{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2022:HWVO3YJKG6CK2E6523U5V2SP2W","short_pith_number":"pith:HWVO3YJK","schema_version":"1.0","canonical_sha256":"3daaede12a3784ad13ddd6e9daea4fd5ad21730068f20acc405aeb3199d89c9d","source":{"kind":"arxiv","id":"2211.04686","version":3},"attestation_state":"computed","paper":{"title":"Directional Privacy for Deep Learning","license":"http://creativecommons.org/licenses/by/4.0/","headline":"","cross_cats":["cs.CR"],"primary_cat":"cs.LG","authors_text":"Annabelle McIver, Mark Dras, Natasha Fernandes, Pedro Faustini, Shakila Tonni","submitted_at":"2022-11-09T05:18:08Z","abstract_excerpt":"Differentially Private Stochastic Gradient Descent (DP-SGD) is a key method for applying privacy in the training of deep learning models. It applies isotropic Gaussian noise to gradients during training, which can perturb these gradients in any direction, damaging utility. Metric DP, however, can provide alternative mechanisms based on arbitrary metrics that might be more suitable for preserving utility. In this paper, we apply \\textit{directional privacy}, via a mechanism based on the von Mises-Fisher (VMF) distribution, to perturb gradients in terms of \\textit{angular distance} so that gradi"},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"2211.04686","kind":"arxiv","version":3},"metadata":{"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.LG","submitted_at":"2022-11-09T05:18:08Z","cross_cats_sorted":["cs.CR"],"title_canon_sha256":"9d21e629896f9abc7b582de2e79c8872d02b9a92330f4d9e831e6457ef3705c3","abstract_canon_sha256":"5022696f8824968757dfe4317d4ee4d589afda99cb21aa31d7161c76854d0e6c"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-07-05T07:16:34.769032Z","signature_b64":"SOISol69BLc2v/WjnoC2md7QnwH3GkwfNESUgoTr56mzOD9i8CGtE7GK50XvOQxkjqKVynkswTROxhcfhWAnDQ==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"3daaede12a3784ad13ddd6e9daea4fd5ad21730068f20acc405aeb3199d89c9d","last_reissued_at":"2026-07-05T07:16:34.768532Z","signature_status":"signed_v1","first_computed_at":"2026-07-05T07:16:34.768532Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"Directional Privacy for Deep Learning","license":"http://creativecommons.org/licenses/by/4.0/","headline":"","cross_cats":["cs.CR"],"primary_cat":"cs.LG","authors_text":"Annabelle McIver, Mark Dras, Natasha Fernandes, Pedro Faustini, Shakila Tonni","submitted_at":"2022-11-09T05:18:08Z","abstract_excerpt":"Differentially Private Stochastic Gradient Descent (DP-SGD) is a key method for applying privacy in the training of deep learning models. It applies isotropic Gaussian noise to gradients during training, which can perturb these gradients in any direction, damaging utility. Metric DP, however, can provide alternative mechanisms based on arbitrary metrics that might be more suitable for preserving utility. In this paper, we apply \\textit{directional privacy}, via a mechanism based on the von Mises-Fisher (VMF) distribution, to perturb gradients in terms of \\textit{angular distance} so that gradi"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2211.04686","kind":"arxiv","version":3},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2211.04686/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"2211.04686","created_at":"2026-07-05T07:16:34.768591+00:00"},{"alias_kind":"arxiv_version","alias_value":"2211.04686v3","created_at":"2026-07-05T07:16:34.768591+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2211.04686","created_at":"2026-07-05T07:16:34.768591+00:00"},{"alias_kind":"pith_short_12","alias_value":"HWVO3YJKG6CK","created_at":"2026-07-05T07:16:34.768591+00:00"},{"alias_kind":"pith_short_16","alias_value":"HWVO3YJKG6CK2E65","created_at":"2026-07-05T07:16:34.768591+00:00"},{"alias_kind":"pith_short_8","alias_value":"HWVO3YJK","created_at":"2026-07-05T07:16:34.768591+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":1,"internal_anchor_count":1,"sample":[{"citing_arxiv_id":"2506.09312","citing_title":"What is the Cost of Differential Privacy for Deep Learning-Based Trajectory Generation?","ref_index":42,"is_internal_anchor":true}]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/HWVO3YJKG6CK2E6523U5V2SP2W","json":"https://pith.science/pith/HWVO3YJKG6CK2E6523U5V2SP2W.json","graph_json":"https://pith.science/api/pith-number/HWVO3YJKG6CK2E6523U5V2SP2W/graph.json","events_json":"https://pith.science/api/pith-number/HWVO3YJKG6CK2E6523U5V2SP2W/events.json","paper":"https://pith.science/paper/HWVO3YJK"},"agent_actions":{"view_html":"https://pith.science/pith/HWVO3YJKG6CK2E6523U5V2SP2W","download_json":"https://pith.science/pith/HWVO3YJKG6CK2E6523U5V2SP2W.json","view_paper":"https://pith.science/paper/HWVO3YJK","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=2211.04686&json=true","fetch_graph":"https://pith.science/api/pith-number/HWVO3YJKG6CK2E6523U5V2SP2W/graph.json","fetch_events":"https://pith.science/api/pith-number/HWVO3YJKG6CK2E6523U5V2SP2W/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/HWVO3YJKG6CK2E6523U5V2SP2W/action/timestamp_anchor","attest_storage":"https://pith.science/pith/HWVO3YJKG6CK2E6523U5V2SP2W/action/storage_attestation","attest_author":"https://pith.science/pith/HWVO3YJKG6CK2E6523U5V2SP2W/action/author_attestation","sign_citation":"https://pith.science/pith/HWVO3YJKG6CK2E6523U5V2SP2W/action/citation_signature","submit_replication":"https://pith.science/pith/HWVO3YJKG6CK2E6523U5V2SP2W/action/replication_record"}},"created_at":"2026-07-05T07:16:34.768591+00:00","updated_at":"2026-07-05T07:16:34.768591+00:00"}