[{"user_id":"2DF688A6-F248-11E8-B48F-1D18A9856A87","_id":"22102","ec_funded":1,"article_number":"218","publication_identifier":{"eissn":["2475-1421"]},"OA_place":"publisher","has_accepted_license":"1","citation":{"ama":"Chatterjee K, Goharshady E, Zikelic D. SuperDP: Differential privacy refutation via supermartingales. <i>Proceedings of the ACM on Programming Languages</i>. 2026;10(PLDI). doi:<a href=\"https://doi.org/10.1145/3808296\">10.1145/3808296</a>","apa":"Chatterjee, K., Goharshady, E., &#38; Zikelic, D. (2026). SuperDP: Differential privacy refutation via supermartingales. <i>Proceedings of the ACM on Programming Languages</i>. Association for Computing Machinery. <a href=\"https://doi.org/10.1145/3808296\">https://doi.org/10.1145/3808296</a>","short":"K. Chatterjee, E. Goharshady, D. Zikelic, Proceedings of the ACM on Programming Languages 10 (2026).","ista":"Chatterjee K, Goharshady E, Zikelic D. 2026. SuperDP: Differential privacy refutation via supermartingales. Proceedings of the ACM on Programming Languages. 10(PLDI), 218.","mla":"Chatterjee, Krishnendu, et al. “SuperDP: Differential Privacy Refutation via Supermartingales.” <i>Proceedings of the ACM on Programming Languages</i>, vol. 10, no. PLDI, 218, Association for Computing Machinery, 2026, doi:<a href=\"https://doi.org/10.1145/3808296\">10.1145/3808296</a>.","ieee":"K. Chatterjee, E. Goharshady, and D. Zikelic, “SuperDP: Differential privacy refutation via supermartingales,” <i>Proceedings of the ACM on Programming Languages</i>, vol. 10, no. PLDI. Association for Computing Machinery, 2026.","chicago":"Chatterjee, Krishnendu, Ehsan Goharshady, and Dorde Zikelic. “SuperDP: Differential Privacy Refutation via Supermartingales.” <i>Proceedings of the ACM on Programming Languages</i>. Association for Computing Machinery, 2026. <a href=\"https://doi.org/10.1145/3808296\">https://doi.org/10.1145/3808296</a>."},"PlanS_conform":"1","tmp":{"legal_code_url":"https://creativecommons.org/licenses/by/4.0/legalcode","name":"Creative Commons Attribution 4.0 International Public License (CC-BY 4.0)","image":"/images/cc_by.png","short":"CC BY (4.0)"},"quality_controlled":"1","department":[{"_id":"KrCh"}],"title":"SuperDP: Differential privacy refutation via supermartingales","researchdata_availability":"yes","date_created":"2026-06-21T22:02:59Z","month":"06","scopus_import":"1","article_type":"original","oa":1,"license":"https://creativecommons.org/licenses/by/4.0/","publication_status":"published","dataavailabilitystatement":"The artifact supporting the findings of this study, which includes the underlying datasets, software\r\ncode, and experiments, is publicly available in Zenodo https://zenodo.org/records/19399862.","ddc":["000"],"acknowledgement":"The authors would like to thank Petr Novotný for valuable discussions that helped shape this work.\r\nThis research was supported by the Singapore Ministry of Education (MOE) Academic Research\r\nFund (AcRF) Tier 1 grant (Proposal ID: 25-SIS-SMU-009), Vienna Science and Technology Fund\r\n(WWTF), State of Lower Austria [Grant ID 10.47379/ICT25017], ERC CoG 863818 (ForM-SMArt),\r\nand Austrian Science Fund (FWF) 10.55776/COE12.","year":"2026","external_id":{"arxiv":["2603.26215"]},"arxiv":1,"keyword":["Static Program Analysis","Differential Privacy","Probabilistic Programming","Martingales"],"related_material":{"record":[{"id":"22134","status":"public","relation":"research_data"}]},"das_tickbox":"1","intvolume":"        10","date_updated":"2026-06-24T06:39:37Z","day":"08","project":[{"call_identifier":"H2020","_id":"0599E47C-7A3F-11EA-A408-12923DDC885E","name":"Formal Methods for Stochastic Models: Algorithms and Applications","grant_number":"863818"}],"author":[{"first_name":"Krishnendu","id":"2E5DCA20-F248-11E8-B48F-1D18A9856A87","orcid":"0000-0002-4561-241X","full_name":"Chatterjee, Krishnendu","last_name":"Chatterjee"},{"full_name":"Kafshdar Goharshadi, Ehsan","last_name":"Kafshdar Goharshadi","first_name":"Ehsan","id":"103b4fa0-896a-11ed-bdf8-87b697bef40d","orcid":"0000-0002-8595-0587"},{"orcid":"0000-0002-4681-1699","id":"294AA7A6-F248-11E8-B48F-1D18A9856A87","first_name":"Dorde","full_name":"Zikelic, Dorde","last_name":"Zikelic"}],"publisher":"Association for Computing Machinery","type":"journal_article","oa_version":"Published Version","file":[{"success":1,"checksum":"994bf21d6269dabccf1e1091e02962c5","date_created":"2026-06-24T06:19:56Z","relation":"main_file","creator":"dernst","file_size":858595,"access_level":"open_access","file_id":"22135","file_name":"2026_ProcACMProgrammingLanguages_Chatterjee.pdf","date_updated":"2026-06-24T06:19:56Z","content_type":"application/pdf"}],"publication":"Proceedings of the ACM on Programming Languages","supplementarymaterial":"no","issue":"PLDI","status":"public","corr_author":"1","abstract":[{"text":"Differential privacy (DP) has established itself as one of the standards for ensuring privacy of individual data. However, reasoning about DP is a challenging and error-prone task, hence methods for formal verification and refutation of DP properties have received significant interest in recent years. In this work, we present a novel method for automated formal refutation of є-DP. Our method refutes є-DP by searching for a pair of inputs together with a non-negative function over outputs whose expected value on these two inputs differs by a significant amount. The two inputs and the non-negative function over outputs are computed simultaneously, by utilizing upper expectation supermartingales and lower expectation submartingales from probabilistic program analysis, which we leverage to introduce a sound and complete proof rule for є-DP refutation. To the best of our knowledge, our method is the first method for є-DP refutation to offer the following four desirable features: (1) it is fully automated, (2) it is applicable to stochastic mechanisms with sampling instructions from both discrete and continuous distributions, (3) it provides soundness guarantees, and (4) it provides semi-completeness guarantees. Our experiments show that our prototype tool SuperDP achieves superior performance compared to the state of the art and manages to refute є-DP for a number of challenging examples collected from the literature, including ones that were out of the reach of prior methods.","lang":"eng"}],"file_date_updated":"2026-06-24T06:19:56Z","date_published":"2026-06-08T00:00:00Z","OA_type":"gold","language":[{"iso":"eng"}],"volume":10,"doi":"10.1145/3808296","article_processing_charge":"Yes"},{"user_id":"2DF688A6-F248-11E8-B48F-1D18A9856A87","_id":"22146","article_number":"2:1-2:21","ec_funded":1,"OA_place":"publisher","publication_identifier":{"eissn":["1868-8969"],"isbn":["9783959774192"]},"citation":{"ieee":"N. Kalinin and J. D. Andersson, “Learning rate scheduling with matrix factorization for private training,” in <i>7th Symposium on Foundations of Responsible Computing</i>, Cambridge, MA; United States, 2026, vol. 368.","chicago":"Kalinin, Nikita, and Joel D Andersson. “Learning Rate Scheduling with Matrix Factorization for Private Training.” In <i>7th Symposium on Foundations of Responsible Computing</i>, Vol. 368. Schloss Dagstuhl - Leibniz-Zentrum für Informatik, 2026. <a href=\"https://doi.org/10.4230/LIPIcs.FORC.2026.2\">https://doi.org/10.4230/LIPIcs.FORC.2026.2</a>.","mla":"Kalinin, Nikita, and Joel D. Andersson. “Learning Rate Scheduling with Matrix Factorization for Private Training.” <i>7th Symposium on Foundations of Responsible Computing</i>, vol. 368, 2:1-2:21, Schloss Dagstuhl - Leibniz-Zentrum für Informatik, 2026, doi:<a href=\"https://doi.org/10.4230/LIPIcs.FORC.2026.2\">10.4230/LIPIcs.FORC.2026.2</a>.","short":"N. Kalinin, J.D. Andersson, in:, 7th Symposium on Foundations of Responsible Computing, Schloss Dagstuhl - Leibniz-Zentrum für Informatik, 2026.","ista":"Kalinin N, Andersson JD. 2026. Learning rate scheduling with matrix factorization for private training. 7th Symposium on Foundations of Responsible Computing. FORC: Symposium on Foundations of Responsible Computing, LIPIcs, vol. 368, 2:1-2:21.","apa":"Kalinin, N., &#38; Andersson, J. D. (2026). Learning rate scheduling with matrix factorization for private training. In <i>7th Symposium on Foundations of Responsible Computing</i> (Vol. 368). Cambridge, MA; United States: Schloss Dagstuhl - Leibniz-Zentrum für Informatik. <a href=\"https://doi.org/10.4230/LIPIcs.FORC.2026.2\">https://doi.org/10.4230/LIPIcs.FORC.2026.2</a>","ama":"Kalinin N, Andersson JD. Learning rate scheduling with matrix factorization for private training. In: <i>7th Symposium on Foundations of Responsible Computing</i>. Vol 368. Schloss Dagstuhl - Leibniz-Zentrum für Informatik; 2026. doi:<a href=\"https://doi.org/10.4230/LIPIcs.FORC.2026.2\">10.4230/LIPIcs.FORC.2026.2</a>"},"has_accepted_license":"1","tmp":{"legal_code_url":"https://creativecommons.org/licenses/by/4.0/legalcode","name":"Creative Commons Attribution 4.0 International Public License (CC-BY 4.0)","image":"/images/cc_by.png","short":"CC BY (4.0)"},"title":"Learning rate scheduling with matrix factorization for private training","quality_controlled":"1","department":[{"_id":"ChLa"},{"_id":"GradSch"},{"_id":"MoHe"}],"date_created":"2026-06-28T22:01:34Z","researchdata_availability":"no","month":"06","alternative_title":["LIPIcs"],"scopus_import":"1","oa":1,"ddc":["000"],"publication_status":"published","acknowledgement":"We thank Rasmus Pagh, Christoph Lampert and Jalaj Upadhyay for valuable\r\ncomments on an early draft. We thank Ryan Mckenna for a fruitful discussion on the experiment\r\ndesign. We thank Antti Honkela for sharing insights on learning rate scheduling and DP.\r\nNikita P. Kalinin: Funded in part by the Austrian Science Fund (FWF) [10.55776/COE12].\r\nJoel Daniel Andersson: Funded by the European Union. Views and opinions expressed are however\r\nthose of the author(s) only and do not necessarily reflect those of the European Union or the European\r\nResearch Council Executive Agency. Neither the European Union nor the granting authority can be\r\nheld responsible for them. This project has received funding from the European Research Council\r\n(ERC) under the European Union’s Horizon 2020 research and innovation programme (MoDynStruct,\r\nNo. 101019564). Additional funding by Providentia, a Data Science Distinguished Investigator grant\r\nfrom Novo Nordisk Fonden, with additional support from VILLUM Investigator grant 54451.\r\n","arxiv":1,"external_id":{"arxiv":["2511.17994"]},"year":"2026","keyword":["differential privacy","machine learning","matrix factorization"],"intvolume":"       368","das_tickbox":"0","date_updated":"2026-06-29T06:56:34Z","day":"01","project":[{"name":"The design and evaluation of modern fully dynamic data structures","grant_number":"101019564","call_identifier":"H2020","_id":"bd9ca328-d553-11ed-ba76-dc4f890cfe62"}],"publisher":"Schloss Dagstuhl - Leibniz-Zentrum für Informatik","author":[{"id":"4b14526e-14d2-11ed-ba64-c14c9553d137","first_name":"Nikita","full_name":"Kalinin, Nikita","last_name":"Kalinin"},{"id":"4a893819-d954-11f0-89b1-e360bad9ccc5","first_name":"Joel D","full_name":"Andersson, Joel D","last_name":"Andersson"}],"type":"conference","oa_version":"Published Version","conference":{"end_date":"2026-06-05","name":"FORC: Symposium on Foundations of Responsible Computing","start_date":"2026-06-03","location":"Cambridge, MA; United States"},"supplementarymaterial":"no","file":[{"relation":"main_file","date_created":"2026-06-29T06:55:23Z","checksum":"c661f016d3861a1c1b590b87a744d087","success":1,"content_type":"application/pdf","file_name":"2026_LIPIcsFORC_Kalinin.pdf","date_updated":"2026-06-29T06:55:23Z","file_id":"22149","access_level":"open_access","file_size":1231914,"creator":"dernst"}],"publication":"7th Symposium on Foundations of Responsible Computing","abstract":[{"text":"We study differentially private model training with stochastic gradient descent under learning rate scheduling and correlated noise. Although correlated noise, in particular via matrix factorizations, has been shown to improve accuracy, prior theoretical work focused primarily on the prefix-sum workload. That workload assumes a constant learning rate, whereas in practice learning rate schedules are widely used to accelerate training and improve convergence. We close this gap by deriving general upper and lower bounds for a broad class of learning rate schedules in both single- and multi-epoch settings. Building on these results, we propose a learning-rate-aware factorization that achieves improvements over prefix-sum factorizations under both MaxSE and MeanSE error metrics. Our theoretical analysis yields memory-efficient constructions suitable for practical deployment, and experiments on CIFAR-10 and IMDB datasets confirm that schedule-aware factorizations improve accuracy in private training.","lang":"eng"}],"corr_author":"1","status":"public","date_published":"2026-06-01T00:00:00Z","language":[{"iso":"eng"}],"OA_type":"gold","file_date_updated":"2026-06-29T06:55:23Z","volume":368,"doi":"10.4230/LIPIcs.FORC.2026.2","article_processing_charge":"No"},{"has_accepted_license":"1","citation":{"apa":"Henzinger, M., Safavi Hemami, R., &#38; Vadhan, S. (2026). Concurrent composition for differentially private continual mechanisms. <i>Proceedings of the ACM on Management of Data</i>. Association for Computing Machinery. <a href=\"https://doi.org/10.1145/3801895\">https://doi.org/10.1145/3801895</a>","ama":"Henzinger M, Safavi Hemami R, Vadhan S. Concurrent composition for differentially private continual mechanisms. <i>Proceedings of the ACM on Management of Data</i>. 2026;4(2):1-26. doi:<a href=\"https://doi.org/10.1145/3801895\">10.1145/3801895</a>","short":"M. Henzinger, R. Safavi Hemami, S. Vadhan, Proceedings of the ACM on Management of Data 4 (2026) 1–26.","ista":"Henzinger M, Safavi Hemami R, Vadhan S. 2026. Concurrent composition for differentially private continual mechanisms. Proceedings of the ACM on Management of Data. 4(2), 1–26.","mla":"Henzinger, Monika, et al. “Concurrent Composition for Differentially Private Continual Mechanisms.” <i>Proceedings of the ACM on Management of Data</i>, vol. 4, no. 2, Association for Computing Machinery, 2026, pp. 1–26, doi:<a href=\"https://doi.org/10.1145/3801895\">10.1145/3801895</a>.","ieee":"M. Henzinger, R. Safavi Hemami, and S. Vadhan, “Concurrent composition for differentially private continual mechanisms,” <i>Proceedings of the ACM on Management of Data</i>, vol. 4, no. 2. Association for Computing Machinery, pp. 1–26, 2026.","chicago":"Henzinger, Monika, Roodabeh Safavi Hemami, and Salil Vadhan. “Concurrent Composition for Differentially Private Continual Mechanisms.” <i>Proceedings of the ACM on Management of Data</i>. Association for Computing Machinery, 2026. <a href=\"https://doi.org/10.1145/3801895\">https://doi.org/10.1145/3801895</a>."},"tmp":{"legal_code_url":"https://creativecommons.org/licenses/by/4.0/legalcode","name":"Creative Commons Attribution 4.0 International Public License (CC-BY 4.0)","image":"/images/cc_by.png","short":"CC BY (4.0)"},"PlanS_conform":"1","quality_controlled":"1","department":[{"_id":"MoHe"}],"title":"Concurrent composition for differentially private continual mechanisms","researchdata_availability":"no","date_created":"2026-07-13T14:59:14Z","user_id":"2DF688A6-F248-11E8-B48F-1D18A9856A87","_id":"22318","ec_funded":1,"publication_identifier":{"issn":["2836-6573"]},"OA_place":"publisher","year":"2026","arxiv":1,"external_id":{"arxiv":["2411.03299"]},"keyword":["differential privacy","concurrent composition","continual release","continual observation","data streaming","continual mechanisms","concurrent parallel composition","concurrent filter composition"],"das_tickbox":"0","intvolume":"         4","month":"06","article_type":"original","scopus_import":"1","oa":1,"acknowledgement":"1Salil Vadhan was supported by NSF grant BCS-2218803, a grant from the Sloan Foundation, and\r\na Simons Investigator Award. Work began while a Visiting Researcher at the Bocconi University\r\nDepartment of Computing Sciences, supported by Luca Trevisan’s ERC Project GA-834861.\r\n2Monika Henzinger and Roodabeh Safavi were supported by the European Research Council (ERC)\r\nunder the European Union’s Horizon 2020 research and innovation programme (Grant agreement\r\nNo. 101019564), and the Austrian Science Fund (FWF) under grants DOI 10.55776/Z422, DOI\r\n10.55776/I5982, and DOI 10.55776/P33775. For open access purposes, the author has applied a CC BY\r\npublic copyright license to any author-accepted manuscript version arising from this submission.\r\nViews and opinions expressed are however those of the author(s)\r\nonly and do not necessarily reflect those of the European Union\r\nor the European Research Council Executive Agency. Neither the\r\nEuropean Union nor the granting authority can be held responsible for them.","publication_status":"published","ddc":["000"],"publisher":"Association for Computing Machinery","author":[{"id":"540c9bbd-f2de-11ec-812d-d04a5be85630","first_name":"Monika H","orcid":"0000-0002-5008-6530","full_name":"Henzinger, Monika H","last_name":"Henzinger"},{"first_name":"Roodabeh","id":"72ed2640-8972-11ed-ae7b-f9c81ec75154","last_name":"Safavi Hemami","full_name":"Safavi Hemami, Roodabeh"},{"first_name":"Salil","full_name":"Vadhan, Salil","last_name":"Vadhan"}],"type":"journal_article","date_updated":"2026-07-16T09:14:49Z","day":"01","project":[{"name":"The design and evaluation of modern fully dynamic data structures","grant_number":"101019564","call_identifier":"H2020","_id":"bd9ca328-d553-11ed-ba76-dc4f890cfe62"},{"_id":"bda196b2-d553-11ed-ba76-8e8ee6c21103","grant_number":"I05982","name":"Static and Dynamic Hierarchical Graph Decompositions"},{"_id":"bd9e3a2e-d553-11ed-ba76-8aa684ce17fe","grant_number":"P33775","name":"Fast Algorithms for a Reactive Network Layer"},{"name":"Efficient algorithms","grant_number":"Z00422","_id":"34def286-11ca-11ed-8bc3-da5948e1613c"}],"file_date_updated":"2026-07-16T09:09:53Z","date_published":"2026-06-01T00:00:00Z","OA_type":"gold","language":[{"iso":"eng"}],"volume":4,"article_processing_charge":"Yes","doi":"10.1145/3801895","page":"1-26","oa_version":"Published Version","supplementarymaterial":"no","file":[{"checksum":"c6c5e256d02b90682c0690c3bee94040","date_created":"2026-07-16T09:09:53Z","relation":"main_file","success":1,"content_type":"application/pdf","access_level":"open_access","file_id":"22345","date_updated":"2026-07-16T09:09:53Z","file_name":"2026_ACMMgmtData_Henzinger.pdf","creator":"dernst","file_size":655405}],"publication":"Proceedings of the ACM on Management of Data","issue":"2","status":"public","abstract":[{"text":"Many intended uses of differential privacy involve a continual mechanism that is set up to run continuously\r\nover a long period of time, making more statistical releases as either queries come in or the dataset is updated.\r\nIn this paper, we give the first general treatment of privacy against adaptive adversaries for mechanisms that\r\nsupport dataset updates and a variety of queries, all arbitrarily interleaved. It also models a very general notion\r\nof neighboring, that includes both event-level and user-level privacy. We prove several concurrent composition\r\ntheorems for continual mechanisms, which ensure privacy even when an adversary can interleave its queries\r\nand dataset updates to the different composed mechanisms. Previous concurrent composition theorems for\r\ndifferential privacy were only for the case when the dataset is static, with no adaptive updates. We also give\r\nthe first interactive and continual generalizations of the “parallel composition theorem” for noninteractive\r\ndifferential privacy. Specifically, we show that the analogue of the noninteractive parallel composition theorem\r\nholds if either there are no adaptive dataset updates or each of the composed mechanisms satisfies pure\r\ndifferential privacy, but it fails to hold for composing approximately differentially private mechanisms with\r\ndataset updates. Thus, we prove a tight new composition theorem for this case. In addition, we prove concurrent\r\nfilter compositions theorems for the scenarios in which the privacy parameters are adaptively chosen. We\r\nextend these results to other measures of differential privacy, including Rényi DP and 𝑓 -DP.\r\nWe then formalize a set of general conditions on a continual mechanism M that runs multiple continual submechanisms such that the privacy guarantees of M follow directly using the above concurrent composition\r\ntheorems on the sub-mechanisms, without further privacy loss. This enables us to give a simpler and modular\r\nprivacy analysis of a recent continual histogram mechanism of Henzinger, Sricharan, and Steiner. In the\r\ncase of approximate DP, ours is the first proof that shows that its privacy holds against adaptive adversaries.\r\nWe also provide a framework that simplifies the analysis of local differential privacy when the protocol\r\nincludes multi-round server-user interactions. Using this result, we simplify the privacy analysis of the core\r\ndecomposition protocol of Dhulipala, Henzinger, Li, Liu, Sricharan, and Zhu [5].","lang":"eng"}],"corr_author":"1"}]
