IP Library Granted Patent US 12,223,083
Granted Patent B2
US 12,223,083 · App. 18/225,573 · Granted Feb 11, 2025

Differentially private processing and database storage

Inventors: Ishaan Nerurkar (Berkeley, CA); Christopher Hockenbrocht (Berkeley, CA); Liam Damewood (Walnut Creek, CA); Mihai Maruseac (Berkeley, CA); Alexander Rozenshteyn (Berkeley, CA)
Assignee: Snowflake Inc.
G06F21/6227G06F16/24547G06F16/2455G06F16/2462G06F16/2465G06F16/248G06F16/25G06F21/6218G06F21/6245G06F21/6254G06N5/01G06N20/00G06N20/20H04L63/105
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,223,083
App. No.
18/225,573
Granted
Feb 11, 2025
Kind
B2
Abstract

A hardware database privacy device is communicatively coupled to a private database system. The hardware database privacy device receives a request from a client device to perform a query of the private database system and identifies a level of differential privacy corresponding to the request. The identified level of differential privacy includes privacy parameters (ε,δ) indicating the degree of information released about the private database system. The hardware database privacy device identifies a set of operations to be performed on the set of data that corresponds to the requested query. After the set of data is accessed, the set of operations is modified based on the identified level of differential privacy such that a performance of the modified set of operations produces a result set that is (ε,δ)-differentially private.

Claims (278)

1. A system comprising:

a processor configured to execute computer program instructions; and

a non-transitory computer-readable storage medium storing computer program instructions executable by the processor to perform actions comprising:

receiving a database query requesting a differentially private response to the database query;

determining a privacy parameter associated with the database query, the privacy parameter describing a degree of information to release about a set of data stored by the system that is responsive to the database query;

identifying a privacy budget associated with the database query, the privacy budget describing a degree of information available to be released about data by the system;

decrementing the privacy budget by a first spend determined responsive to the database query; and

responsive to the database query, performing the database query by performing a differentially private set of operations on the set of data stored by the system to produce a differentially private result set that releases a certain degree of information about the set of data based on the privacy parameter, each entry in a subset of the set of data being labeled with a category chosen from a set of two or more categories, the differentially private set of operations comprising:

generating an output vector by applying a trained classifier to entries of the subset, each element of the output vector corresponding to a numerical output of the trained classifier for a corresponding entry in the subset;

identifying a threshold value and assigning categories to each element of the output vector based on a perturbed threshold value; and

recording counts related to a performance of the trained classifier, the counts generated by comparing the assigned categories of the elements of the output vector to the corresponding label in the subset.

2. The system of claim 1 , wherein the differentially private set of operations comprises:

identifying a loss function for the set of data, the loss function comprising a function of a set of parameters θ that describes correlations in the set of data; and

minimizing a perturbed loss function over the set of parameters θ, and the differentially private set of operations comprising perturbing the loss function by a factor defined by:

θ

T

υ

(

G

(

4

·

K

2

·

R

2

2

·

(

log

2

δ

+

ϵ

)

ϵ

2

)

)

,

to produce the set of parameters θ that minimizes the perturbed loss function, wherein K and R 2 are constants, ϵ is the first spend, δ is another privacy parameter, and v( ) denotes a vector populated with one or more random variables.

3. The system of claim 1 , wherein the subset of the set of data is a first subset of the set of data, wherein the differentially private set of operations comprises an interquartile range operation on a second subset of the set of data, and wherein the differentially private set of operations comprises perturbing a result of the interquartile range operation by a factor defined by:

(

1

1

+

log

n

)

L

(

c

2

ϵ

3

)

,

to produce the differentially private result set, wherein Lis a zero-centered Laplacian random variable, c 2 and n are constants, and ϵ 2 is a second spend.

4. The system of claim 1 , wherein the subset of the set of data is a first subset of the set of data, and wherein the differentially private set of operations comprises:

identifying a loss function for a second subset of the set of data, the loss function a function of a set of parameters θ describing correlations in the second subset; and

for at least one time step, generating an estimate for the set of parameters θ that minimize the loss function, and wherein the differentially private set of operations comprises for each time step, perturbing the estimate for the set of parameters θ by:

η

t

·

υ

(

G

(

c

1

2

·

n

2

·

(

log

n

δ

+

log

1

δ

)

ϵ

4

)

)

,

to produce the perturbed estimate of the set of parameters θ as the differentially private result set, wherein n t , n, and c 1 are constants, and ϵ 2 is a second spend, G( ) denotes a zero-centered Gaussian random variable and v( ) denotes a vector populated with one or more random variables.

5. The system of claim 1 ,

wherein the differentially private set of operations comprises:

perturbing the threshold value based on a second spend to generate the perturbed threshold value; and

perturbing counts relating to performance of the trained classifier based on the second spend to produce the perturbed counts as the differentially private result set.

6. The system of claim 1 , wherein the differentially private set of operations is performed responsive to determining that the privacy budget accommodates the first spend.

7. The system of claim 1 , wherein the privacy budget is associated with a user of the system.

8. A method comprising:

receiving, by one or more processors, a database query requesting a differentially private response to the database query;

determining, by the one or more processors, a privacy parameter associated with the database query, the privacy parameter describing a degree of information to release about a set of data stored by a database system that is responsive to the database query;

identifying, by the one or more processors, a privacy budget associated with the database query, the privacy budget describing a degree of information available to be released about data by the database system;

decrementing, by the one or more processors, the privacy budget by a first spend determined responsive to the database query; and

responsive to the database query, performing the database query, by the one or more processors, by performing a differentially private set of operations on the set of data stored by the database system to produce a differentially private result set that releases a certain degree of information about the set of data based on the privacy parameter, each entry in a subset of the set of data being labeled with a category chosen from a set of two or more categories, the differentially private set of operations comprising:

generating an output vector by applying a trained classifier to entries of the subset, each element of the output vector corresponding to a numerical output of the trained classifier for a corresponding entry in the subset;

identifying a threshold value and assigning categories to each element of the output vector based on a perturbed threshold value; and

recording counts related to a performance of the trained classifier, the counts generated by comparing the assigned categories of the elements of the output vector to the corresponding label in the subset.

9. The method of claim 8 , wherein the differentially private set of operations comprises:

identifying a loss function for the set of data, the loss function comprising a function of a set of parameters θ that describes correlations in the set of data; and

minimizing a perturbed loss function over the set of parameters θ, and the differentially private set of operations comprising perturbing the loss function by a factor defined by:

θ

T

υ

(

G

(

4

·

K

2

·

R

3

2

·

(

log

1

δ

+

ϵ

)

ϵ

2

)

)

,

to produce the set of parameters θ that minimizes the perturbed loss function, wherein K and R 2 are constants, ϵ is the first spend, δ is another privacy parameter, and v( ) denotes a vector populated with one or more random variables.

10. The method of claim 8 , wherein the subset of the set of data is a first subset of the set of data, wherein the differentially private set of operations comprises an interquartile range operation on a second subset of the set of data, and wherein the differentially private set of operations comprises perturbing a result of the interquartile range operation by a factor defined by:

(

1

1

+

log

n

)

L

(

c

2

ϵ

3

)

,

to produce the differentially private result set, wherein Lis a zero-centered Laplacian random variable, c 2 and n are constants, and ϵ 2 is a second spend.

11. The method of claim 8 , wherein the subset of the set of data is a first subset of the set of data, and wherein the differentially private set of operations comprises:

identifying a loss function for a second subset of the set of data, the loss function a function of a set of parameters θ describing correlations in the second subset; and

for at least one time step, generating an estimate for the set of parameters θ that minimize the loss function, and wherein the differentially private set of operations comprises for each time step, perturbing the estimate for the set of parameters θ by:

η

t

·

υ

(

G

(

c

1

2

·

n

2

·

(

log

n

δ

+

log

1

δ

)

ϵ

4

)

)

,

to produce the perturbed estimate of the set of parameters θ as the differentially private result set, wherein n t , n, and c 1 are constants, and ϵ 2 is a second spend, G( ) denotes a zero-centered Gaussian random variable and v( ) denotes a vector populated with one or more random variables.

12. The method of claim 8 ,

wherein the differentially private set of operations comprises:

perturbing the threshold value based on a second spend to generate the perturbed threshold value; and

perturbing counts relating to performance of the trained classifier based on the second spend to produce the perturbed counts as the differentially private result set.

13. The method of claim 8 , wherein the differentially private set of operations is performed responsive to determining that the privacy budget accommodates the first spend.

14. The method of claim 8 , wherein the privacy budget is associated with a user of the database system.

15. A non-transitory computer-readable storage medium storing computer program instructions executable by a processor to perform actions for implementing differential privacy comprising:

receiving a database query requesting a differentially private response to the database query;

determining a privacy parameter associated with the database query, the privacy parameter describing a degree of information to release about a set of data stored by a database system that is responsive to the database query;

identifying a privacy budget associated with the database query, the privacy budget describing a degree of information available to be released about data by the database system;

decrementing the privacy budget by a first spend determined responsive to the database query; and

responsive to the database query, performing the database query by performing a differentially private set of operations on the set of data stored by the database system to produce a differentially private result set that releases a certain degree of information about the set of data based on the privacy parameter, the differentially private set of operations comprising a median operation on elements associated with a subset of the set of data, each entry in a subset of the set of data being labeled with a category chosen from a set of two or more categories, the differentially private set of operations comprising:

generating an output vector by applying a trained classifier to entries of the subset, each element of the output vector corresponding to a numerical output of the trained classifier for a corresponding entry in the subset;

identifying a threshold value and assigning categories to each element of the output vector based on a perturbed threshold value; and

recording counts related to a performance of the trained classifier, the counts generated by comparing the assigned categories of the elements of the output vector to the corresponding label in the subset.

16. The non-transitory computer-readable storage medium of claim 15 , wherein the differentially private set of operations comprises:

identifying a loss function for the set of data, the loss function comprising a function of a set of parameters θ that describes correlations in the set of data; and

minimizing a perturbed loss function over the set of parameters θ, and the differentially private set of operations comprising perturbing the loss function by a factor defined by:

θ

T

υ

(

G

(

4

·

K

2

·

R

3

2

·

(

log

1

δ

+

ϵ

)

ϵ

2

)

)

,

to produce the set of parameters θ that minimizes the perturbed loss function, wherein K and R 2 are constants, ϵ is the first spend, δ is another privacy parameter, and v( ) denotes a vector populated with one or more random variables.

17. The non-transitory computer-readable storage medium of claim 15 , wherein the subset of the set of data is a first subset of the set of data, wherein the differentially private set of operations comprises an interquartile range operation on a second subset of the set of data, and wherein the differentially private set of operations comprises perturbing a result of the interquartile range operation by a factor defined by:

(

1

1

+

log

n

)

L

(

c

2

ϵ

3

)

,

to produce the differentially private result set, wherein Lis a zero-centered Laplacian random variable, c 2 and n are constants, and ϵ 2 is a second spend.

18. The non-transitory computer-readable storage medium of claim 15 , wherein the differentially private set of operations comprises:

perturbing the threshold value based on a second spend to generate the perturbed threshold value; and

perturbing counts relating to performance of the trained classifier based on the second spend to produce the perturbed counts as the differentially private result set.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 31, 2023
From: NERURKAR, ISHAAN; HOCKENBROCHT, CHRISTOPHER; DAMEWOOD, LIAM; MARUSEAC, MIHAI; ROZENSHTEYN, ALEXANDER
To: LEAPYEAR TECHNOLOGIES, INC.
Reel/Frame 065401/0715 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 31, 2023
From: LEAPYEAR TECHNOLOGIES, INC.
To: SNOWFLAKE INC.
Reel/Frame 065401/0791 →
Continuity (7)
Continuation 17389100 · Jul 29, 2021
Continuation 16810708 · Mar 5, 2020
Continuation 16238439 · Jan 2, 2019
Continuation 15793907 · Oct 25, 2017
Continuation 15203797 · Jul 7, 2016
Provisional Application 62249938 · Nov 2, 2015
Related Publication 20240012928A1 · Jan 11, 2024
References Cited (237)
US 6038563A · Bapat et al. · 2000 [cited by applicant]
US 6438549B1 · Aldred et al. · 2002 [cited by applicant]
US 6546389B1 · Agrawal et al. · 2003 [cited by applicant]
US 6618721B1 · Lee · 2003 [cited by applicant]
US 6823338B1 · Byrne et al. · 2004 [cited by applicant]
US 7219237B1 · Trimberger · 2007 [cited by applicant]
US 7356840B1 · Bedell et al. · 2008 [cited by applicant]
US 7698250B2 · Dwork et al. · 2010 [cited by applicant]
US 7801967B1 · Bedell et al. · 2010 [cited by applicant]
US 9002803B2 · Qayyum et al. · 2015 [cited by applicant]
US 9094378B1 · Yung et al. · 2015 [cited by applicant]
US 9244976B1 · Zhang et al. · 2016 [cited by applicant]
US 9384226B1 · Goel et al. · 2016 [cited by applicant]
US 10192069B2 · Nerurkar et al. · 2019 [cited by applicant]
US 10229287B2 · Nerurkar et al. · 2019 [cited by applicant]
US 10242224B2 · Nerurkar et al. · 2019 [cited by applicant]
US 10467234B2 · Nerurkar et al. · 2019 [cited by applicant]
US 10489605B2 · Nerurkar et al. · 2019 [cited by applicant]
US 10586068B2 · Nerurkar et al. · 2020 [cited by applicant]
US 10642847B1 · Nerurkar et al. · 2020 [cited by applicant]
US 10726153B2 · Nerurkar et al. · 2020 [cited by applicant]
US 10733320B2 · Nerurkar et al. · 2020 [cited by applicant]
US 11055432B2 · Hockenbrocht et al. · 2021 [cited by applicant]
US 11100247B2 · Nerurkar et al. · 2021 [cited by applicant]
US 20010034847A1 · Gaul, Jr. · 2001 [cited by applicant]
US 20030110467A1 · Balakrishnan · 2003 [cited by applicant]
US 20030177118A1 · Moon et al. · 2003 [cited by applicant]
US 20040225896A1 · Ng · 2004 [cited by applicant]
US 20040250120A1 · Ng · 2004 [cited by applicant]
US 20050278786A1 · Tippett et al. · 2005 [cited by applicant]
US 20060053112A1 · Chitkara et al. · 2006 [cited by applicant]
US 20060161527A1 · Dwork et al. · 2006 [cited by applicant]
US 20060200431A1 · Dwork et al. · 2006 [cited by applicant]
US 20060224597A1 · Fitzpatrick et al. · 2006 [cited by applicant]
US 20060238503A1 · Smith et al. · 2006 [cited by applicant]
US 20060265396A1 · Raman et al. · 2006 [cited by applicant]
US 20060282433A1 · Dutta et al. · 2006 [cited by applicant]
US 20070047558A1 · Ayers et al. · 2007 [cited by applicant]
US 20070136027A1 · Dwork et al. · 2007 [cited by applicant]
US 20070143289A1 · Dwork et al. · 2007 [cited by applicant]
US 20070239982A1 · Aggarwal et al. · 2007 [cited by applicant]
US 20080033960A1 · Banks et al. · 2008 [cited by applicant]
US 20080133935A1 · Elovici et al. · 2008 [cited by applicant]
US 20090119298A1 · Faitelson et al. · 2009 [cited by applicant]
US 20090177685A1 · Tanyeri et al. · 2009 [cited by applicant]
US 20090249436A1 · Coles et al. · 2009 [cited by applicant]
US 20090254971A1 · Herz et al. · 2009 [cited by applicant]
US 20090265354A1 · Machak et al. · 2009 [cited by applicant]
US 20090327228A1 · Krause et al. · 2009 [cited by applicant]
US 20110064221A1 · McSherry et al. · 2011 [cited by applicant]
US 20110078143A1 · Aggarwal · 2011 [cited by applicant]
US 20110125730A1 · Bordawekar et al. · 2011 [cited by applicant]
US 20110131222A1 · Dicrescenzo · 2011 [cited by applicant]
US 20110208763A1 · Mcsherry et al. · 2011 [cited by applicant]
US 20110238611A1 · Mcsherry et al. · 2011 [cited by applicant]
US 20110282865A1 · Talwar et al. · 2011 [cited by applicant]
US 20120109830A1 · Vogel · 2012 [cited by applicant]
US 20120143922A1 · Rane et al. · 2012 [cited by applicant]
US 20120166483A1 · Choudhary et al. · 2012 [cited by applicant]
US 20120197864A1 · Bourdoncle et al. · 2012 [cited by applicant]
US 20120226492A1 · Tsuboi et al. · 2012 [cited by applicant]
US 20130031136A1 · Shah · 2013 [cited by applicant]
US 20130145473A1 · Cormode et al. · 2013 [cited by applicant]
US 20130332891A1 · Schmitlin et al. · 2013 [cited by applicant]
US 20140013400A1 · Warshavsky et al. · 2014 [cited by applicant]
US 20140028291A1 · Lee et al. · 2014 [cited by applicant]
US 20140088989A1 · Krishnapuram et al. · 2014 [cited by applicant]
US 20140214735A1 · Harik · 2014 [cited by applicant]
US 20140281572A1 · Wang et al. · 2014 [cited by applicant]
US 20140283091A1 · Zhang et al. · 2014 [cited by applicant]
US 20150235051A1 · Fawaz et al. · 2015 [cited by applicant]
US 20150286827A1 · Fawaz et al. · 2015 [cited by applicant]
US 20150293923A1 · Eide et al. · 2015 [cited by applicant]
US 20160036827A1 · Kling et al. · 2016 [cited by applicant]
US 20160105409A1 · Torman et al. · 2016 [cited by applicant]
US 20160218738A1 · Kim · 2016 [cited by applicant]
US 20160283738A1 · Wang et al. · 2016 [cited by applicant]
US 20160283938A1 · Streuter et al. · 2016 [cited by applicant]
US 20160306709A1 · Shaull · 2016 [cited by applicant]
US 20160335455A1 · Mohan et al. · 2016 [cited by applicant]
US 20170124152A1 · Nerurkar et al. · 2017 [cited by applicant]
US 20170126694A1 · Nerurkar et al. · 2017 [cited by applicant]
US 20170169253A1 · Curcio et al. · 2017 [cited by applicant]
US 20170235974A1 · Zhang et al. · 2017 [cited by applicant]
US 20170316391A1 · Peikert et al. · 2017 [cited by applicant]
US 20170359364A1 · Thakurta et al. · 2017 [cited by applicant]
US 20180039674A1 · Seyvet et al. · 2018 [cited by applicant]
US 20180048653A1 · Nerurkar et al. · 2018 [cited by applicant]
US 20180048654A1 · Nerurkar et al. · 2018 [cited by applicant]
US 20180239924A1 · Rickard, Jr. et al. · 2018 [cited by applicant]
US 20180239925A1 · Nerurkar et al. · 2018 [cited by applicant]
US 20180329952A1 · Ramachandra et al. · 2018 [cited by applicant]
US 20180349384A1 · Nerurkar et al. · 2018 [cited by applicant]
US 20190026489A1 · Nerurkar et al. · 2019 [cited by applicant]
US 20190138743A1 · Nerurkar et al. · 2019 [cited by applicant]
US 20190141052A1 · Nerurkar et al. · 2019 [cited by applicant]
US 20190147188A1 · Benaloh et al. · 2019 [cited by applicant]
US 20190318121A1 · Hockenbrocht et al. · 2019 [cited by applicant]
US 20200210610A1 · Nerurkar et al. · 2020 [cited by applicant]
US 20210357523A1 · Nerurkar et al. · 2021 [cited by applicant]
CA 2998839A1 · 2017 [cited by applicant]
CA 2998839C · 2021 [cited by applicant]
CN 108537055A · 2018 [cited by applicant]
CN 110198302A · 2019 [cited by applicant]
EP 3353734A1 · 2018 [cited by applicant]
WO WO2015090445A1 · 2015 [cited by applicant]
WO WO2015157020A1 · 2015 [cited by applicant]
WO WO2017078808A1 · 2017 [cited by applicant]
WO WO2017187207A1 · 2017 [cited by applicant]
Kasiviswanathan SP, Nissim K, Raskhodnikova S, Smith A. Analyzing graphs with node differential privacy. InTheory of Cryptography: 10th Theory of Cryptography Conference, TCC 2013, Tokyo, Japan, Mar. 3-6, 2013. Proceedi… [cited by examiner]
“U.S. Appl. No. 17/389,100, Non Final Office Action mailed Jan. 24, 2024”, 10 pgs. [cited by applicant]
“U.S. Appl. No. 17/389,100, Response filed Jan. 31, 2024 to Non Final Office Action mailed Jan. 24, 2024”, 14 pgs. [cited by applicant]
“U.S. Appl. No. 17/389,100, Notice of Allowance mailed Mar. 6, 2024”, 8 pgs. [cited by applicant]
Goryczka, S, “A comprehensive comparison of multiparty secure additions with differential privacy”, IEEE transactions on dependable and secure computing, (Oct. 1, 2015), 463-77. [cited by applicant]
Li, C, “Optimizing linear counting queries under differential privacy”, In Proceedings of the twenty-ninth ACM SIGMOD-SIGACT-SIGART symposium on Principles of database systems, (Jun. 6, 2010), 123-134. [cited by applicant]
Rastogi, Vibhor, “Differentially Private Aggregation of Distributed Time Series with Transformation and Encryption”, SIGMOD 2010, (Jun. 6-11, 2010), 25 pages. [cited by applicant]
“U.S. Appl. No. 15/166,035, Non Final Office Action mailed May 10, 2018”, 18 pgs. [cited by applicant]
“U.S. Appl. No. 15/203,797, Examiner Interview Summary mailed Mar. 26, 2018”, 3 pgs. [cited by applicant]
“U.S. Appl. No. 15/203,797, Final Office Action mailed Jun. 8, 2018”, 13 pgs. [cited by applicant]
“U.S. Appl. No. 15/203,797, Non Final Office Action mailed Jan. 17, 2018”, 13 pgs. [cited by applicant]
“U.S. Appl. No. 15/203,797, Notice of Allowance mailed Sep. 11, 2018”, 8 pgs. [cited by applicant]
“U.S. Appl. No. 15/203,797, Response filed Apr. 6, 2018 to Non Final Office Action mailed Jan. 17, 2018”, 19 pgs. [cited by applicant]
“U.S. Appl. No. 15/793,898, Examiner Interview Summary mailed Feb. 27, 2018”, 2 pgs. [cited by applicant]
“U.S. Appl. No. 15/793,898, Examiner Interview Summary mailed Jun. 18, 2018”, 3 pgs. [cited by applicant]
“U.S. Appl. No. 15/793,898, Final Office Action mailed May 15, 2018”, 14 pgs. [cited by applicant]
“U.S. Appl. No. 15/793,898, Non Final Office Action mailed Feb. 7, 2018”, 11 pgs. [cited by applicant]
“U.S. Appl. No. 15/793,898, Notice of Allowance mailed Nov. 20, 2018”, 12 pgs. [cited by applicant]
“U.S. Appl. No. 15/793,898, Response filed Apr. 6, 2018 to Non Final Office Action mailed Feb. 7, 2018”, 18 pgs. [cited by applicant]
“U.S. Appl. No. 15/793,898, Response filed Jul. 10, 2018 to Final Office Action mailed May 15, 2018”, 12 pgs. [cited by applicant]
“U.S. Appl. No. 15/793,907, Examiner Interview Summary mailed Feb. 27, 2018”, 2 pgs. [cited by applicant]
“U.S. Appl. No. 15/793,907, Examiner Interview Summary mailed Jun. 18, 2018”, 3 pgs. [cited by applicant]
“U.S. Appl. No. 15/793,907, Final Office Action mailed May 15, 2018”, 14 pgs. [cited by applicant]
“U.S. Appl. No. 15/793,907, Non Final Office Action mailed Jan. 31, 2018”, 11 pgs. [cited by applicant]
“U.S. Appl. No. 15/793,907, Notice of Allowance mailed Oct. 26, 2018”, 11 pgs. [cited by applicant]
“U.S. Appl. No. 15/793,907, Response filed Apr. 6, 2018 to Non Final Office Action mailed Jan. 31, 2018”, 17 pgs. [cited by applicant]
“U.S. Appl. No. 15/793,907, Response filed Jul. 10, 2018 to Final Office Action mailed May 15, 2018”, 11 pgs. [cited by applicant]
“U.S. Appl. No. 15/960,486, Non Final Office Action mailed May 10, 2019”, 9 pgs. [cited by applicant]
“U.S. Appl. No. 15/960,486, Notice of Allowance mailed Aug. 28, 2019”, 9 pgs. [cited by applicant]
“U.S. Appl. No. 15/960,486, Response filed Jul. 18, 2019 to Non Final Office Action mailed May 10, 2019”, 11 pgs. [cited by applicant]
“U.S. Appl. No. 16/040,478, Notice of Allowance mailed Aug. 6, 2019”, 11 pgs. [cited by applicant]
“U.S. Appl. No. 16/144,790, Non Final Office Action mailed Oct. 17, 2019”, 12 pgs. [cited by applicant]
“U.S. Appl. No. 16/144,790, Notice of Allowance mailed Mar. 25, 2020”, 10 pgs. [cited by applicant]
“U.S. Appl. No. 16/144,790, Response filed Feb. 12, 2020 to Non Final Office Action mailed Oct. 17, 2019”, 16 pgs. [cited by applicant]
“U.S. Appl. No. 16/238,437, Corrected Notice of Allowability mailed Jan. 28, 2020”. [cited by applicant]
“U.S. Appl. No. 16/238,437, Non Final Office Action mailed Oct. 31, 2019”, 13 pgs. [cited by applicant]
“U.S. Appl. No. 16/238,437, Notice of Allowability mailed Dec. 30, 2019”, 9 pgs. [cited by applicant]
“U.S. Appl. No. 16/238,437, Response filed Nov. 21, 2019 to Non Final Office Action mailed Oct. 31, 2019”, 12 pgs. [cited by applicant]
“U.S. Appl. No. 16/238,439, Corrected Notice of Allowability mailed Jun. 26, 2020”, 2 pgs. [cited by applicant]
“U.S. Appl. No. 16/238,439, Non Final Office Action mailed Oct. 28, 2019”, 15 pgs. [cited by applicant]
“U.S. Appl. No. 16/238,439, Notice of Allowance mailed Apr. 10, 2020”, 9 pgs. [cited by applicant]
“U.S. Appl. No. 16/238,439, Response filed Feb. 27, 2020 to Non Final Office Action mailed Oct. 28, 2019”, 12 pgs. [cited by applicant]
“U.S. Appl. No. 16/810,708, Non Final Office Action mailed Nov. 10, 2020”, 18 pgs. [cited by applicant]
“U.S. Appl. No. 16/810,708, Notice of Allowance mailed Apr. 20, 2021”, 10 pgs. [cited by applicant]
“U.S. Appl. No. 16/810,708, Response filed Mar. 9, 2021 to Non Final Office Action mailed Nov. 10, 2020”, 14 pgs. [cited by applicant]
“U.S. Appl. No. 17/389,100, 312 Amendment filed Jul. 24, 2023”, 1 pgs. [cited by applicant]
“U.S. Appl. No. 17/389,100, Non Final Office Action mailed Nov. 23, 2022”, 8 pgs. [cited by applicant]
“U.S. Appl. No. 17/389,100, Notice of Allowance mailed Apr. 26, 2023”, 8 pgs. [cited by applicant]
“U.S. Appl. No. 17/389,100, PTO Response to Rule 312 Communication mailed Aug. 14, 2023”, 2 pgs. [cited by applicant]
“U.S. Appl. No. 17/389,100, Response filed Mar. 22, 2023 to Non Final Office Action mailed Nov. 23, 2022”, 14 pgs. [cited by applicant]
“U.S. Appl. No. 17/389,100, Supplemental Notice of Allowability mailed Jun. 22, 2023”, 2 pgs. [cited by applicant]
“Canadian Application Serial No. 2,998,839, Office Action mailed Jan. 7, 2020”, 3 pgs. [cited by applicant]
“Canadian Application Serial No. 2,998,839, Office Action mailed Feb. 12, 2019”, 3 pgs. [cited by applicant]
“Canadian Application Serial No. 2,998,839, Response filed May 5, 2020 to Office Action mailed Jan. 7, 2020”, 16 pgs. [cited by applicant]
“Canadian Application Serial No. 2,998,839, Response filed Aug. 7, 2019 to Office Action mailed Feb. 12, 2019”, 17 pgs. [cited by applicant]
“European Application Serial No. 16862625.7, Amendment filed Sep. 16, 2022”, 48 pgs. [cited by applicant]
“European Application Serial No. 16862625.7, Communication Pursuant to Article 94(3) EPC mailed May 4, 2020”, 9 pgs. [cited by applicant]
“European Application Serial No. 16862625.7, decision to refuse mailed May 11, 2022”, 18 pgs. [cited by applicant]
“European Application Serial No. 16862625.7, Extended European Search Report mailed Mar. 27, 2019”, 9 pgs. [cited by applicant]
“European Application Serial No. 16862625.7, Office Action mailed Oct. 24, 2022”, 2 pgs. [cited by applicant]
“European Application Serial No. 16862625.7, Response filed Feb. 25, 2022 to Summons to attend oral proceedings mailed Oct. 22, 2021”, 22 pgs. [cited by applicant]
“European Application Serial No. 16862625.7, Response filed Aug. 22, 2019 to Extended European Search Report mailed Mar. 27, 2019”, 12 pgs. [cited by applicant]
“European Application Serial No. 16862625.7, Response filed Oct. 30, 2020 to Communication Pursuant to Article 94(3) EPC mailed May 4, 2020”, 9 pgs. [cited by applicant]
“European Application Serial No. 16862625.7, Response to Communication pursuant to Rules 161 and 162 EPC filed Oct. 29, 2018”, 8 pgs. [cited by applicant]
“European Application Serial No. 16862625.7, Summons to attend oral proceedings mailed Oct. 22, 2021”, 9 pgs. [cited by applicant]
“European Application Serial No. 19785548.9, Extended European Search Report mailed Dec. 10, 2021”, 10 pgs. [cited by applicant]
“European Application Serial No. 19889515.3, Extended European Search Report mailed Jun. 24, 2022”, 6 pgs. [cited by applicant]
“European Application Serial No. 20153847.7, Extended European Search Report mailed Apr. 30, 2020”, 11 pgs. [cited by applicant]
“European Application Serial No. 20173244.3, Extended European Search Report mailed Sep. 14, 2020”, 11 pgs. [cited by applicant]
“International Application Serial No. PCT/US2016/044178, International Preliminary Report on Patentability mailed May 17, 2018”, 9 pgs. [cited by applicant]
“International Application Serial No. PCT/US2016/044178, International Search Report mailed Oct. 18, 2016”, 3 pgs. [cited by applicant]
“International Application Serial No. PCT/US2016/044178, Written Opinion mailed Oct. 18, 2016”, 7 pgs. [cited by applicant]
“International Application Serial No. PCT/US2019/015035, International Search Report mailed Jun. 20, 2019”, 2 pgs. [cited by applicant]
“International Application Serial No. PCT/US2019/015035, Written Opinion mailed Jun. 20, 2019”, 3 pgs. [cited by applicant]
Agrawal, R., et al., “Privacy-Preserving Data Mining”, ACM SIGMOD, (May 2000), pp. 439-450. [cited by applicant]
Amirbekyan, A., et al., “Privacy-Preserving Regression Algorithms”, Proceedings of the 7th WSEAS International Conference on Simulation, Modeling, and Optimization, (2007), 37-45. [cited by applicant]
Beigi, G, et al., “Privacy in Social Media: Identification, Mitigation and Applications”, ACM Trans. Web, vol. 9, No. 4, Article 39, (Jul. 2018), 1-36. [cited by applicant]
Bost, R., et al., “Machine Learning Classification over Encrypted Data”, NDSS '15, (Feb. 8-11, 2015), 1-14. [cited by applicant]
Chaudhuri, K., et al., “Privacy-preserving logistic regression”, Advances in Neural Information Processing Systems, (2009), 8 pages. [cited by applicant]
Chaudhuri, S., et al., “Database Access Control & Privacy: Is There a Common Ground?”, CIDR 2011: Fifth C1 Biennial Conference on Innovative Data Systems Research, [Online]. Retrieved from the Internet: <URL: https://ww… [cited by applicant]
Cock, M. D, et al., “Fast, Privacy Preserving Linear Regression over Distributed Datasets based on Pre-Distributed Data”, Proceedings of the 8th ACM Workshop on Artificial Intelligence and Security, (2015), 3-14. [cited by applicant]
Dankar, Fidak, et al., “Practicing Differential Privacy in Health Care: A Review”, Transactions on Data Privacy 5, [Online]. Retrieved from the Internet: <URL: http://www.tdp.cat/issues11/tdp.a129a13.pdf>, (2013), 35-67. [cited by applicant]
Du, Wenliang, et al., “Privacy-Preserving Multivariate Statistical Analysis: Linear Regression and Classification”, Electrical Engineering and Computer Science. Paper 12, Proceedings of the 2004 SIAM International Confe… [cited by applicant]
Dwork, C., et al., “A Firm Foundation for Private Data Analysis”, Proceedings of the ACM, vol. 54, Issue 1, (Jan. 2011), 8 pages. [cited by applicant]
Dwork, C., et al., “Calibrating noise to sensitivity in private data analysis”, In Proceedings of the Third Conference on Theory of Cryptography, ser. TCC'06. Berlin, Heidelberg: Springer-Verlag, [Online] Retrieved from… [cited by applicant]
Dwork, C., et al., “Differential Privacy and Robust Statistics”, Proceedings of the Forty-First Annual ACM Symposium on Theory of Computing, [Online] Retrieved from the internet: <http://www.stat.cmu.edu/˜jingle/dprs_st… [cited by applicant]
Dwork, Cynthia, et al., “Differential Privacy: A Survey of Results”, TAMC, LNCS 4978, Agrawal, M. et al., (eds.), (2008), 1-19. [cited by applicant]
Fang, W., et al., “Privacy preserving linear regression modeling of distributed databases”, Optimization Letters, vol. 7, (2013), pp. 807-818. [cited by applicant]
Fletcher, S, et al., “A Differentially Private Decision Forest”, Proceedings of the 13th Australasian Data Mining Conference (AusDM), Sydney, Australia, vol. 168, (2015), 99-108. [cited by applicant]
Frades, M R, “Overview on Techniques in Cluster Analysis”, Bioinformatics in Clinical Research, Methods in Molecular Biology (Methods and Protocols), vol. 593, (2010), pp. 81-107. [cited by applicant]
Fraley, C., et al., “How Many Clusters? Which Clustering Method? Answers Via Model-Based Cluster Analysis”, The Computer Journal, vol. 41, No. 8, (1998), 578-588. [cited by applicant]
Friedman, A., et al., “Data Mining with Differential Privacy”, Proceedings of the 16th ACM SIGKDD International Conference on Knowledge Discovery and Data Mining, [Online] Retrieved from the internet: <http://users.cis.… [cited by applicant]
Gaboardi, M., “PSI: a Private data Sharing Interface”, (Aug. 4, 2018), 1-35. [cited by applicant]
Geumlek, J, et al., “Renyi Differential Privacy Mechanisms for Posterior Sampling”, NIPS 2017: Advances in Neural Information Processing Systems 30, (Oct. 2, 2017), 1-34. [cited by applicant]
Han, S., et al., “Privacy-Preserving Gradient-Descent Methods”, IEEE Transactions on Knowledge and Data Engineering, 22(6), (Jun. 29, 2009), pp. 884-899. [cited by applicant]
Huang, Yiqing, et al., “Telco Churn Prediction with Big Data”, Proceedings of the 2015 Acm Sigmod International Conference on Management of Data, [Online] Retrieved from the internet: <http://users.WPI.edu/˜yli15/Includ… [cited by applicant]
Jagannathan, G., et al., “A Practical Differentially Private Random Decision Tree Classifier”, International Conference on Data Mining Workshops, Proceedings of the ICDM International Workshop on the Privacy Aspects of … [cited by applicant]
Jayaraman, B., et al., “Evaluating Differentially Private Machine Learning in Practice”, 28th USENIX Security Symposium, (Feb. 2019), 1-18. [cited by applicant]
Ji, Z., et al., “Differential Privacy and Machine Learning: a Survey and Review”, Cornell University Library—arXiv preprint, [Online] Retrieved from the internet: <http://arxiv.org/pdf/1412.7584.pdf>, (Dec. 24, 2014), 3… [cited by applicant]
Kellaris, G, et al., “Practical differential privacy via grouping and smoothing”, Proceedings of the VLDB Endowment vol. 6, No. 5, (Mar. 1, 2013), 301-312. [cited by applicant]
Koufogiannis, F., et al., “Gradual Release of Sensitive Data under Differential Privacy”, Cornel University, CrvDtoaraDhv and Security,, (Oct. 15, 2018), 1-22. [cited by applicant]
Liu, H, et al., “Privacy-Presenting Monotonicity of Differential Privacy Mechanisms”, Applied Sciences, vol. 8,No. 11, (Oct. 28, 2018), 1-32. [cited by applicant]
Metoui, N., et al., “Differential Privacy Based Access Control”, OTM 2016: On the Move to Meaningful Internet Systems, (Oct. 18, 2016), 962-974. [cited by applicant]
Mironov, I., “Renyi Differential Privacy”, (2017), 1-13. [cited by applicant]
Nissim, K., et al., “Smooth Sensitivity and Sampling in Private Data Analysis”, Proceedings of the Thirty-Ninth Annual ACM Symposium on Theory of Computing, [Online]. Retrieved from the Internet: <http://www.cse.psu.edu… [cited by applicant]
Patil, A., et al., “Differential Private Random Forest”, International Conference on Advances in Computing, Communications and Informatics, [Online] Retrieved from the internet: <http://ieeexplore.ieee.org/stamp/stamp.j… [cited by applicant]
Peng, S., et al., “Query Optimization for Differentially Private Data Management Systems”, ICDE Conference, (2013), pp. 1093-1104. [cited by applicant]
Sanil, Ashish P, et al., “Privacy Preserving Regression Modelling Via Distributed Computation”, Proceedings of the Tenth ACM SIGKDD International Conference on Knowledge Discovery and Data Mining, (2004), 677-682. [cited by applicant]
Saranya, R., et al., “Precision-Constrained Privacy Preserving Role-Based Access Control”, International Journal of Emerging Technology in Computer Science & Electronics, vol. 13, No. 1, (Mar. 2015), pp. 405-408. [cited by applicant]
Shang, S, et al., “The Application of Differential Privacy for Rank Aggregation: Privacy and Accuracy”, 17th International Conference on Information Fusion, (Jul. 7, 2014), 1-7. [cited by applicant]
Xiao, X., et al., “Differential privacy via wavelet transforms”, IEEE Transactions on Knowledge and Data Engineering, vol. 23, No. 8, (Aug. 2011), pp. 1200-1214. [cited by applicant]
Xiao, X., et al., “iReduct: Differential Privacy with Reduced Relative Errors”, SIGMOD' 11, (Jun. 12-16, 2011), 229-240. [cited by applicant]
Xu, J., et al., “Differentially Private Histogram Publication”, IEEE 28th International Conference on Data Engineering, (Apr. 2012), 32-43. [cited by applicant]
Zhang, J., et al., “Functional Mechanism: Regression Analysis under Differential Privacy”, Proceedings of the VLDB Endowment, vol. 5, No. 11, (2012), pp. 1364-1375. [cited by applicant]
Zhang, N., et al., “Distributed Data Mining with Differential Privacy”, IEEE ICC proceedings, (2011), 5 pages. [cited by applicant]
U.S. Appl. No. 15/203,797 U.S. Pat. No. 10,192,069, filed Jul. 7, 2016, Differentially Private Processing and Database Storage. [cited by applicant]
U.S. Appl. No. 15/793,907 U.S. Pat. No. 10,229,287, filed Oct. 25, 2017, Differentially Private Processing and Database Storage. [cited by applicant]
U.S. Appl. No. 16/238,439 U.S. Pat. No. 10,733,320, filed Jan. 2, 2019, Differentially Private Processing and Database Storage. [cited by applicant]
U.S. Appl. No. 16/810,708 U.S. Pat. No. 11,100,247, filed Mar. 5, 2020, Differentially Private Processing and Database Storage. [cited by applicant]
U.S. Appl. No. 17/389,100 U.S. Pat. No. 11,775,671 filed Jul. 29, 2021, Differentially Private Processing and Database Storage. [cited by applicant]
U.S. Appl. No. 15/793,898 U.S. Pat. No. 10,242,224, filed Oct. 25, 2017, Differentially Private Processing and Database Storage. [cited by applicant]
U.S. Appl. No. 15/166,035, filed May 26, 2016, , Differentially Private Processing and Database Storage. [cited by applicant]
U.S. Appl. No. 15/960,486 U.S. Pat. No. 10,489,605, filed Apr. 23, 2018, Differentially Private Density Plots. [cited by applicant]
U.S. Appl. No. 16/040,478 U.S. Pat. No. 10,467,234, filed Jul. 19, 2018, Differentially Private Database Queries Involving Rank Statistics. [cited by applicant]
U.S. Appl. No. 16/144,790 U.S. Pat. No. 10,726,153, filed Sep. 27, 2018, Differentially Private Machine Learning Using a Random Forest Classifier. [cited by applicant]
U.S. Appl. No. 16/238,437 U.S. Pat. No. 10,586,068, filed Jan. 2, 2019, Differentially Private Processing and Database Storage. [cited by applicant]
“U.S. Appl. No. 17/389,100, Corrected Notice of Allowability mailed Jul. 9, 2024”, 2 pgs. [cited by applicant]
“European Application Serial No. 16862625.7, Summons to Attend Oral Proceedings mailed May 23, 2024”, 6 pgs. [cited by applicant]