither private nor fair: Impact of data imbalance on utility and fairness in differential privacy,” in Proceedings of the 2020 workshop on privacy-preserving machine learning in practice , 2020, pp. 15–19

  18. [26]

    Differential privacy and fairness in decisions and learning tasks: A survey,

    F. Fioretto, C. Tran, P. Van Hentenryck, and K. Zhu, “Differential privacy and fairness in decisions and learning tasks: A survey,” inProceedings of the Thirty-First International Joint Conference on Artificial Intelligence, IJCAI-22, L. D. Raedt, Ed. International Joint Confe...

  19. [27]

    Shalev-Shwartz and S

    S. Shalev-Shwartz and S. Ben-David, Understanding machine learning: From theory to algorithms . Cambridge university press, 2014

  20. [28]

    Stochastic gradient learning in neural networks,

    L. Bottou et al. , “Stochastic gradient learning in neural networks,” Proceedings of Neuro-Nımes, vol. 91, no. 8, p. 12, 1991

  21. [29]

    What can we learn privately?

    S. P. Kasiviswanathan, H. K. Lee, K. Nissim, S. Raskhodnikova, and A. Smith, “What can we learn privately?” SIAM Journal on Computing, vol. 40, no. 3, pp. 793–826, 2011

  22. [30]

    How to dp- fy ml: A practical guide to machine learning with differential privacy,

    N. Ponomareva, H. Hazimeh, A. Kurakin, Z. Xu, C. Denison, H. B. McMahan, S. Vassilvitskii, S. Chien, and A. G. Thakurta, “How to dp- fy ml: A practical guide to machine learning with differential privacy,” Journal of Artificial Intelligence Research, vol. 77, pp. 1113–1201, 2023

  23. [31]

    Barocas, M

    S. Barocas, M. Hardt, and A. Narayanan, Fairness and machine learn- ing: Limitations and opportunities . MIT press, 2023

  24. [32]

    Fairness through awareness,

    C. Dwork, M. Hardt, T. Pitassi, O. Reingold, and R. Zemel, “Fairness through awareness,” in Proceedings of the 3rd innovations in theoretical computer science conference , 2012, pp. 214–226

  25. [33]

    Fairness constraints: Mechanisms for fair classification,

    M. B. Zafar, I. Valera, M. G. Rogriguez, and K. P. Gummadi, “Fairness constraints: Mechanisms for fair classification,” in Artificial intelligence and statistics. PMLR, 2017, pp. 962–970

  26. [34]

    Equality of opportunity in supervised learning,

    M. Hardt, E. Price, and N. Srebro, “Equality of opportunity in supervised learning,” Advances in neural information processing systems , vol. 29, 2016

  27. [35]

    Algo- rithmic decision making and the cost of fairness,

    S. Corbett-Davies, E. Pierson, A. Feller, S. Goel, and A. Huq, “Algo- rithmic decision making and the cost of fairness,” in Proceedings of the 23rd acm sigkdd international conference on knowledge discovery and data mining, 2017, pp. 797–806

  28. [36]

    Fair prediction with disparate impact: A study of bias in recidivism prediction instruments,

    A. Chouldechova, “Fair prediction with disparate impact: A study of bias in recidivism prediction instruments,” Big data , vol. 5, no. 2, pp. 153–163, 2017

  29. [37]

    Differentially private fair binary classifications,

    H. Ghoukasian and S. Asoodeh, “Differentially private fair binary classifications,” arXiv preprint arXiv:2402.15603 , 2024

  30. [38]

    Differentially private fair learning,

    M. Jagielski, M. Kearns, J. Mao, A. Oprea, A. Roth, S. Sharifi- Malvajerdi, and J. Ullman, “Differentially private fair learning,” in International Conference on Machine Learning . PMLR, 2019, pp. 3000–3008

  31. [39]

    The mnist database of handwritten digit images for machine learning research,

    L. Deng, “The mnist database of handwritten digit images for machine learning research,” IEEE Signal Processing Magazine , vol. 29, no. 6, pp. 141–142, 2012

  32. [40]

    Adult Data Set,

    R. Kohavi and B. Becker, “Adult Data Set,” UCI Machine Learning Repository, 1996. [Online]. Available: https://archive.ics.uci.edu/ml/ datasets/adult

  33. [41]

    Handling conditional discrim- ination,

    I. ˇZliobaite, F. Kamiran, and T. Calders, “Handling conditional discrim- ination,” in 2011 IEEE 11th international conference on data mining . IEEE, 2011, pp. 992–1001

  34. [42]

    Semi-supervised knowledge transfer for deep learning from private training data,

    N. Papernot, M. Abadi, U. Erlingsson, I. Goodfellow, and K. Talwar, “Semi-supervised knowledge transfer for deep learning from private training data,” arXiv preprint arXiv:1610.05755 , 2016

  35. [43]

    Reading digits in natural images with unsupervised feature learning,

    Y . Netzer, T. Wang, A. Coates, A. Bissacco, B. Wu, A. Y . Ng et al. , “Reading digits in natural images with unsupervised feature learning,” in NIPS workshop on deep learning and unsupervised feature learning , vol. 2011, no. 2. Granada, 2011, p. 4

  36. [44]

    Functional mechanism: regression analysis under differential privacy,

    J. Zhang, Z. Zhang, X. Xiao, Y . Yang, and M. Winslett, “Functional mechanism: regression analysis under differential privacy,” Proceedings of the VLDB Endowment , vol. 5, no. 11, pp. 1364–1375, 2012

  37. [45]

    Randomized response: A survey technique for eliminating evasive answer bias,

    S. L. Warner, “Randomized response: A survey technique for eliminating evasive answer bias,” Journal of the American Statistical Association , vol. 60, no. 309, pp. 63–69, 1965

  38. [46]

    “you can’t fix what you can’t measure

    M. Juarez and A. Korolova, ““you can’t fix what you can’t measure”: Privately measuring demographic performance disparities in federated learning,” in Workshop on Algorithmic Fairness through the Lens of Causality and Privacy . PMLR, 2023, pp. 67–85

  39. [47]

    Principal component analysis,

    H. Abdi and L. J. Williams, “Principal component analysis,” Wiley interdisciplinary reviews: computational statistics, vol. 2, no. 4, pp. 433– 459, 2010

  40. [48]

    Wilds: A benchmark of in-the-wild distribution shifts,

    P. W. Koh, S. Sagawa, H. Marklund, S. M. Xie, M. Zhang, A. Balsubramani, W. Hu, M. Yasunaga, R. L. Phillips, I. Gao, T. Lee, E. David, I. Stavness, W. Guo, B. Earnshaw, I. Haque, S. M. Beery, J. Leskovec, A. Kundaje, E. Pierson, S. Levine, C. Finn, and P. Liang, “Wilds: A benc...

  41. [49]

    Differentially private empirical risk minimization

    K. Chaudhuri, C. Monteleoni, and A. D. Sarwate, “Differentially private empirical risk minimization.” Journal of Machine Learning Research , vol. 12, no. 3, 2011

  42. [50]

    Deep learning face attributes in the wild,

    Z. Liu, P. Luo, X. Wang, and X. Tang, “Deep learning face attributes in the wild,” in Proceedings of International Conference on Computer Vision (ICCV), December 2015

  43. [51]

    Retiring adult: New datasets for fair machine learning,

    F. Ding, M. Hardt, J. Miller, and L. Schmidt, “Retiring adult: New datasets for fair machine learning,” Advances in Neural Information Processing Systems, vol. 34, 2021

  44. [52]

    Dpnas: Neural architecture search for deep learning with differential privacy,

    A. Cheng, J. Wang, X. S. Zhang, Q. Chen, P. Wang, and J. Cheng, “Dpnas: Neural architecture search for deep learning with differential privacy,” in Proceedings of the AAAI Conference on Artificial Intelli- gence, vol. 36, no. 6, 2022, pp. 6358–6366

  45. [53]

    Learning multiple layers of features from tiny images,

    A. Krizhevsky, “Learning multiple layers of features from tiny images,” University of Toronto, Technical Report TR-2009, 2009. [Online]. Available: https://www.cs.toronto.edu/∼kriz/learning-features-2009-TR. pdf

  46. [54]

    Hessian- based analysis of large batch training and robustness to adversaries,

    Z. Yao, A. Gholami, Q. Lei, K. Keutzer, and M. W. Mahoney, “Hessian- based analysis of large batch training and robustness to adversaries,” Advances in Neural Information Processing Systems , vol. 31, 2018

  47. [55]

    Fairdp: Certified fairness with differential privacy,

    K. Tran, F. Fioretto, I. Khalil, M. T. Thai, and N. Phan, “Fairdp: Certified fairness with differential privacy,” arXiv preprint arXiv:2305.16474 , 2023

  48. [56]

    On the convergence and calibration of deep learning with differential privacy,

    Z. Bu, H. Wang, Z. Dai, and Q. Long, “On the convergence and calibration of deep learning with differential privacy,” Transactions on machine learning research, vol. 2023, 2023

  49. [57]

    Fairer machine learning in the real world: Mitigating discrimination without collecting sensitive data,

    M. Veale and R. Binns, “Fairer machine learning in the real world: Mitigating discrimination without collecting sensitive data,” Big Data & Society, vol. 4, no. 2, p. 2053951717743530, 2017

  50. [58]

    Awareness in practice: tensions in access to sensitive attribute data for antidiscrimination,

    M. Bogen, A. Rieke, and S. Ahmed, “Awareness in practice: tensions in access to sensitive attribute data for antidiscrimination,” in Proceedings of the 2020 conference on fairness, accountability, and transparency , 2020, pp. 492–500

  51. [59]

    The trouble with bias,

    K. Crawford, “The trouble with bias,” NeurIPS Keynote speech (201. https://web.archive.org/web/20210830213447/https://github.com/ Blooware/blooface, 2017, Accessed: 2024-09-10

  52. [60]

    Why is my classifier discriminatory?

    I. Chen, F. D. Johansson, and D. Sontag, “Why is my classifier discriminatory?” Advances in neural information processing systems , vol. 31, 2018

  53. [61]

    Explainable ai: A review of machine learning interpretability methods,

    P. Linardatos, V . Papastefanopoulos, and S. Kotsiantis, “Explainable ai: A review of machine learning interpretability methods,”Entropy, vol. 23, no. 1, p. 18, 2020

  54. [62]

    The impossibility of

    T. Miconi, “The impossibility of” fairness”: a generalized impossibility result for decisions,” arXiv preprint arXiv:1707.01195 , 2017

  55. [63]

    The impossibility theorem of machine fairness–a causal perspective,

    K. K. Saravanakumar, “The impossibility theorem of machine fairness–a causal perspective,” arXiv preprint arXiv:2007.06024 , 2020

  56. [64]

    Compas recidivism risk score data,

    “Compas recidivism risk score data,” 2016, data and analysis by ProPublica. [Online]. Available: https://www.propublica.org/datastore/ dataset/compas-recidivism-risk-score-data-and-analysis

  57. [65]

    Religious landscape study,

    P. R. Center, “Religious landscape study,” 2014. [Online]. Available: https://www.pewforum.org/religious-landscape-study/

  58. [66]

    Gender shades: Intersectional accuracy disparities in commercial gender classification,

    J. Buolamwini and T. Gebru, “Gender shades: Intersectional accuracy disparities in commercial gender classification,” 2018. [Online]. Available: http://gendershades.org

  59. [67]

    A survey of transformers,

    T. Lin, Y . Wang, X. Liu, and X. Qiu, “A survey of transformers,” AI open, vol. 3, pp. 111–132, 2022

  60. [68]

    Bert: Pre-training of deep bidirectional transformers for language understanding,

    J. Devlin, “Bert: Pre-training of deep bidirectional transformers for language understanding,” arXiv preprint arXiv:1810.04805 , 2018

  61. [69]

    Distilbert, a distilled version of bert: smaller, faster, cheaper and lighter,

    V . Sanh, L. Debut, J. Chaumond, and T. Wolf, “Distilbert, a distilled version of bert: smaller, faster, cheaper and lighter,” in NeurIPS EMC2 Workshop, 2019. APPENDIX A GOOGLE SCHOLAR SEARCH QUERY In this section, we provide the details about the construction of the Google Sc...

  62. [70]

    examines gradient clipping as a contributing factor. On the MNIST dataset, studies [14], [9], and [11] offer further complementary insights by addressing distinct goals, such as comparing DP-SGD with PATE ( [14]), developing mitigation techniques [9], and analyzing gradient cl...

Pith tools

Reviewed August 10, 2026 · model on record in the stance chip above.