# Further Reading

Differential privacy has grown into a mature, interdisciplinary field spanning theory, systems, and practice. This chapter highlights foundational papers, influential systems, and active areas of research for readers who want to go the extra mile!

## Foundations of Differential Privacy

- The original definition of differential privacy and early mechanisms:
  - Dwork et al. (2006): *Calibrating Noise to Sensitivity in Private Data Analysis* {cite}`dwork2006B`
  - Dwork (2008): *Differential Privacy: A Survey of Results* {cite}`dwork2008survey`


## Practical Systems and Implementations

- Production-grade DP systems:
  - Google’s [RAPPOR](https://research.google/pubs/pub42852/) and Apple’s [Differential Privacy Deployment](https://www.apple.com/privacy/docs/Differential_Privacy_Overview.pdf)

- Libraries and frameworks:
  - [Opacus](https://opacus.ai/) for DP in PyTorch
  - [TensorFlow Privacy](https://github.com/tensorflow/privacy)

## Machine Learning with Differential Privacy

- DP-SGD and modern private ML:
  - Abadi et al. (2016): *Deep Learning with Differential Privacy* {cite}`abadi2016deep`
  - Bu et al. (2022): *Deep Learning with Gaussian Differential Privacy* {cite}`bu2022deep`

- Privacy attacks and auditing:
  - Shokri et al. (2017): *Membership Inference Attacks* {cite}`shokri2017membership`
  - Carlini et al. (2019): *Secret Sharer: Evaluating and Testing Unintended Memorization* {cite}`carlini2019secret`

## Experimental Design and Statistics

- DP for statistical estimation:
  - Smith (2011): *Privacy-Preserving Statistical Estimation with Optimal Convergence Rates* {cite}`smith2011privacyestimation`
  - Karwa and Slavkovic (2016): *Inference in Contingency Tables under Differential Privacy* {cite}`karwa2016noisydegrees`

- Private hypothesis testing:
  - Sheffet (2017): *Differentially Private Ordinary Least Squares* {cite}`sheffet2017dpols`

## Advanced Topics

- Local differential privacy:
  - Kasiviswanathan et al. (2011): *What Can We Learn Privately?* {cite}`kasiviswanathan2011learnprivately`
  - Erlingsson et al. (2014): *RAPPOR: Privacy-Preserving Reporting System* {cite}`rappor`

- Composition and privacy accounting:
  - Mironov (2017): *Rényi Differential Privacy* {cite}`mironov2017renyi`
  - Kairouz et al. (2015): *The Composition Theorem in Differential Privacy* {cite}`kairouz2015composition`

- Verification and formal reasoning:
  - Reed, Jason and Pierce, Benjamin C. (2010): *Distance makes the types grow stronger: a calculus for differential privacy* {cite}`pierce2010distance`
  - Abuah et al. (2022): *Solo: a lightweight static analysis for differential privacy* {cite}`abuah2022solo`

## Applications and Policy

- Use in government and public policy:
  - U.S. Census Bureau (2020): *Disclosure Avoidance System for the 2020 Census* {cite}`uscensus2021das` {cite}`abowd2022topdown`

## Survey and Future Directions

- Ullman (2020): *Privacy and Data Analysis: A Research Overview* {cite}`ullman2020overview`






## References 

In the web/html version of the book, the bibliography will appear *directly below this current text section*.

However in the print versions which are based on $\text{\LaTeX}$, the bibliography will appear (more traditionally) as the penultimate un-numbered standalone chapter which precedes the Proof Index.

```{bibliography}
:style: unsrt
```
