{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2019:HGRV2H3NW5WJ3NRQCUD3WIZ67A","short_pith_number":"pith:HGRV2H3N","schema_version":"1.0","canonical_sha256":"39a35d1f6db76c9db6301507bb233ef82c0953afddf51b17313fc0f2ac8e9537","source":{"kind":"arxiv","id":"1908.10530","version":1},"attestation_state":"computed","paper":{"title":"R\\'enyi Differential Privacy of the Sampled Gaussian Mechanism","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.CR","stat.ML"],"primary_cat":"cs.LG","authors_text":"Ilya Mironov, Kunal Talwar, Li Zhang","submitted_at":"2019-08-28T03:03:25Z","abstract_excerpt":"The Sampled Gaussian Mechanism (SGM)---a composition of subsampling and the additive Gaussian noise---has been successfully used in a number of machine learning applications. The mechanism's unexpected power is derived from privacy amplification by sampling where the privacy cost of a single evaluation diminishes quadratically, rather than linearly, with the sampling rate. Characterizing the precise privacy properties of SGM motivated development of several relaxations of the notion of differential privacy.\n  This work unifies and fills in gaps in published results on SGM. We describe a numeri"},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"1908.10530","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2019-08-28T03:03:25Z","cross_cats_sorted":["cs.CR","stat.ML"],"title_canon_sha256":"8f0b472a27da448caf663044dfb0f7e5ab7fd79b2566fc3cba994318c0ff2689","abstract_canon_sha256":"3a2d989b5149a55bacab7a3fff22ce028c1b939fa4be802fc6006f6eea05763a"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-07-05T00:00:18.125419Z","signature_b64":"hd2Jk0VDa+wnS7piKHp5uop3ddMrGyI2rtjtZIUlT3HErbiseMSgb1JBGEl11LWFgQZ8xdNiX01t+emeUqvjAw==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"39a35d1f6db76c9db6301507bb233ef82c0953afddf51b17313fc0f2ac8e9537","last_reissued_at":"2026-07-05T00:00:18.125013Z","signature_status":"signed_v1","first_computed_at":"2026-07-05T00:00:18.125013Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"R\\'enyi Differential Privacy of the Sampled Gaussian Mechanism","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.CR","stat.ML"],"primary_cat":"cs.LG","authors_text":"Ilya Mironov, Kunal Talwar, Li Zhang","submitted_at":"2019-08-28T03:03:25Z","abstract_excerpt":"The Sampled Gaussian Mechanism (SGM)---a composition of subsampling and the additive Gaussian noise---has been successfully used in a number of machine learning applications. The mechanism's unexpected power is derived from privacy amplification by sampling where the privacy cost of a single evaluation diminishes quadratically, rather than linearly, with the sampling rate. Characterizing the precise privacy properties of SGM motivated development of several relaxations of the notion of differential privacy.\n  This work unifies and fills in gaps in published results on SGM. We describe a numeri"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1908.10530","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/1908.10530/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"1908.10530","created_at":"2026-07-05T00:00:18.125064+00:00"},{"alias_kind":"arxiv_version","alias_value":"1908.10530v1","created_at":"2026-07-05T00:00:18.125064+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1908.10530","created_at":"2026-07-05T00:00:18.125064+00:00"},{"alias_kind":"pith_short_12","alias_value":"HGRV2H3NW5WJ","created_at":"2026-07-05T00:00:18.125064+00:00"},{"alias_kind":"pith_short_16","alias_value":"HGRV2H3NW5WJ3NRQ","created_at":"2026-07-05T00:00:18.125064+00:00"},{"alias_kind":"pith_short_8","alias_value":"HGRV2H3N","created_at":"2026-07-05T00:00:18.125064+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":15,"internal_anchor_count":1,"sample":[{"citing_arxiv_id":"2607.05866","citing_title":"Differentially Private Natural Gradient Descent","ref_index":34,"is_internal_anchor":true},{"citing_arxiv_id":"2606.21757","citing_title":"AdaPrivate-TS: Private Thompson Sampling for Contextual Bandits with Privacy Amplification","ref_index":7,"is_internal_anchor":false},{"citing_arxiv_id":"2606.09401","citing_title":"Benchmarking Empirical Privacy Protection for Adaptations of Large Language Models","ref_index":245,"is_internal_anchor":false},{"citing_arxiv_id":"2605.06259","citing_title":"Trade-off Functions for DP-SGD with Subsampling based on Random Shuffling: Tight Upper and Lower Bounds","ref_index":21,"is_internal_anchor":false},{"citing_arxiv_id":"2605.26243","citing_title":"Provably Communication-Efficient and Privacy-Preserving Federated Graph Neural Networks","ref_index":55,"is_internal_anchor":false},{"citing_arxiv_id":"2605.30312","citing_title":"DP-SAPF: Saliency-Aware Parameter Fine-tuning of Public Models for Differentially Private Image Synthesis","ref_index":23,"is_internal_anchor":false},{"citing_arxiv_id":"2605.15648","citing_title":"Rethinking the Security of DP-SGD: A Corrected Analysis of Differentially Private Machine Learning","ref_index":32,"is_internal_anchor":false},{"citing_arxiv_id":"2605.17432","citing_title":"DP-SelFT: Differentially Private Selective Fine-Tuning for Large Language Models","ref_index":24,"is_internal_anchor":false},{"citing_arxiv_id":"2506.00158","citing_title":"Privacy Amplification in Differentially Private Zeroth-Order Optimization with Hidden States","ref_index":19,"is_internal_anchor":false},{"citing_arxiv_id":"2509.03472","citing_title":"DPQuant: Efficient and Differentially-Private Model Training via Dynamic Quantization Scheduling","ref_index":33,"is_internal_anchor":false},{"citing_arxiv_id":"2601.10237","citing_title":"Fundamental Limitations of Favorable Privacy-Utility Guarantees for DP-SGD","ref_index":51,"is_internal_anchor":false},{"citing_arxiv_id":"2605.05723","citing_title":"$\\alpha$-Wasserstein Mechanism for R\\'{e}nyi Pufferfish Privacy","ref_index":28,"is_internal_anchor":false},{"citing_arxiv_id":"2605.06259","citing_title":"Trade-off Functions for DP-SGD with Subsampling based on Random Shuffling: Tight Upper and Lower Bounds","ref_index":21,"is_internal_anchor":false},{"citing_arxiv_id":"2604.20985","citing_title":"Differentially Private Model Merging","ref_index":23,"is_internal_anchor":false},{"citing_arxiv_id":"2605.07930","citing_title":"INO-SGD: Addressing Utility Imbalance under Individualized Differential Privacy","ref_index":103,"is_internal_anchor":false}]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/HGRV2H3NW5WJ3NRQCUD3WIZ67A","json":"https://pith.science/pith/HGRV2H3NW5WJ3NRQCUD3WIZ67A.json","graph_json":"https://pith.science/api/pith-number/HGRV2H3NW5WJ3NRQCUD3WIZ67A/graph.json","events_json":"https://pith.science/api/pith-number/HGRV2H3NW5WJ3NRQCUD3WIZ67A/events.json","paper":"https://pith.science/paper/HGRV2H3N"},"agent_actions":{"view_html":"https://pith.science/pith/HGRV2H3NW5WJ3NRQCUD3WIZ67A","download_json":"https://pith.science/pith/HGRV2H3NW5WJ3NRQCUD3WIZ67A.json","view_paper":"https://pith.science/paper/HGRV2H3N","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=1908.10530&json=true","fetch_graph":"https://pith.science/api/pith-number/HGRV2H3NW5WJ3NRQCUD3WIZ67A/graph.json","fetch_events":"https://pith.science/api/pith-number/HGRV2H3NW5WJ3NRQCUD3WIZ67A/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/HGRV2H3NW5WJ3NRQCUD3WIZ67A/action/timestamp_anchor","attest_storage":"https://pith.science/pith/HGRV2H3NW5WJ3NRQCUD3WIZ67A/action/storage_attestation","attest_author":"https://pith.science/pith/HGRV2H3NW5WJ3NRQCUD3WIZ67A/action/author_attestation","sign_citation":"https://pith.science/pith/HGRV2H3NW5WJ3NRQCUD3WIZ67A/action/citation_signature","submit_replication":"https://pith.science/pith/HGRV2H3NW5WJ3NRQCUD3WIZ67A/action/replication_record"}},"created_at":"2026-07-05T00:00:18.125064+00:00","updated_at":"2026-07-05T00:00:18.125064+00:00"}