summaryrefslogtreecommitdiff
path: root/ACSAC
diff options
context:
space:
mode:
Diffstat (limited to 'ACSAC')
-rw-r--r--ACSAC/figures/advdebias/census/census_advdeb_attack_hard_race.pdfbin0 -> 49861 bytes
-rw-r--r--ACSAC/figures/advdebias/census/census_advdeb_attack_hard_sex.pdfbin0 -> 49905 bytes
-rw-r--r--ACSAC/figures/advdebias/census/census_advdeb_attack_soft_experimental_race.pdfbin0 -> 49835 bytes
-rw-r--r--ACSAC/figures/advdebias/census/census_advdeb_attack_soft_experimental_sex.pdfbin0 -> 49873 bytes
-rw-r--r--ACSAC/figures/advdebias/census/census_advdeb_dp_lvl_race.pdfbin0 -> 49676 bytes
-rw-r--r--ACSAC/figures/advdebias/census/census_advdeb_dp_lvl_sex.pdfbin0 -> 49684 bytes
-rw-r--r--ACSAC/figures/advdebias/census/census_advdeb_utility.pdfbin0 -> 49785 bytes
-rw-r--r--ACSAC/figures/advdebias/census/old_format/census_advdeb_attack_hard_race.pdfbin0 -> 49936 bytes
-rw-r--r--ACSAC/figures/advdebias/census/old_format/census_advdeb_attack_hard_sex.pdfbin0 -> 49981 bytes
-rw-r--r--ACSAC/figures/advdebias/census/old_format/census_advdeb_attack_soft_experimental_race.pdfbin0 -> 49880 bytes
-rw-r--r--ACSAC/figures/advdebias/census/old_format/census_advdeb_attack_soft_experimental_sex.pdfbin0 -> 49887 bytes
-rw-r--r--ACSAC/figures/advdebias/census/old_format/census_advdeb_dp_lvl_race.pdfbin0 -> 49704 bytes
-rw-r--r--ACSAC/figures/advdebias/census/old_format/census_advdeb_dp_lvl_sex.pdfbin0 -> 49714 bytes
-rw-r--r--ACSAC/figures/advdebias/census/old_format/census_advdeb_utility.pdfbin0 -> 49812 bytes
-rw-r--r--ACSAC/figures/advdebias/compas/compas_advdeb_attack_hard_race.pdfbin0 -> 49474 bytes
-rw-r--r--ACSAC/figures/advdebias/compas/compas_advdeb_attack_hard_sex.pdfbin0 -> 50376 bytes
-rw-r--r--ACSAC/figures/advdebias/compas/compas_advdeb_attack_soft_experimental_race.pdfbin0 -> 50182 bytes
-rw-r--r--ACSAC/figures/advdebias/compas/compas_advdeb_attack_soft_experimental_sex.pdfbin0 -> 49453 bytes
-rw-r--r--ACSAC/figures/advdebias/compas/compas_advdeb_dp_lvl_race.pdfbin0 -> 49450 bytes
-rw-r--r--ACSAC/figures/advdebias/compas/compas_advdeb_dp_lvl_sex.pdfbin0 -> 50029 bytes
-rw-r--r--ACSAC/figures/advdebias/compas/compas_advdeb_utility.pdfbin0 -> 49807 bytes
-rw-r--r--ACSAC/figures/advdebias/compas/old_format/compas_advdeb_attack_hard_race.pdfbin0 -> 49554 bytes
-rw-r--r--ACSAC/figures/advdebias/compas/old_format/compas_advdeb_attack_hard_sex.pdfbin0 -> 50452 bytes
-rw-r--r--ACSAC/figures/advdebias/compas/old_format/compas_advdeb_attack_soft_experimental_race.pdfbin0 -> 49896 bytes
-rw-r--r--ACSAC/figures/advdebias/compas/old_format/compas_advdeb_attack_soft_experimental_sex.pdfbin0 -> 49867 bytes
-rw-r--r--ACSAC/figures/advdebias/compas/old_format/compas_advdeb_dp_lvl_race.pdfbin0 -> 49483 bytes
-rw-r--r--ACSAC/figures/advdebias/compas/old_format/compas_advdeb_dp_lvl_sex.pdfbin0 -> 50059 bytes
-rw-r--r--ACSAC/figures/advdebias/compas/old_format/compas_advdeb_utility.pdfbin0 -> 49838 bytes
-rw-r--r--ACSAC/figures/advdebias/lfw/lfw_advdeb_attack_hard_race.pdfbin0 -> 49759 bytes
-rw-r--r--ACSAC/figures/advdebias/lfw/lfw_advdeb_attack_hard_sex.pdfbin0 -> 50237 bytes
-rw-r--r--ACSAC/figures/advdebias/lfw/lfw_advdeb_attack_soft_experimental_race.pdfbin0 -> 49837 bytes
-rw-r--r--ACSAC/figures/advdebias/lfw/lfw_advdeb_attack_soft_experimental_sex.pdfbin0 -> 49879 bytes
-rw-r--r--ACSAC/figures/advdebias/lfw/lfw_advdeb_dp_lvl_race.pdfbin0 -> 49664 bytes
-rw-r--r--ACSAC/figures/advdebias/lfw/lfw_advdeb_dp_lvl_sex.pdfbin0 -> 49872 bytes
-rw-r--r--ACSAC/figures/advdebias/lfw/lfw_advdeb_utility.pdfbin0 -> 49999 bytes
-rw-r--r--ACSAC/figures/advdebias/lfw/old_format/lfw_advdeb_attack_hard_race.pdfbin0 -> 49835 bytes
-rw-r--r--ACSAC/figures/advdebias/lfw/old_format/lfw_advdeb_attack_hard_sex.pdfbin0 -> 50310 bytes
-rw-r--r--ACSAC/figures/advdebias/lfw/old_format/lfw_advdeb_attack_soft_experimental_race.pdfbin0 -> 50043 bytes
-rw-r--r--ACSAC/figures/advdebias/lfw/old_format/lfw_advdeb_attack_soft_experimental_sex.pdfbin0 -> 49909 bytes
-rw-r--r--ACSAC/figures/advdebias/lfw/old_format/lfw_advdeb_dp_lvl_race.pdfbin0 -> 49695 bytes
-rw-r--r--ACSAC/figures/advdebias/lfw/old_format/lfw_advdeb_dp_lvl_sex.pdfbin0 -> 49902 bytes
-rw-r--r--ACSAC/figures/advdebias/lfw/old_format/lfw_advdeb_utility.pdfbin0 -> 50023 bytes
-rw-r--r--ACSAC/figures/advdebias/meps/meps_advdeb_attack_hard_race.pdfbin0 -> 49881 bytes
-rw-r--r--ACSAC/figures/advdebias/meps/meps_advdeb_attack_hard_sex.pdfbin0 -> 50088 bytes
-rw-r--r--ACSAC/figures/advdebias/meps/meps_advdeb_attack_soft_experimental_race.pdfbin0 -> 49860 bytes
-rw-r--r--ACSAC/figures/advdebias/meps/meps_advdeb_attack_soft_experimental_sex.pdfbin0 -> 49673 bytes
-rw-r--r--ACSAC/figures/advdebias/meps/meps_advdeb_dp_lvl_race.pdfbin0 -> 49694 bytes
-rw-r--r--ACSAC/figures/advdebias/meps/meps_advdeb_dp_lvl_sex.pdfbin0 -> 50020 bytes
-rw-r--r--ACSAC/figures/advdebias/meps/meps_advdeb_utility.pdfbin0 -> 49453 bytes
-rw-r--r--ACSAC/figures/advdebias/meps/old_format/meps_advdeb_attack_hard_race.pdfbin0 -> 49958 bytes
-rw-r--r--ACSAC/figures/advdebias/meps/old_format/meps_advdeb_attack_hard_sex.pdfbin0 -> 50163 bytes
-rw-r--r--ACSAC/figures/advdebias/meps/old_format/meps_advdeb_attack_soft_experimental_race.pdfbin0 -> 49839 bytes
-rw-r--r--ACSAC/figures/advdebias/meps/old_format/meps_advdeb_attack_soft_experimental_sex.pdfbin0 -> 49720 bytes
-rw-r--r--ACSAC/figures/advdebias/meps/old_format/meps_advdeb_dp_lvl_race.pdfbin0 -> 49721 bytes
-rw-r--r--ACSAC/figures/advdebias/meps/old_format/meps_advdeb_dp_lvl_sex.pdfbin0 -> 50046 bytes
-rw-r--r--ACSAC/figures/advdebias/meps/old_format/meps_advdeb_utility.pdfbin0 -> 49482 bytes
-rw-r--r--ACSAC/figures/after.pdfbin0 -> 35687 bytes
-rw-r--r--ACSAC/figures/before.pdfbin0 -> 35441 bytes
-rw-r--r--ACSAC/figures/distribution_attack_impact/debiasing.pdfbin0 -> 118324 bytes
-rw-r--r--ACSAC/figures/distribution_attack_impact/egd.pdfbin0 -> 117296 bytes
-rw-r--r--ACSAC/figures/distribution_attack_impact/res.pdfbin0 -> 118319 bytes
-rw-r--r--ACSAC/figures/distributions/LAW_dist.pdfbin0 -> 33470 bytes
-rw-r--r--ACSAC/figures/distributions/LFW_dist.pdfbin0 -> 34773 bytes
-rw-r--r--ACSAC/figures/distributions/census_dist.pdfbin0 -> 35274 bytes
-rw-r--r--ACSAC/figures/distributions/compas_dist.pdfbin0 -> 30021 bytes
-rw-r--r--ACSAC/figures/distributions/credit_dist.pdfbin0 -> 34271 bytes
-rw-r--r--ACSAC/figures/distributions/meps_dist.pdfbin0 -> 30179 bytes
-rw-r--r--ACSAC/figures/egd/census/census_egd_attack_hard_race.pdfbin0 -> 49512 bytes
-rw-r--r--ACSAC/figures/egd/census/census_egd_attack_hard_sex.pdfbin0 -> 50367 bytes
-rw-r--r--ACSAC/figures/egd/census/census_egd_dp_lvl_race.pdfbin0 -> 49485 bytes
-rw-r--r--ACSAC/figures/egd/census/census_egd_dp_lvl_sex.pdfbin0 -> 50055 bytes
-rw-r--r--ACSAC/figures/egd/census/census_egd_utility.pdfbin0 -> 49472 bytes
-rw-r--r--ACSAC/figures/egd/census/old_format/census_egd_attack_hard_race.pdfbin0 -> 49593 bytes
-rw-r--r--ACSAC/figures/egd/census/old_format/census_egd_attack_hard_sex.pdfbin0 -> 50444 bytes
-rw-r--r--ACSAC/figures/egd/census/old_format/census_egd_dp_lvl_race.pdfbin0 -> 49535 bytes
-rw-r--r--ACSAC/figures/egd/census/old_format/census_egd_dp_lvl_sex.pdfbin0 -> 50105 bytes
-rw-r--r--ACSAC/figures/egd/census/old_format/census_egd_utility.pdfbin0 -> 49522 bytes
-rw-r--r--ACSAC/figures/egd/compas/compas_egd_attack_hard_race.pdfbin0 -> 50036 bytes
-rw-r--r--ACSAC/figures/egd/compas/compas_egd_attack_hard_sex.pdfbin0 -> 49856 bytes
-rw-r--r--ACSAC/figures/egd/compas/compas_egd_dp_lvl_race.pdfbin0 -> 49707 bytes
-rw-r--r--ACSAC/figures/egd/compas/compas_egd_dp_lvl_sex.pdfbin0 -> 49889 bytes
-rw-r--r--ACSAC/figures/egd/compas/compas_egd_utility.pdfbin0 -> 49843 bytes
-rw-r--r--ACSAC/figures/egd/compas/old_format/compas_egd_attack_hard_race.pdfbin0 -> 50112 bytes
-rw-r--r--ACSAC/figures/egd/compas/old_format/compas_egd_attack_hard_sex.pdfbin0 -> 49936 bytes
-rw-r--r--ACSAC/figures/egd/compas/old_format/compas_egd_dp_lvl_race.pdfbin0 -> 49756 bytes
-rw-r--r--ACSAC/figures/egd/compas/old_format/compas_egd_dp_lvl_sex.pdfbin0 -> 49934 bytes
-rw-r--r--ACSAC/figures/egd/compas/old_format/compas_egd_utility.pdfbin0 -> 49892 bytes
-rw-r--r--ACSAC/figures/egd/lfw/lfw_egd_attack_hard_race.pdfbin0 -> 50023 bytes
-rw-r--r--ACSAC/figures/egd/lfw/lfw_egd_attack_hard_sex.pdfbin0 -> 49710 bytes
-rw-r--r--ACSAC/figures/egd/lfw/lfw_egd_dp_lvl_race.pdfbin0 -> 49896 bytes
-rw-r--r--ACSAC/figures/egd/lfw/lfw_egd_dp_lvl_sex.pdfbin0 -> 49724 bytes
-rw-r--r--ACSAC/figures/egd/lfw/lfw_egd_utility.pdfbin0 -> 49841 bytes
-rw-r--r--ACSAC/figures/egd/lfw/old_format/lfw_egd_attack_hard_race.pdfbin0 -> 50100 bytes
-rw-r--r--ACSAC/figures/egd/lfw/old_format/lfw_egd_attack_hard_sex.pdfbin0 -> 49791 bytes
-rw-r--r--ACSAC/figures/egd/lfw/old_format/lfw_egd_dp_lvl_race.pdfbin0 -> 49944 bytes
-rw-r--r--ACSAC/figures/egd/lfw/old_format/lfw_egd_dp_lvl_sex.pdfbin0 -> 49775 bytes
-rw-r--r--ACSAC/figures/egd/lfw/old_format/lfw_egd_utility.pdfbin0 -> 49890 bytes
-rw-r--r--ACSAC/figures/egd/meps/meps_egd_attack_hard_race.pdfbin0 -> 50215 bytes
-rw-r--r--ACSAC/figures/egd/meps/meps_egd_attack_hard_sex.pdfbin0 -> 49908 bytes
-rw-r--r--ACSAC/figures/egd/meps/meps_egd_dp_lvl_race.pdfbin0 -> 50054 bytes
-rw-r--r--ACSAC/figures/egd/meps/meps_egd_dp_lvl_sex.pdfbin0 -> 49875 bytes
-rw-r--r--ACSAC/figures/egd/meps/meps_egd_utility.pdfbin0 -> 49454 bytes
-rw-r--r--ACSAC/figures/egd/meps/old_format/meps_egd_attack_hard_race.pdfbin0 -> 50291 bytes
-rw-r--r--ACSAC/figures/egd/meps/old_format/meps_egd_attack_hard_sex.pdfbin0 -> 49990 bytes
-rw-r--r--ACSAC/figures/egd/meps/old_format/meps_egd_dp_lvl_race.pdfbin0 -> 50103 bytes
-rw-r--r--ACSAC/figures/egd/meps/old_format/meps_egd_dp_lvl_sex.pdfbin0 -> 49924 bytes
-rw-r--r--ACSAC/figures/egd/meps/old_format/meps_egd_utility.pdfbin0 -> 49504 bytes
-rw-r--r--ACSAC/figures/fig_advdebias_attacc.tex139
-rw-r--r--ACSAC/figures/fig_advdebias_fair.tex47
-rw-r--r--ACSAC/figures/fig_advdebias_utility.tex23
-rw-r--r--ACSAC/figures/fig_egd_attack.tex50
-rw-r--r--ACSAC/figures/fig_egd_fair.tex46
-rw-r--r--ACSAC/figures/fig_egd_utility.tex20
-rw-r--r--ACSAC/figures/fig_tm2.tex47
-rw-r--r--ACSAC/figures/old_distrib.pdfbin0 -> 16234 bytes
-rw-r--r--ACSAC/image/BaVsState.pdfbin0 -> 14028 bytes
-rw-r--r--ACSAC/image/annexe/attack/CENSUS/race.pdfbin0 -> 11168 bytes
-rw-r--r--ACSAC/image/annexe/attack/CENSUS/sex.pdfbin0 -> 10555 bytes
-rw-r--r--ACSAC/image/annexe/attack/COMPAS/race.pdfbin0 -> 10386 bytes
-rw-r--r--ACSAC/image/annexe/attack/COMPAS/sex.pdfbin0 -> 10172 bytes
-rw-r--r--ACSAC/image/annexe/attack/CREDIT/race.pdfbin0 -> 10284 bytes
-rw-r--r--ACSAC/image/annexe/attack/CREDIT/sex.pdfbin0 -> 10958 bytes
-rw-r--r--ACSAC/image/annexe/attack/LAW/race.pdfbin0 -> 11549 bytes
-rw-r--r--ACSAC/image/annexe/attack/LAW/sex.pdfbin0 -> 10289 bytes
-rw-r--r--ACSAC/image/annexe/attack/MEPS/race.pdfbin0 -> 11181 bytes
-rw-r--r--ACSAC/image/annexe/attack/MEPS/sex.pdfbin0 -> 11496 bytes
-rw-r--r--ACSAC/image/annexe/mia/CENSUS/race.pdfbin0 -> 11634 bytes
-rw-r--r--ACSAC/image/annexe/mia/CENSUS/sex.pdfbin0 -> 11413 bytes
-rw-r--r--ACSAC/image/annexe/mia/COMPAS/race.pdfbin0 -> 11352 bytes
-rw-r--r--ACSAC/image/annexe/mia/COMPAS/sex.pdfbin0 -> 11585 bytes
-rw-r--r--ACSAC/image/annexe/mia/CREDIT/race.pdfbin0 -> 10632 bytes
-rw-r--r--ACSAC/image/annexe/mia/CREDIT/sex.pdfbin0 -> 10610 bytes
-rw-r--r--ACSAC/image/annexe/mia/LAW/race.pdfbin0 -> 12045 bytes
-rw-r--r--ACSAC/image/annexe/mia/LAW/sex.pdfbin0 -> 12244 bytes
-rw-r--r--ACSAC/image/annexe/mia/MEPS/race.pdfbin0 -> 11061 bytes
-rw-r--r--ACSAC/image/annexe/mia/MEPS/sex.pdfbin0 -> 11389 bytes
-rw-r--r--ACSAC/image/annexe/utility/CENSUS/race.pdfbin0 -> 11631 bytes
-rw-r--r--ACSAC/image/annexe/utility/CENSUS/sex.pdfbin0 -> 11943 bytes
-rw-r--r--ACSAC/image/annexe/utility/COMPAS/race.pdfbin0 -> 11603 bytes
-rw-r--r--ACSAC/image/annexe/utility/COMPAS/sex.pdfbin0 -> 11610 bytes
-rw-r--r--ACSAC/image/annexe/utility/CREDIT/race.pdfbin0 -> 12284 bytes
-rw-r--r--ACSAC/image/annexe/utility/CREDIT/sex.pdfbin0 -> 11631 bytes
-rw-r--r--ACSAC/image/annexe/utility/LAW/race.pdfbin0 -> 11089 bytes
-rw-r--r--ACSAC/image/annexe/utility/LAW/sex.pdfbin0 -> 11083 bytes
-rw-r--r--ACSAC/image/annexe/utility/MEPS/race.pdfbin0 -> 11633 bytes
-rw-r--r--ACSAC/image/annexe/utility/MEPS/sex.pdfbin0 -> 12019 bytes
-rw-r--r--ACSAC/image/dpvseoo.pdfbin0 -> 14065 bytes
-rw-r--r--ACSAC/image/hardvsdef.pdfbin0 -> 12402 bytes
-rw-r--r--ACSAC/image/miaeoo.pdfbin0 -> 12044 bytes
-rw-r--r--ACSAC/image/rfvsnn.pdfbin0 -> 12073 bytes
-rw-r--r--ACSAC/image/roc.pdfbin0 -> 13651 bytes
-rw-r--r--ACSAC/llncs.cls1244
-rw-r--r--ACSAC/paper.bib1204
-rw-r--r--ACSAC/proofs/proof_advdebias.tex30
-rw-r--r--ACSAC/proofs/proof_egd_dp.tex33
-rw-r--r--ACSAC/proofs/proof_egd_eo.tex35
-rw-r--r--ACSAC/tables/tab_attack.tex30
-rw-r--r--ACSAC/tables/tab_datasets.tex17
-rw-r--r--ACSAC/tables/tab_summary.tex32
159 files changed, 2997 insertions, 0 deletions
diff --git a/ACSAC/figures/advdebias/census/census_advdeb_attack_hard_race.pdf b/ACSAC/figures/advdebias/census/census_advdeb_attack_hard_race.pdf
new file mode 100644
index 0000000..a6b8ad6
--- /dev/null
+++ b/ACSAC/figures/advdebias/census/census_advdeb_attack_hard_race.pdf
Binary files differ
diff --git a/ACSAC/figures/advdebias/census/census_advdeb_attack_hard_sex.pdf b/ACSAC/figures/advdebias/census/census_advdeb_attack_hard_sex.pdf
new file mode 100644
index 0000000..6cd8129
--- /dev/null
+++ b/ACSAC/figures/advdebias/census/census_advdeb_attack_hard_sex.pdf
Binary files differ
diff --git a/ACSAC/figures/advdebias/census/census_advdeb_attack_soft_experimental_race.pdf b/ACSAC/figures/advdebias/census/census_advdeb_attack_soft_experimental_race.pdf
new file mode 100644
index 0000000..cfa61f4
--- /dev/null
+++ b/ACSAC/figures/advdebias/census/census_advdeb_attack_soft_experimental_race.pdf
Binary files differ
diff --git a/ACSAC/figures/advdebias/census/census_advdeb_attack_soft_experimental_sex.pdf b/ACSAC/figures/advdebias/census/census_advdeb_attack_soft_experimental_sex.pdf
new file mode 100644
index 0000000..f1d5b73
--- /dev/null
+++ b/ACSAC/figures/advdebias/census/census_advdeb_attack_soft_experimental_sex.pdf
Binary files differ
diff --git a/ACSAC/figures/advdebias/census/census_advdeb_dp_lvl_race.pdf b/ACSAC/figures/advdebias/census/census_advdeb_dp_lvl_race.pdf
new file mode 100644
index 0000000..034900a
--- /dev/null
+++ b/ACSAC/figures/advdebias/census/census_advdeb_dp_lvl_race.pdf
Binary files differ
diff --git a/ACSAC/figures/advdebias/census/census_advdeb_dp_lvl_sex.pdf b/ACSAC/figures/advdebias/census/census_advdeb_dp_lvl_sex.pdf
new file mode 100644
index 0000000..4618c53
--- /dev/null
+++ b/ACSAC/figures/advdebias/census/census_advdeb_dp_lvl_sex.pdf
Binary files differ
diff --git a/ACSAC/figures/advdebias/census/census_advdeb_utility.pdf b/ACSAC/figures/advdebias/census/census_advdeb_utility.pdf
new file mode 100644
index 0000000..75a4918
--- /dev/null
+++ b/ACSAC/figures/advdebias/census/census_advdeb_utility.pdf
Binary files differ
diff --git a/ACSAC/figures/advdebias/census/old_format/census_advdeb_attack_hard_race.pdf b/ACSAC/figures/advdebias/census/old_format/census_advdeb_attack_hard_race.pdf
new file mode 100644
index 0000000..b42aff1
--- /dev/null
+++ b/ACSAC/figures/advdebias/census/old_format/census_advdeb_attack_hard_race.pdf
Binary files differ
diff --git a/ACSAC/figures/advdebias/census/old_format/census_advdeb_attack_hard_sex.pdf b/ACSAC/figures/advdebias/census/old_format/census_advdeb_attack_hard_sex.pdf
new file mode 100644
index 0000000..b29cdc5
--- /dev/null
+++ b/ACSAC/figures/advdebias/census/old_format/census_advdeb_attack_hard_sex.pdf
Binary files differ
diff --git a/ACSAC/figures/advdebias/census/old_format/census_advdeb_attack_soft_experimental_race.pdf b/ACSAC/figures/advdebias/census/old_format/census_advdeb_attack_soft_experimental_race.pdf
new file mode 100644
index 0000000..f1916a9
--- /dev/null
+++ b/ACSAC/figures/advdebias/census/old_format/census_advdeb_attack_soft_experimental_race.pdf
Binary files differ
diff --git a/ACSAC/figures/advdebias/census/old_format/census_advdeb_attack_soft_experimental_sex.pdf b/ACSAC/figures/advdebias/census/old_format/census_advdeb_attack_soft_experimental_sex.pdf
new file mode 100644
index 0000000..6e3a8e8
--- /dev/null
+++ b/ACSAC/figures/advdebias/census/old_format/census_advdeb_attack_soft_experimental_sex.pdf
Binary files differ
diff --git a/ACSAC/figures/advdebias/census/old_format/census_advdeb_dp_lvl_race.pdf b/ACSAC/figures/advdebias/census/old_format/census_advdeb_dp_lvl_race.pdf
new file mode 100644
index 0000000..bd91e9c
--- /dev/null
+++ b/ACSAC/figures/advdebias/census/old_format/census_advdeb_dp_lvl_race.pdf
Binary files differ
diff --git a/ACSAC/figures/advdebias/census/old_format/census_advdeb_dp_lvl_sex.pdf b/ACSAC/figures/advdebias/census/old_format/census_advdeb_dp_lvl_sex.pdf
new file mode 100644
index 0000000..34bea6f
--- /dev/null
+++ b/ACSAC/figures/advdebias/census/old_format/census_advdeb_dp_lvl_sex.pdf
Binary files differ
diff --git a/ACSAC/figures/advdebias/census/old_format/census_advdeb_utility.pdf b/ACSAC/figures/advdebias/census/old_format/census_advdeb_utility.pdf
new file mode 100644
index 0000000..0f42ba6
--- /dev/null
+++ b/ACSAC/figures/advdebias/census/old_format/census_advdeb_utility.pdf
Binary files differ
diff --git a/ACSAC/figures/advdebias/compas/compas_advdeb_attack_hard_race.pdf b/ACSAC/figures/advdebias/compas/compas_advdeb_attack_hard_race.pdf
new file mode 100644
index 0000000..45fb1f8
--- /dev/null
+++ b/ACSAC/figures/advdebias/compas/compas_advdeb_attack_hard_race.pdf
Binary files differ
diff --git a/ACSAC/figures/advdebias/compas/compas_advdeb_attack_hard_sex.pdf b/ACSAC/figures/advdebias/compas/compas_advdeb_attack_hard_sex.pdf
new file mode 100644
index 0000000..619782d
--- /dev/null
+++ b/ACSAC/figures/advdebias/compas/compas_advdeb_attack_hard_sex.pdf
Binary files differ
diff --git a/ACSAC/figures/advdebias/compas/compas_advdeb_attack_soft_experimental_race.pdf b/ACSAC/figures/advdebias/compas/compas_advdeb_attack_soft_experimental_race.pdf
new file mode 100644
index 0000000..a46ef7f
--- /dev/null
+++ b/ACSAC/figures/advdebias/compas/compas_advdeb_attack_soft_experimental_race.pdf
Binary files differ
diff --git a/ACSAC/figures/advdebias/compas/compas_advdeb_attack_soft_experimental_sex.pdf b/ACSAC/figures/advdebias/compas/compas_advdeb_attack_soft_experimental_sex.pdf
new file mode 100644
index 0000000..e24476c
--- /dev/null
+++ b/ACSAC/figures/advdebias/compas/compas_advdeb_attack_soft_experimental_sex.pdf
Binary files differ
diff --git a/ACSAC/figures/advdebias/compas/compas_advdeb_dp_lvl_race.pdf b/ACSAC/figures/advdebias/compas/compas_advdeb_dp_lvl_race.pdf
new file mode 100644
index 0000000..f4d6efe
--- /dev/null
+++ b/ACSAC/figures/advdebias/compas/compas_advdeb_dp_lvl_race.pdf
Binary files differ
diff --git a/ACSAC/figures/advdebias/compas/compas_advdeb_dp_lvl_sex.pdf b/ACSAC/figures/advdebias/compas/compas_advdeb_dp_lvl_sex.pdf
new file mode 100644
index 0000000..a107b3c
--- /dev/null
+++ b/ACSAC/figures/advdebias/compas/compas_advdeb_dp_lvl_sex.pdf
Binary files differ
diff --git a/ACSAC/figures/advdebias/compas/compas_advdeb_utility.pdf b/ACSAC/figures/advdebias/compas/compas_advdeb_utility.pdf
new file mode 100644
index 0000000..9e50fc3
--- /dev/null
+++ b/ACSAC/figures/advdebias/compas/compas_advdeb_utility.pdf
Binary files differ
diff --git a/ACSAC/figures/advdebias/compas/old_format/compas_advdeb_attack_hard_race.pdf b/ACSAC/figures/advdebias/compas/old_format/compas_advdeb_attack_hard_race.pdf
new file mode 100644
index 0000000..8c92c18
--- /dev/null
+++ b/ACSAC/figures/advdebias/compas/old_format/compas_advdeb_attack_hard_race.pdf
Binary files differ
diff --git a/ACSAC/figures/advdebias/compas/old_format/compas_advdeb_attack_hard_sex.pdf b/ACSAC/figures/advdebias/compas/old_format/compas_advdeb_attack_hard_sex.pdf
new file mode 100644
index 0000000..9cd49c9
--- /dev/null
+++ b/ACSAC/figures/advdebias/compas/old_format/compas_advdeb_attack_hard_sex.pdf
Binary files differ
diff --git a/ACSAC/figures/advdebias/compas/old_format/compas_advdeb_attack_soft_experimental_race.pdf b/ACSAC/figures/advdebias/compas/old_format/compas_advdeb_attack_soft_experimental_race.pdf
new file mode 100644
index 0000000..de1bf37
--- /dev/null
+++ b/ACSAC/figures/advdebias/compas/old_format/compas_advdeb_attack_soft_experimental_race.pdf
Binary files differ
diff --git a/ACSAC/figures/advdebias/compas/old_format/compas_advdeb_attack_soft_experimental_sex.pdf b/ACSAC/figures/advdebias/compas/old_format/compas_advdeb_attack_soft_experimental_sex.pdf
new file mode 100644
index 0000000..060ee8b
--- /dev/null
+++ b/ACSAC/figures/advdebias/compas/old_format/compas_advdeb_attack_soft_experimental_sex.pdf
Binary files differ
diff --git a/ACSAC/figures/advdebias/compas/old_format/compas_advdeb_dp_lvl_race.pdf b/ACSAC/figures/advdebias/compas/old_format/compas_advdeb_dp_lvl_race.pdf
new file mode 100644
index 0000000..ad254c2
--- /dev/null
+++ b/ACSAC/figures/advdebias/compas/old_format/compas_advdeb_dp_lvl_race.pdf
Binary files differ
diff --git a/ACSAC/figures/advdebias/compas/old_format/compas_advdeb_dp_lvl_sex.pdf b/ACSAC/figures/advdebias/compas/old_format/compas_advdeb_dp_lvl_sex.pdf
new file mode 100644
index 0000000..a8ffae1
--- /dev/null
+++ b/ACSAC/figures/advdebias/compas/old_format/compas_advdeb_dp_lvl_sex.pdf
Binary files differ
diff --git a/ACSAC/figures/advdebias/compas/old_format/compas_advdeb_utility.pdf b/ACSAC/figures/advdebias/compas/old_format/compas_advdeb_utility.pdf
new file mode 100644
index 0000000..1ab57f1
--- /dev/null
+++ b/ACSAC/figures/advdebias/compas/old_format/compas_advdeb_utility.pdf
Binary files differ
diff --git a/ACSAC/figures/advdebias/lfw/lfw_advdeb_attack_hard_race.pdf b/ACSAC/figures/advdebias/lfw/lfw_advdeb_attack_hard_race.pdf
new file mode 100644
index 0000000..7a40ea1
--- /dev/null
+++ b/ACSAC/figures/advdebias/lfw/lfw_advdeb_attack_hard_race.pdf
Binary files differ
diff --git a/ACSAC/figures/advdebias/lfw/lfw_advdeb_attack_hard_sex.pdf b/ACSAC/figures/advdebias/lfw/lfw_advdeb_attack_hard_sex.pdf
new file mode 100644
index 0000000..7ebda1f
--- /dev/null
+++ b/ACSAC/figures/advdebias/lfw/lfw_advdeb_attack_hard_sex.pdf
Binary files differ
diff --git a/ACSAC/figures/advdebias/lfw/lfw_advdeb_attack_soft_experimental_race.pdf b/ACSAC/figures/advdebias/lfw/lfw_advdeb_attack_soft_experimental_race.pdf
new file mode 100644
index 0000000..a77dbfa
--- /dev/null
+++ b/ACSAC/figures/advdebias/lfw/lfw_advdeb_attack_soft_experimental_race.pdf
Binary files differ
diff --git a/ACSAC/figures/advdebias/lfw/lfw_advdeb_attack_soft_experimental_sex.pdf b/ACSAC/figures/advdebias/lfw/lfw_advdeb_attack_soft_experimental_sex.pdf
new file mode 100644
index 0000000..56f315b
--- /dev/null
+++ b/ACSAC/figures/advdebias/lfw/lfw_advdeb_attack_soft_experimental_sex.pdf
Binary files differ
diff --git a/ACSAC/figures/advdebias/lfw/lfw_advdeb_dp_lvl_race.pdf b/ACSAC/figures/advdebias/lfw/lfw_advdeb_dp_lvl_race.pdf
new file mode 100644
index 0000000..5d60275
--- /dev/null
+++ b/ACSAC/figures/advdebias/lfw/lfw_advdeb_dp_lvl_race.pdf
Binary files differ
diff --git a/ACSAC/figures/advdebias/lfw/lfw_advdeb_dp_lvl_sex.pdf b/ACSAC/figures/advdebias/lfw/lfw_advdeb_dp_lvl_sex.pdf
new file mode 100644
index 0000000..d7e611b
--- /dev/null
+++ b/ACSAC/figures/advdebias/lfw/lfw_advdeb_dp_lvl_sex.pdf
Binary files differ
diff --git a/ACSAC/figures/advdebias/lfw/lfw_advdeb_utility.pdf b/ACSAC/figures/advdebias/lfw/lfw_advdeb_utility.pdf
new file mode 100644
index 0000000..0750661
--- /dev/null
+++ b/ACSAC/figures/advdebias/lfw/lfw_advdeb_utility.pdf
Binary files differ
diff --git a/ACSAC/figures/advdebias/lfw/old_format/lfw_advdeb_attack_hard_race.pdf b/ACSAC/figures/advdebias/lfw/old_format/lfw_advdeb_attack_hard_race.pdf
new file mode 100644
index 0000000..7bc5d56
--- /dev/null
+++ b/ACSAC/figures/advdebias/lfw/old_format/lfw_advdeb_attack_hard_race.pdf
Binary files differ
diff --git a/ACSAC/figures/advdebias/lfw/old_format/lfw_advdeb_attack_hard_sex.pdf b/ACSAC/figures/advdebias/lfw/old_format/lfw_advdeb_attack_hard_sex.pdf
new file mode 100644
index 0000000..fb517b2
--- /dev/null
+++ b/ACSAC/figures/advdebias/lfw/old_format/lfw_advdeb_attack_hard_sex.pdf
Binary files differ
diff --git a/ACSAC/figures/advdebias/lfw/old_format/lfw_advdeb_attack_soft_experimental_race.pdf b/ACSAC/figures/advdebias/lfw/old_format/lfw_advdeb_attack_soft_experimental_race.pdf
new file mode 100644
index 0000000..547ac5f
--- /dev/null
+++ b/ACSAC/figures/advdebias/lfw/old_format/lfw_advdeb_attack_soft_experimental_race.pdf
Binary files differ
diff --git a/ACSAC/figures/advdebias/lfw/old_format/lfw_advdeb_attack_soft_experimental_sex.pdf b/ACSAC/figures/advdebias/lfw/old_format/lfw_advdeb_attack_soft_experimental_sex.pdf
new file mode 100644
index 0000000..8a016f0
--- /dev/null
+++ b/ACSAC/figures/advdebias/lfw/old_format/lfw_advdeb_attack_soft_experimental_sex.pdf
Binary files differ
diff --git a/ACSAC/figures/advdebias/lfw/old_format/lfw_advdeb_dp_lvl_race.pdf b/ACSAC/figures/advdebias/lfw/old_format/lfw_advdeb_dp_lvl_race.pdf
new file mode 100644
index 0000000..0bc2213
--- /dev/null
+++ b/ACSAC/figures/advdebias/lfw/old_format/lfw_advdeb_dp_lvl_race.pdf
Binary files differ
diff --git a/ACSAC/figures/advdebias/lfw/old_format/lfw_advdeb_dp_lvl_sex.pdf b/ACSAC/figures/advdebias/lfw/old_format/lfw_advdeb_dp_lvl_sex.pdf
new file mode 100644
index 0000000..74abd1a
--- /dev/null
+++ b/ACSAC/figures/advdebias/lfw/old_format/lfw_advdeb_dp_lvl_sex.pdf
Binary files differ
diff --git a/ACSAC/figures/advdebias/lfw/old_format/lfw_advdeb_utility.pdf b/ACSAC/figures/advdebias/lfw/old_format/lfw_advdeb_utility.pdf
new file mode 100644
index 0000000..f229545
--- /dev/null
+++ b/ACSAC/figures/advdebias/lfw/old_format/lfw_advdeb_utility.pdf
Binary files differ
diff --git a/ACSAC/figures/advdebias/meps/meps_advdeb_attack_hard_race.pdf b/ACSAC/figures/advdebias/meps/meps_advdeb_attack_hard_race.pdf
new file mode 100644
index 0000000..f127522
--- /dev/null
+++ b/ACSAC/figures/advdebias/meps/meps_advdeb_attack_hard_race.pdf
Binary files differ
diff --git a/ACSAC/figures/advdebias/meps/meps_advdeb_attack_hard_sex.pdf b/ACSAC/figures/advdebias/meps/meps_advdeb_attack_hard_sex.pdf
new file mode 100644
index 0000000..760396f
--- /dev/null
+++ b/ACSAC/figures/advdebias/meps/meps_advdeb_attack_hard_sex.pdf
Binary files differ
diff --git a/ACSAC/figures/advdebias/meps/meps_advdeb_attack_soft_experimental_race.pdf b/ACSAC/figures/advdebias/meps/meps_advdeb_attack_soft_experimental_race.pdf
new file mode 100644
index 0000000..e404fbf
--- /dev/null
+++ b/ACSAC/figures/advdebias/meps/meps_advdeb_attack_soft_experimental_race.pdf
Binary files differ
diff --git a/ACSAC/figures/advdebias/meps/meps_advdeb_attack_soft_experimental_sex.pdf b/ACSAC/figures/advdebias/meps/meps_advdeb_attack_soft_experimental_sex.pdf
new file mode 100644
index 0000000..13dd4ef
--- /dev/null
+++ b/ACSAC/figures/advdebias/meps/meps_advdeb_attack_soft_experimental_sex.pdf
Binary files differ
diff --git a/ACSAC/figures/advdebias/meps/meps_advdeb_dp_lvl_race.pdf b/ACSAC/figures/advdebias/meps/meps_advdeb_dp_lvl_race.pdf
new file mode 100644
index 0000000..b7d7108
--- /dev/null
+++ b/ACSAC/figures/advdebias/meps/meps_advdeb_dp_lvl_race.pdf
Binary files differ
diff --git a/ACSAC/figures/advdebias/meps/meps_advdeb_dp_lvl_sex.pdf b/ACSAC/figures/advdebias/meps/meps_advdeb_dp_lvl_sex.pdf
new file mode 100644
index 0000000..feee72c
--- /dev/null
+++ b/ACSAC/figures/advdebias/meps/meps_advdeb_dp_lvl_sex.pdf
Binary files differ
diff --git a/ACSAC/figures/advdebias/meps/meps_advdeb_utility.pdf b/ACSAC/figures/advdebias/meps/meps_advdeb_utility.pdf
new file mode 100644
index 0000000..4ed4f87
--- /dev/null
+++ b/ACSAC/figures/advdebias/meps/meps_advdeb_utility.pdf
Binary files differ
diff --git a/ACSAC/figures/advdebias/meps/old_format/meps_advdeb_attack_hard_race.pdf b/ACSAC/figures/advdebias/meps/old_format/meps_advdeb_attack_hard_race.pdf
new file mode 100644
index 0000000..ec398e9
--- /dev/null
+++ b/ACSAC/figures/advdebias/meps/old_format/meps_advdeb_attack_hard_race.pdf
Binary files differ
diff --git a/ACSAC/figures/advdebias/meps/old_format/meps_advdeb_attack_hard_sex.pdf b/ACSAC/figures/advdebias/meps/old_format/meps_advdeb_attack_hard_sex.pdf
new file mode 100644
index 0000000..40b080f
--- /dev/null
+++ b/ACSAC/figures/advdebias/meps/old_format/meps_advdeb_attack_hard_sex.pdf
Binary files differ
diff --git a/ACSAC/figures/advdebias/meps/old_format/meps_advdeb_attack_soft_experimental_race.pdf b/ACSAC/figures/advdebias/meps/old_format/meps_advdeb_attack_soft_experimental_race.pdf
new file mode 100644
index 0000000..8c51e72
--- /dev/null
+++ b/ACSAC/figures/advdebias/meps/old_format/meps_advdeb_attack_soft_experimental_race.pdf
Binary files differ
diff --git a/ACSAC/figures/advdebias/meps/old_format/meps_advdeb_attack_soft_experimental_sex.pdf b/ACSAC/figures/advdebias/meps/old_format/meps_advdeb_attack_soft_experimental_sex.pdf
new file mode 100644
index 0000000..5791e29
--- /dev/null
+++ b/ACSAC/figures/advdebias/meps/old_format/meps_advdeb_attack_soft_experimental_sex.pdf
Binary files differ
diff --git a/ACSAC/figures/advdebias/meps/old_format/meps_advdeb_dp_lvl_race.pdf b/ACSAC/figures/advdebias/meps/old_format/meps_advdeb_dp_lvl_race.pdf
new file mode 100644
index 0000000..0b10830
--- /dev/null
+++ b/ACSAC/figures/advdebias/meps/old_format/meps_advdeb_dp_lvl_race.pdf
Binary files differ
diff --git a/ACSAC/figures/advdebias/meps/old_format/meps_advdeb_dp_lvl_sex.pdf b/ACSAC/figures/advdebias/meps/old_format/meps_advdeb_dp_lvl_sex.pdf
new file mode 100644
index 0000000..5145848
--- /dev/null
+++ b/ACSAC/figures/advdebias/meps/old_format/meps_advdeb_dp_lvl_sex.pdf
Binary files differ
diff --git a/ACSAC/figures/advdebias/meps/old_format/meps_advdeb_utility.pdf b/ACSAC/figures/advdebias/meps/old_format/meps_advdeb_utility.pdf
new file mode 100644
index 0000000..ab1e523
--- /dev/null
+++ b/ACSAC/figures/advdebias/meps/old_format/meps_advdeb_utility.pdf
Binary files differ
diff --git a/ACSAC/figures/after.pdf b/ACSAC/figures/after.pdf
new file mode 100644
index 0000000..79b48ca
--- /dev/null
+++ b/ACSAC/figures/after.pdf
Binary files differ
diff --git a/ACSAC/figures/before.pdf b/ACSAC/figures/before.pdf
new file mode 100644
index 0000000..4dc956e
--- /dev/null
+++ b/ACSAC/figures/before.pdf
Binary files differ
diff --git a/ACSAC/figures/distribution_attack_impact/debiasing.pdf b/ACSAC/figures/distribution_attack_impact/debiasing.pdf
new file mode 100644
index 0000000..a39e062
--- /dev/null
+++ b/ACSAC/figures/distribution_attack_impact/debiasing.pdf
Binary files differ
diff --git a/ACSAC/figures/distribution_attack_impact/egd.pdf b/ACSAC/figures/distribution_attack_impact/egd.pdf
new file mode 100644
index 0000000..b9e34d7
--- /dev/null
+++ b/ACSAC/figures/distribution_attack_impact/egd.pdf
Binary files differ
diff --git a/ACSAC/figures/distribution_attack_impact/res.pdf b/ACSAC/figures/distribution_attack_impact/res.pdf
new file mode 100644
index 0000000..944cb96
--- /dev/null
+++ b/ACSAC/figures/distribution_attack_impact/res.pdf
Binary files differ
diff --git a/ACSAC/figures/distributions/LAW_dist.pdf b/ACSAC/figures/distributions/LAW_dist.pdf
new file mode 100644
index 0000000..f7767f6
--- /dev/null
+++ b/ACSAC/figures/distributions/LAW_dist.pdf
Binary files differ
diff --git a/ACSAC/figures/distributions/LFW_dist.pdf b/ACSAC/figures/distributions/LFW_dist.pdf
new file mode 100644
index 0000000..d8f05c6
--- /dev/null
+++ b/ACSAC/figures/distributions/LFW_dist.pdf
Binary files differ
diff --git a/ACSAC/figures/distributions/census_dist.pdf b/ACSAC/figures/distributions/census_dist.pdf
new file mode 100644
index 0000000..3a6cd0c
--- /dev/null
+++ b/ACSAC/figures/distributions/census_dist.pdf
Binary files differ
diff --git a/ACSAC/figures/distributions/compas_dist.pdf b/ACSAC/figures/distributions/compas_dist.pdf
new file mode 100644
index 0000000..45bd5f4
--- /dev/null
+++ b/ACSAC/figures/distributions/compas_dist.pdf
Binary files differ
diff --git a/ACSAC/figures/distributions/credit_dist.pdf b/ACSAC/figures/distributions/credit_dist.pdf
new file mode 100644
index 0000000..8b2473e
--- /dev/null
+++ b/ACSAC/figures/distributions/credit_dist.pdf
Binary files differ
diff --git a/ACSAC/figures/distributions/meps_dist.pdf b/ACSAC/figures/distributions/meps_dist.pdf
new file mode 100644
index 0000000..d62e6b2
--- /dev/null
+++ b/ACSAC/figures/distributions/meps_dist.pdf
Binary files differ
diff --git a/ACSAC/figures/egd/census/census_egd_attack_hard_race.pdf b/ACSAC/figures/egd/census/census_egd_attack_hard_race.pdf
new file mode 100644
index 0000000..dc652ca
--- /dev/null
+++ b/ACSAC/figures/egd/census/census_egd_attack_hard_race.pdf
Binary files differ
diff --git a/ACSAC/figures/egd/census/census_egd_attack_hard_sex.pdf b/ACSAC/figures/egd/census/census_egd_attack_hard_sex.pdf
new file mode 100644
index 0000000..1f61b13
--- /dev/null
+++ b/ACSAC/figures/egd/census/census_egd_attack_hard_sex.pdf
Binary files differ
diff --git a/ACSAC/figures/egd/census/census_egd_dp_lvl_race.pdf b/ACSAC/figures/egd/census/census_egd_dp_lvl_race.pdf
new file mode 100644
index 0000000..9e36e6b
--- /dev/null
+++ b/ACSAC/figures/egd/census/census_egd_dp_lvl_race.pdf
Binary files differ
diff --git a/ACSAC/figures/egd/census/census_egd_dp_lvl_sex.pdf b/ACSAC/figures/egd/census/census_egd_dp_lvl_sex.pdf
new file mode 100644
index 0000000..762592c
--- /dev/null
+++ b/ACSAC/figures/egd/census/census_egd_dp_lvl_sex.pdf
Binary files differ
diff --git a/ACSAC/figures/egd/census/census_egd_utility.pdf b/ACSAC/figures/egd/census/census_egd_utility.pdf
new file mode 100644
index 0000000..be36f75
--- /dev/null
+++ b/ACSAC/figures/egd/census/census_egd_utility.pdf
Binary files differ
diff --git a/ACSAC/figures/egd/census/old_format/census_egd_attack_hard_race.pdf b/ACSAC/figures/egd/census/old_format/census_egd_attack_hard_race.pdf
new file mode 100644
index 0000000..f18f4f6
--- /dev/null
+++ b/ACSAC/figures/egd/census/old_format/census_egd_attack_hard_race.pdf
Binary files differ
diff --git a/ACSAC/figures/egd/census/old_format/census_egd_attack_hard_sex.pdf b/ACSAC/figures/egd/census/old_format/census_egd_attack_hard_sex.pdf
new file mode 100644
index 0000000..2edd459
--- /dev/null
+++ b/ACSAC/figures/egd/census/old_format/census_egd_attack_hard_sex.pdf
Binary files differ
diff --git a/ACSAC/figures/egd/census/old_format/census_egd_dp_lvl_race.pdf b/ACSAC/figures/egd/census/old_format/census_egd_dp_lvl_race.pdf
new file mode 100644
index 0000000..552296f
--- /dev/null
+++ b/ACSAC/figures/egd/census/old_format/census_egd_dp_lvl_race.pdf
Binary files differ
diff --git a/ACSAC/figures/egd/census/old_format/census_egd_dp_lvl_sex.pdf b/ACSAC/figures/egd/census/old_format/census_egd_dp_lvl_sex.pdf
new file mode 100644
index 0000000..50a2e4d
--- /dev/null
+++ b/ACSAC/figures/egd/census/old_format/census_egd_dp_lvl_sex.pdf
Binary files differ
diff --git a/ACSAC/figures/egd/census/old_format/census_egd_utility.pdf b/ACSAC/figures/egd/census/old_format/census_egd_utility.pdf
new file mode 100644
index 0000000..75c9f96
--- /dev/null
+++ b/ACSAC/figures/egd/census/old_format/census_egd_utility.pdf
Binary files differ
diff --git a/ACSAC/figures/egd/compas/compas_egd_attack_hard_race.pdf b/ACSAC/figures/egd/compas/compas_egd_attack_hard_race.pdf
new file mode 100644
index 0000000..1cf5680
--- /dev/null
+++ b/ACSAC/figures/egd/compas/compas_egd_attack_hard_race.pdf
Binary files differ
diff --git a/ACSAC/figures/egd/compas/compas_egd_attack_hard_sex.pdf b/ACSAC/figures/egd/compas/compas_egd_attack_hard_sex.pdf
new file mode 100644
index 0000000..e9474b5
--- /dev/null
+++ b/ACSAC/figures/egd/compas/compas_egd_attack_hard_sex.pdf
Binary files differ
diff --git a/ACSAC/figures/egd/compas/compas_egd_dp_lvl_race.pdf b/ACSAC/figures/egd/compas/compas_egd_dp_lvl_race.pdf
new file mode 100644
index 0000000..d7cac7d
--- /dev/null
+++ b/ACSAC/figures/egd/compas/compas_egd_dp_lvl_race.pdf
Binary files differ
diff --git a/ACSAC/figures/egd/compas/compas_egd_dp_lvl_sex.pdf b/ACSAC/figures/egd/compas/compas_egd_dp_lvl_sex.pdf
new file mode 100644
index 0000000..e4619b1
--- /dev/null
+++ b/ACSAC/figures/egd/compas/compas_egd_dp_lvl_sex.pdf
Binary files differ
diff --git a/ACSAC/figures/egd/compas/compas_egd_utility.pdf b/ACSAC/figures/egd/compas/compas_egd_utility.pdf
new file mode 100644
index 0000000..4f92317
--- /dev/null
+++ b/ACSAC/figures/egd/compas/compas_egd_utility.pdf
Binary files differ
diff --git a/ACSAC/figures/egd/compas/old_format/compas_egd_attack_hard_race.pdf b/ACSAC/figures/egd/compas/old_format/compas_egd_attack_hard_race.pdf
new file mode 100644
index 0000000..322907d
--- /dev/null
+++ b/ACSAC/figures/egd/compas/old_format/compas_egd_attack_hard_race.pdf
Binary files differ
diff --git a/ACSAC/figures/egd/compas/old_format/compas_egd_attack_hard_sex.pdf b/ACSAC/figures/egd/compas/old_format/compas_egd_attack_hard_sex.pdf
new file mode 100644
index 0000000..b0b6b95
--- /dev/null
+++ b/ACSAC/figures/egd/compas/old_format/compas_egd_attack_hard_sex.pdf
Binary files differ
diff --git a/ACSAC/figures/egd/compas/old_format/compas_egd_dp_lvl_race.pdf b/ACSAC/figures/egd/compas/old_format/compas_egd_dp_lvl_race.pdf
new file mode 100644
index 0000000..6a151ae
--- /dev/null
+++ b/ACSAC/figures/egd/compas/old_format/compas_egd_dp_lvl_race.pdf
Binary files differ
diff --git a/ACSAC/figures/egd/compas/old_format/compas_egd_dp_lvl_sex.pdf b/ACSAC/figures/egd/compas/old_format/compas_egd_dp_lvl_sex.pdf
new file mode 100644
index 0000000..946ce2d
--- /dev/null
+++ b/ACSAC/figures/egd/compas/old_format/compas_egd_dp_lvl_sex.pdf
Binary files differ
diff --git a/ACSAC/figures/egd/compas/old_format/compas_egd_utility.pdf b/ACSAC/figures/egd/compas/old_format/compas_egd_utility.pdf
new file mode 100644
index 0000000..5297e16
--- /dev/null
+++ b/ACSAC/figures/egd/compas/old_format/compas_egd_utility.pdf
Binary files differ
diff --git a/ACSAC/figures/egd/lfw/lfw_egd_attack_hard_race.pdf b/ACSAC/figures/egd/lfw/lfw_egd_attack_hard_race.pdf
new file mode 100644
index 0000000..a654acd
--- /dev/null
+++ b/ACSAC/figures/egd/lfw/lfw_egd_attack_hard_race.pdf
Binary files differ
diff --git a/ACSAC/figures/egd/lfw/lfw_egd_attack_hard_sex.pdf b/ACSAC/figures/egd/lfw/lfw_egd_attack_hard_sex.pdf
new file mode 100644
index 0000000..44f46ea
--- /dev/null
+++ b/ACSAC/figures/egd/lfw/lfw_egd_attack_hard_sex.pdf
Binary files differ
diff --git a/ACSAC/figures/egd/lfw/lfw_egd_dp_lvl_race.pdf b/ACSAC/figures/egd/lfw/lfw_egd_dp_lvl_race.pdf
new file mode 100644
index 0000000..5578370
--- /dev/null
+++ b/ACSAC/figures/egd/lfw/lfw_egd_dp_lvl_race.pdf
Binary files differ
diff --git a/ACSAC/figures/egd/lfw/lfw_egd_dp_lvl_sex.pdf b/ACSAC/figures/egd/lfw/lfw_egd_dp_lvl_sex.pdf
new file mode 100644
index 0000000..8108e89
--- /dev/null
+++ b/ACSAC/figures/egd/lfw/lfw_egd_dp_lvl_sex.pdf
Binary files differ
diff --git a/ACSAC/figures/egd/lfw/lfw_egd_utility.pdf b/ACSAC/figures/egd/lfw/lfw_egd_utility.pdf
new file mode 100644
index 0000000..f3ab5ce
--- /dev/null
+++ b/ACSAC/figures/egd/lfw/lfw_egd_utility.pdf
Binary files differ
diff --git a/ACSAC/figures/egd/lfw/old_format/lfw_egd_attack_hard_race.pdf b/ACSAC/figures/egd/lfw/old_format/lfw_egd_attack_hard_race.pdf
new file mode 100644
index 0000000..c4bdf46
--- /dev/null
+++ b/ACSAC/figures/egd/lfw/old_format/lfw_egd_attack_hard_race.pdf
Binary files differ
diff --git a/ACSAC/figures/egd/lfw/old_format/lfw_egd_attack_hard_sex.pdf b/ACSAC/figures/egd/lfw/old_format/lfw_egd_attack_hard_sex.pdf
new file mode 100644
index 0000000..03ab032
--- /dev/null
+++ b/ACSAC/figures/egd/lfw/old_format/lfw_egd_attack_hard_sex.pdf
Binary files differ
diff --git a/ACSAC/figures/egd/lfw/old_format/lfw_egd_dp_lvl_race.pdf b/ACSAC/figures/egd/lfw/old_format/lfw_egd_dp_lvl_race.pdf
new file mode 100644
index 0000000..83d6a83
--- /dev/null
+++ b/ACSAC/figures/egd/lfw/old_format/lfw_egd_dp_lvl_race.pdf
Binary files differ
diff --git a/ACSAC/figures/egd/lfw/old_format/lfw_egd_dp_lvl_sex.pdf b/ACSAC/figures/egd/lfw/old_format/lfw_egd_dp_lvl_sex.pdf
new file mode 100644
index 0000000..a1b0999
--- /dev/null
+++ b/ACSAC/figures/egd/lfw/old_format/lfw_egd_dp_lvl_sex.pdf
Binary files differ
diff --git a/ACSAC/figures/egd/lfw/old_format/lfw_egd_utility.pdf b/ACSAC/figures/egd/lfw/old_format/lfw_egd_utility.pdf
new file mode 100644
index 0000000..9f39a64
--- /dev/null
+++ b/ACSAC/figures/egd/lfw/old_format/lfw_egd_utility.pdf
Binary files differ
diff --git a/ACSAC/figures/egd/meps/meps_egd_attack_hard_race.pdf b/ACSAC/figures/egd/meps/meps_egd_attack_hard_race.pdf
new file mode 100644
index 0000000..b5c8413
--- /dev/null
+++ b/ACSAC/figures/egd/meps/meps_egd_attack_hard_race.pdf
Binary files differ
diff --git a/ACSAC/figures/egd/meps/meps_egd_attack_hard_sex.pdf b/ACSAC/figures/egd/meps/meps_egd_attack_hard_sex.pdf
new file mode 100644
index 0000000..4cc6ebc
--- /dev/null
+++ b/ACSAC/figures/egd/meps/meps_egd_attack_hard_sex.pdf
Binary files differ
diff --git a/ACSAC/figures/egd/meps/meps_egd_dp_lvl_race.pdf b/ACSAC/figures/egd/meps/meps_egd_dp_lvl_race.pdf
new file mode 100644
index 0000000..58e912a
--- /dev/null
+++ b/ACSAC/figures/egd/meps/meps_egd_dp_lvl_race.pdf
Binary files differ
diff --git a/ACSAC/figures/egd/meps/meps_egd_dp_lvl_sex.pdf b/ACSAC/figures/egd/meps/meps_egd_dp_lvl_sex.pdf
new file mode 100644
index 0000000..031896a
--- /dev/null
+++ b/ACSAC/figures/egd/meps/meps_egd_dp_lvl_sex.pdf
Binary files differ
diff --git a/ACSAC/figures/egd/meps/meps_egd_utility.pdf b/ACSAC/figures/egd/meps/meps_egd_utility.pdf
new file mode 100644
index 0000000..75d6f55
--- /dev/null
+++ b/ACSAC/figures/egd/meps/meps_egd_utility.pdf
Binary files differ
diff --git a/ACSAC/figures/egd/meps/old_format/meps_egd_attack_hard_race.pdf b/ACSAC/figures/egd/meps/old_format/meps_egd_attack_hard_race.pdf
new file mode 100644
index 0000000..6fdb539
--- /dev/null
+++ b/ACSAC/figures/egd/meps/old_format/meps_egd_attack_hard_race.pdf
Binary files differ
diff --git a/ACSAC/figures/egd/meps/old_format/meps_egd_attack_hard_sex.pdf b/ACSAC/figures/egd/meps/old_format/meps_egd_attack_hard_sex.pdf
new file mode 100644
index 0000000..afb6155
--- /dev/null
+++ b/ACSAC/figures/egd/meps/old_format/meps_egd_attack_hard_sex.pdf
Binary files differ
diff --git a/ACSAC/figures/egd/meps/old_format/meps_egd_dp_lvl_race.pdf b/ACSAC/figures/egd/meps/old_format/meps_egd_dp_lvl_race.pdf
new file mode 100644
index 0000000..ef3720a
--- /dev/null
+++ b/ACSAC/figures/egd/meps/old_format/meps_egd_dp_lvl_race.pdf
Binary files differ
diff --git a/ACSAC/figures/egd/meps/old_format/meps_egd_dp_lvl_sex.pdf b/ACSAC/figures/egd/meps/old_format/meps_egd_dp_lvl_sex.pdf
new file mode 100644
index 0000000..be47174
--- /dev/null
+++ b/ACSAC/figures/egd/meps/old_format/meps_egd_dp_lvl_sex.pdf
Binary files differ
diff --git a/ACSAC/figures/egd/meps/old_format/meps_egd_utility.pdf b/ACSAC/figures/egd/meps/old_format/meps_egd_utility.pdf
new file mode 100644
index 0000000..8aaf310
--- /dev/null
+++ b/ACSAC/figures/egd/meps/old_format/meps_egd_utility.pdf
Binary files differ
diff --git a/ACSAC/figures/fig_advdebias_attacc.tex b/ACSAC/figures/fig_advdebias_attacc.tex
new file mode 100644
index 0000000..6c4d29a
--- /dev/null
+++ b/ACSAC/figures/fig_advdebias_attacc.tex
@@ -0,0 +1,139 @@
+% \begin{figure}[!htb]
+% \centering
+% \begin{minipage}[b]{\linewidth}
+% \centering
+% \subfigure[\census (\race)]{
+% \includegraphics[width=0.48\linewidth]{ACSAC/figures/advdebias/census/census_advdeb_attack_soft_experimental_race.pdf}
+% }%
+% \subfigure[\census (\sex)]{
+% \includegraphics[width=0.48\linewidth]{ACSAC/figures/advdebias/census/census_advdeb_attack_soft_experimental_sex.pdf}
+% }
+% \end{minipage}%
+
+
+% \begin{minipage}[b]{\linewidth}
+% \centering
+% \subfigure[\compas (\race)]{
+% \includegraphics[width=0.48\linewidth]{ACSAC/figures/advdebias/compas/compas_advdeb_attack_soft_experimental_race.pdf}
+% }%
+% \subfigure[\compas (\sex)]{
+% \includegraphics[width=0.48\linewidth]{ACSAC/figures/advdebias/compas/compas_advdeb_attack_soft_experimental_sex.pdf}
+% }
+% \end{minipage}%
+
+% \begin{minipage}[b]{\linewidth}
+% \centering
+% \subfigure[\meps (\race)]{
+% \includegraphics[width=0.48\linewidth]{ACSAC/figures/advdebias/meps/meps_advdeb_attack_soft_experimental_race.pdf}
+% }%
+% \subfigure[\meps (\sex)]{
+% \includegraphics[width=0.48\linewidth]{ACSAC/figures/advdebias/meps/meps_advdeb_attack_soft_experimental_sex.pdf}
+% }
+% \end{minipage}%
+
+% \begin{minipage}[b]{\linewidth}
+% \centering
+% \subfigure[\lfw (\race)]{
+% \includegraphics[width=0.48\linewidth]{ACSAC/figures/advdebias/lfw/lfw_advdeb_attack_soft_experimental_race.pdf}
+% }%
+% \subfigure[\lfw (\sex)]{
+% \includegraphics[width=0.48\linewidth]{ACSAC/figures/advdebias/lfw/lfw_advdeb_attack_soft_experimental_sex.pdf}
+% }
+% \end{minipage}%
+
+% \caption{%For both \adaptiveAIASoft and \adaptiveAIAHard, w
+% We observe that \advdebias reduces the attack accuracy to random guess ($\sim$50\%). %Additionally for \adaptiveAIAHard, the theoretical bound on attack accuracy (``Theory'') matches with the empirical results (``Empirical'').
+% }
+% \label{fig:AdaptAIADebias}
+% \end{figure}
+
+
+
+
+
+\begin{figure*}[!htb]
+ \centering
+ \begin{minipage}[b]{0.49\linewidth}
+ \centering
+ \subfigure[\adaptiveAIASoft: \census (\race)]{
+ \includegraphics[width=0.48\linewidth]{ACSAC/figures/advdebias/census/census_advdeb_attack_soft_experimental_race.pdf}
+ }%
+ \subfigure[\adaptiveAIASoft: \census (\sex)]{
+ \includegraphics[width=0.48\linewidth]{ACSAC/figures/advdebias/census/census_advdeb_attack_soft_experimental_sex.pdf}
+ }
+ \end{minipage}%
+ \begin{minipage}[b]{0.49\linewidth}
+ \centering
+ \subfigure[\adaptiveAIAHard: \census (\race)]{
+ \includegraphics[width=0.48\linewidth]{ACSAC/figures/advdebias/census/census_advdeb_attack_hard_race.pdf}
+ }%
+ \subfigure[\adaptiveAIAHard: \census (\sex)]{
+ \includegraphics[width=0.48\linewidth]{ACSAC/figures/advdebias/census/census_advdeb_attack_hard_sex.pdf}
+ }
+ \end{minipage}\\
+
+
+ \begin{minipage}[b]{0.49\linewidth}
+ \centering
+ \subfigure[\adaptiveAIASoft: \compas (\race)]{
+ \includegraphics[width=0.48\linewidth]{ACSAC/figures/advdebias/compas/compas_advdeb_attack_soft_experimental_race.pdf}
+ }%
+ \subfigure[\adaptiveAIASoft: \compas (\sex)]{
+ \includegraphics[width=0.48\linewidth]{ACSAC/figures/advdebias/compas/compas_advdeb_attack_soft_experimental_sex.pdf}
+ }
+ \end{minipage}%
+ \begin{minipage}[b]{0.49\linewidth}
+ \centering
+ \subfigure[\adaptiveAIAHard: \compas (\race)]{
+ \includegraphics[width=0.48\linewidth]{ACSAC/figures/advdebias/compas/compas_advdeb_attack_hard_race.pdf}
+ }%
+ \subfigure[\adaptiveAIAHard: \compas (\sex)]{
+ \includegraphics[width=0.48\linewidth]{ACSAC/figures/advdebias/compas/compas_advdeb_attack_hard_sex.pdf}
+ }
+ \end{minipage}\\
+
+
+ \begin{minipage}[b]{0.49\linewidth}
+ \centering
+ \subfigure[\adaptiveAIASoft: \meps (\race)]{
+ \includegraphics[width=0.48\linewidth]{ACSAC/figures/advdebias/meps/meps_advdeb_attack_soft_experimental_race.pdf}
+ }%
+ \subfigure[\adaptiveAIASoft: \meps (\sex)]{
+ \includegraphics[width=0.48\linewidth]{ACSAC/figures/advdebias/meps/meps_advdeb_attack_soft_experimental_sex.pdf}
+ }
+ \end{minipage}%
+ \begin{minipage}[b]{0.49\linewidth}
+ \centering
+ \subfigure[\adaptiveAIAHard: \meps (\race)]{
+ \includegraphics[width=0.48\linewidth]{ACSAC/figures/advdebias/meps/meps_advdeb_attack_hard_race.pdf}
+ }%
+ \subfigure[\adaptiveAIAHard: \meps (\sex)]{
+ \includegraphics[width=0.48\linewidth]{ACSAC/figures/advdebias/meps/meps_advdeb_attack_hard_sex.pdf}
+ }
+ \end{minipage}\\
+
+
+ \begin{minipage}[b]{0.49\linewidth}
+ \centering
+ \subfigure[\adaptiveAIASoft: \lfw (\race)]{
+ \includegraphics[width=0.48\linewidth]{ACSAC/figures/advdebias/lfw/lfw_advdeb_attack_soft_experimental_race.pdf}
+ }%
+ \subfigure[\adaptiveAIASoft: \lfw (\sex)]{
+ \includegraphics[width=0.48\linewidth]{ACSAC/figures/advdebias/lfw/lfw_advdeb_attack_soft_experimental_sex.pdf}
+ }
+ \end{minipage}%
+ \begin{minipage}[b]{0.49\linewidth}
+ \centering
+ \subfigure[\adaptiveAIAHard: \lfw (\race)]{
+ \includegraphics[width=0.48\linewidth]{ACSAC/figures/advdebias/lfw/lfw_advdeb_attack_hard_race.pdf}
+ }%
+ \subfigure[\adaptiveAIAHard: \lfw (\sex)]{
+ \includegraphics[width=0.48\linewidth]{ACSAC/figures/advdebias/lfw/lfw_advdeb_attack_hard_sex.pdf}
+ }
+ \end{minipage}
+
+\vspace{-2mm}
+ \caption{For both \adaptiveAIASoft and \adaptiveAIAHard, \advdebias reduces the attack accuracy to random guess ($\sim$50\%). For \adaptiveAIAHard, the theoretical bound on attack accuracy (\theoretical) matches with the empirical results (\empirical).}
+ \label{fig:AdaptAIADebias}
+ \vspace{-2mm}
+\end{figure*}
diff --git a/ACSAC/figures/fig_advdebias_fair.tex b/ACSAC/figures/fig_advdebias_fair.tex
new file mode 100644
index 0000000..42e6835
--- /dev/null
+++ b/ACSAC/figures/fig_advdebias_fair.tex
@@ -0,0 +1,47 @@
+
+\begin{figure}[!htb]
+ \centering
+ \begin{minipage}[b]{1\linewidth}
+ \centering
+ \subfigure[\census (\race)]{
+ \includegraphics[width=0.49\linewidth]{ACSAC/figures/advdebias/census/census_advdeb_dp_lvl_race.pdf}
+ }%
+ \subfigure[\census (\sex)]{
+ \includegraphics[width=0.49\linewidth]{ACSAC/figures/advdebias/census/census_advdeb_dp_lvl_sex.pdf}
+ }
+ \end{minipage}\\
+
+ \begin{minipage}[b]{1\linewidth}
+ \centering
+ \subfigure[\compas (\race)]{
+ \includegraphics[width=0.49\linewidth]{ACSAC/figures/advdebias/compas/compas_advdeb_dp_lvl_race.pdf}
+ }%
+ \subfigure[\compas (\sex)]{
+ \includegraphics[width=0.49\linewidth]{ACSAC/figures/advdebias/compas/compas_advdeb_dp_lvl_sex.pdf}
+ }
+ \end{minipage}\\
+
+ \begin{minipage}[b]{1\linewidth}
+ \centering
+ \subfigure[\meps (\race)]{
+ \includegraphics[width=0.49\linewidth]{ACSAC/figures/advdebias/meps/meps_advdeb_dp_lvl_race.pdf}
+ }%
+ \subfigure[\meps (\sex)]{
+ \includegraphics[width=0.49\linewidth]{ACSAC/figures/advdebias/meps/meps_advdeb_dp_lvl_sex.pdf}
+ }
+ \end{minipage}\\
+
+
+ \begin{minipage}[b]{1\linewidth}
+ \centering
+ \subfigure[\lfw (\race)]{
+ \includegraphics[width=0.49\linewidth]{ACSAC/figures/advdebias/lfw/lfw_advdeb_dp_lvl_race.pdf}
+ }%
+ \subfigure[\lfw (\sex)]{
+ \includegraphics[width=0.49\linewidth]{ACSAC/figures/advdebias/lfw/lfw_advdeb_dp_lvl_sex.pdf}
+ }
+ \end{minipage}
+
+ \caption{\dempar-Level for \advdebias: We observe that \dempar-Level is lower for \advdebias indicating $\targetmodel$ is fair.}
+ \label{fig:DemParAdvDebias2}
+\end{figure} \ No newline at end of file
diff --git a/ACSAC/figures/fig_advdebias_utility.tex b/ACSAC/figures/fig_advdebias_utility.tex
new file mode 100644
index 0000000..0a87115
--- /dev/null
+++ b/ACSAC/figures/fig_advdebias_utility.tex
@@ -0,0 +1,23 @@
+\begin{figure}[!htb]
+ \centering
+ \begin{minipage}[b]{1\linewidth}
+ \centering
+ \subfigure[\census]{
+ \includegraphics[width=0.49\linewidth]{ACSAC/figures/advdebias/census/census_advdeb_utility.pdf}
+ }%
+ \subfigure[\compas]{
+ \includegraphics[width=0.49\linewidth]{ACSAC/figures/advdebias/compas/compas_advdeb_utility.pdf}
+ }
+ \end{minipage}\\
+ \begin{minipage}[b]{1\linewidth}
+ \centering
+ \subfigure[\meps]{
+ \includegraphics[width=0.49\linewidth]{ACSAC/figures/advdebias/meps/meps_advdeb_utility.pdf}
+ }%
+ \subfigure[\lfw]{
+ \includegraphics[width=0.49\linewidth]{ACSAC/figures/advdebias/lfw/lfw_advdeb_utility.pdf}
+ }
+ \end{minipage}
+ \caption{Utility degradation for \advdebias: We observe a statistically significant drop in $\targetmodel$'s accuracy on using \advdebias.}
+ \label{fig:utilityAdvDebias2}
+\end{figure} \ No newline at end of file
diff --git a/ACSAC/figures/fig_egd_attack.tex b/ACSAC/figures/fig_egd_attack.tex
new file mode 100644
index 0000000..8b1c713
--- /dev/null
+++ b/ACSAC/figures/fig_egd_attack.tex
@@ -0,0 +1,50 @@
+
+\begin{figure}[!htb]
+ \centering
+ \begin{minipage}[b]{1\linewidth}
+ \centering
+ \subfigure[\census (\race)]{
+ \includegraphics[width=0.49\linewidth]{ACSAC/figures/egd/census/census_egd_attack_hard_race.pdf}
+ }%
+ \subfigure[\census (\sex)]{
+ \includegraphics[width=0.49\linewidth]{ACSAC/figures/egd/census/census_egd_attack_hard_sex.pdf}
+ }
+ \end{minipage}\\
+
+ \begin{minipage}[b]{1\linewidth}
+ \centering
+ \subfigure[\compas (\race)]{
+ \includegraphics[width=0.49\linewidth]{ACSAC/figures/egd/compas/compas_egd_attack_hard_race.pdf}
+ }%
+ \subfigure[\compas (\sex)]{
+ \includegraphics[width=0.49\linewidth]{ACSAC/figures/egd/compas/compas_egd_attack_hard_sex.pdf}
+ }
+ \end{minipage}\\
+
+ \begin{minipage}[b]{1\linewidth}
+ \centering
+ \subfigure[\meps (\race)]{
+ \includegraphics[width=0.49\linewidth]{ACSAC/figures/egd/meps/meps_egd_attack_hard_race.pdf}
+ }%
+ \subfigure[\meps (\sex)]{
+ \includegraphics[width=0.49\linewidth]{ACSAC/figures/egd/meps/meps_egd_attack_hard_sex.pdf}
+ }
+ \end{minipage}\\
+
+ \begin{minipage}[b]{1\linewidth}
+ \centering
+ \subfigure[\lfw (\race)]{
+ \includegraphics[width=0.49\linewidth]{ACSAC/figures/egd/lfw/lfw_egd_attack_hard_race.pdf}
+ }%
+ \subfigure[\lfw (\sex)]{
+ \includegraphics[width=0.49\linewidth]{ACSAC/figures/egd/lfw/lfw_egd_attack_hard_sex.pdf}
+ }
+ \end{minipage}
+
+ \caption{For \adaptiveAIAHard, we observe that \egd reduces the attack accuracy to random guess ($\sim$50\%). %Additionally, the theoretical bound on attack accuracy (``Theory'') matches with the empirical results (``Empirical'').
+ }
+ \label{fig:AdaptAIAEGD}
+\end{figure}
+
+
+%\textbf{Overall, we observe that using group fairness results in attribute privacy but comes at the cost of $\targetmodel$'s utility.} \ No newline at end of file
diff --git a/ACSAC/figures/fig_egd_fair.tex b/ACSAC/figures/fig_egd_fair.tex
new file mode 100644
index 0000000..bed88b8
--- /dev/null
+++ b/ACSAC/figures/fig_egd_fair.tex
@@ -0,0 +1,46 @@
+
+\begin{figure}[!htb]
+ \centering
+ \begin{minipage}[b]{1\linewidth}
+ \centering
+ \subfigure[\census (\race)]{
+ \includegraphics[width=0.49\linewidth]{ACSAC/figures/egd/census/census_egd_dp_lvl_race.pdf}
+ }%
+ \subfigure[\census (\sex)]{
+ \includegraphics[width=0.49\linewidth]{ACSAC/figures/egd/census/census_egd_dp_lvl_sex.pdf}
+ }
+ \end{minipage}\\
+
+ \begin{minipage}[b]{1\linewidth}
+ \centering
+ \subfigure[\compas (\race)]{
+ \includegraphics[width=0.49\linewidth]{ACSAC/figures/egd/compas/compas_egd_dp_lvl_race.pdf}
+ }%
+ \subfigure[\compas (\sex)]{
+ \includegraphics[width=0.49\linewidth]{ACSAC/figures/egd/compas/compas_egd_dp_lvl_sex.pdf}
+ }
+ \end{minipage}\\
+
+ \begin{minipage}[b]{1\linewidth}
+ \centering
+ \subfigure[\meps (\race)]{
+ \includegraphics[width=0.49\linewidth]{ACSAC/figures/egd/meps/meps_egd_dp_lvl_race.pdf}
+ }%
+ \subfigure[\meps (\sex)]{
+ \includegraphics[width=0.49\linewidth]{ACSAC/figures/egd/meps/meps_egd_dp_lvl_sex.pdf}
+ }
+ \end{minipage}\\
+
+ \begin{minipage}[b]{1\linewidth}
+ \centering
+ \subfigure[\lfw (\race)]{
+ \includegraphics[width=0.49\linewidth]{ACSAC/figures/egd/lfw/lfw_egd_dp_lvl_race.pdf}
+ }%
+ \subfigure[\lfw (\sex)]{
+ \includegraphics[width=0.49\linewidth]{ACSAC/figures/egd/lfw/lfw_egd_dp_lvl_sex.pdf}
+ }
+ \end{minipage}
+
+ \caption{\dempar-Level for \egd: We observe that \dempar-Level is lower for \egd than the baseline indicating $\targetmodel$ is fair after \egd.}
+ \label{fig:DemParegd2}
+\end{figure} \ No newline at end of file
diff --git a/ACSAC/figures/fig_egd_utility.tex b/ACSAC/figures/fig_egd_utility.tex
new file mode 100644
index 0000000..36ae32a
--- /dev/null
+++ b/ACSAC/figures/fig_egd_utility.tex
@@ -0,0 +1,20 @@
+\begin{figure}[!htb]
+ \centering
+ \begin{minipage}[b]{1\linewidth}
+ \centering
+ \subfigure[\census]{
+ \includegraphics[width=0.49\linewidth]{ACSAC/figures/egd/census/census_egd_utility.pdf}
+ }%
+ \subfigure[\compas]{
+ \includegraphics[width=0.49\linewidth]{ACSAC/figures/egd/compas/compas_egd_utility.pdf}
+ }\\
+ \subfigure[\meps]{
+ \includegraphics[width=0.49\linewidth]{ACSAC/figures/egd/meps/meps_egd_utility.pdf}
+ }%
+ \subfigure[\lfw]{
+ \includegraphics[width=0.49\linewidth]{ACSAC/figures/egd/lfw/lfw_egd_utility.pdf}
+ }
+ \end{minipage}
+ \caption{Utility degradation for \egd: We observe a statistically significant drop in $\targetmodel$'s accuracy on using \egddp which matches the observation from prior work~\cite{reductions}.}
+ \label{fig:utilityEGD}
+\end{figure} \ No newline at end of file
diff --git a/ACSAC/figures/fig_tm2.tex b/ACSAC/figures/fig_tm2.tex
new file mode 100644
index 0000000..9cf489b
--- /dev/null
+++ b/ACSAC/figures/fig_tm2.tex
@@ -0,0 +1,47 @@
+\begin{figure}[t]
+\centering
+\resizebox{.68\textwidth}{!}{%
+\begin{tikzpicture}
+
+ \node [rectangle,draw,thick,minimum width=1.5cm, minimum height=0.75cm] (targetmodel) {$\targetmodel$};
+
+ \node[below of=targetmodel,yshift=-0.3cm,database,database radius=0.4cm,database segment height=0.2cm, label={below:\footnotesize $\traindata: (X, Y)$}] (trainingdata) {};
+
+ \node [left of=targetmodel,minimum width=0.75cm,xshift=-0.8cm,fill=red!20,rectangle,draw,thick,label={below:\footnotesize Input}] (inputrecord) {$X'(\omega)$};
+ \node [right of=targetmodel,xshift=1.5cm,rectangle,draw,thick] (outputpred) {$\targetmodel(X'(\omega))$};
+ % \node [below of=outputpred,minimum width=1.5cm,rectangle,draw,thick] (explanation) {$\phi(x)$};
+
+ \begin{scope}[on background layer]
+ \node (tm1) [fit=(targetmodel) (trainingdata), fill= gray!20, rounded corners, inner sep=0.1cm, label={above:\footnotesize }] {};
+ \end{scope}
+
+ \node [right of=outputpred,rectangle,draw,thick,minimum width=1.5cm, minimum height=0.75cm,xshift=1.2cm,fill= gray!20] (attmodel) {$\attackmodel$};
+
+ \node [right of=attmodel,xshift=0.6cm,minimum width=0.75cm,rectangle,draw,thick] (attout) {$S(\omega)$};
+
+ \node[below of=attmodel,database,database radius=0.4cm,database segment height=0.2cm,yshift=-0.3cm, label={below:\footnotesize $\auxdata: (X', Y', S')$}] (auxdata) {};
+
+\begin{scope}[on background layer]
+ \node (models) [fit=(attmodel) (outputpred) (attout) (auxdata), fill= red!20, rounded corners, inner sep=0.1cm] {};
+\end{scope}
+
+
+\draw[->,ultra thick] (inputrecord.east) -- node[anchor=south, align=center] {\em\footnotesize } (targetmodel.west);
+\draw[->,ultra thick] (targetmodel.east) -- node[anchor=south, align=center] {\em\footnotesize } (outputpred.west);
+% \draw[->,ultra thick] (targetmodel.east) -- node[anchor=south, align=center] {\em\footnotesize } (explanation.west);
+
+
+\draw[->,ultra thick, dashed] (outputpred.east) -- node[anchor=south, align=center] {\em\footnotesize } (attmodel.west);
+% \draw[->,ultra thick, dashed] (explanation.east) -- node[anchor=south, align=center] {\em\footnotesize } (attmodel.west);
+\draw[->,ultra thick] (attmodel.east) -- node[anchor=south, align=center] {\em\footnotesize } (attout.west);
+\draw[->,ultra thick,dashed] (trainingdata.north) -- node[anchor=south, align=center,label={[yshift=-0.2cm]right:\footnotesize Train}] {\em\footnotesize } (targetmodel.south);
+\draw[->,ultra thick,dashed] (auxdata.north) -- node[anchor=south, align=center,label={[yshift=-0.2cm]right:\footnotesize Train}] {\em\footnotesize } (attmodel.south);
+
+
+\end{tikzpicture}
+}
+\vspace{-1mm}
+\caption{\adv wants to infer sensitive attributes for an input given its prediction. \adv trains $\attackmodel$ on $\auxdata$ to map $\targetmodel(X'(\omega))$ to $S'(\omega)$. Once trained, \adv only uses $\targetmodel$'s outputs as input to $\attackmodel$ to infer sensitive attributes. \colorbox{red!20}{red} indicates accessible by \adv.}
+\vspace{-1mm}
+\label{fig:tm2}
+\end{figure} \ No newline at end of file
diff --git a/ACSAC/figures/old_distrib.pdf b/ACSAC/figures/old_distrib.pdf
new file mode 100644
index 0000000..5745c6a
--- /dev/null
+++ b/ACSAC/figures/old_distrib.pdf
Binary files differ
diff --git a/ACSAC/image/BaVsState.pdf b/ACSAC/image/BaVsState.pdf
new file mode 100644
index 0000000..57bf28b
--- /dev/null
+++ b/ACSAC/image/BaVsState.pdf
Binary files differ
diff --git a/ACSAC/image/annexe/attack/CENSUS/race.pdf b/ACSAC/image/annexe/attack/CENSUS/race.pdf
new file mode 100644
index 0000000..4b0e218
--- /dev/null
+++ b/ACSAC/image/annexe/attack/CENSUS/race.pdf
Binary files differ
diff --git a/ACSAC/image/annexe/attack/CENSUS/sex.pdf b/ACSAC/image/annexe/attack/CENSUS/sex.pdf
new file mode 100644
index 0000000..208a968
--- /dev/null
+++ b/ACSAC/image/annexe/attack/CENSUS/sex.pdf
Binary files differ
diff --git a/ACSAC/image/annexe/attack/COMPAS/race.pdf b/ACSAC/image/annexe/attack/COMPAS/race.pdf
new file mode 100644
index 0000000..9ecf1b5
--- /dev/null
+++ b/ACSAC/image/annexe/attack/COMPAS/race.pdf
Binary files differ
diff --git a/ACSAC/image/annexe/attack/COMPAS/sex.pdf b/ACSAC/image/annexe/attack/COMPAS/sex.pdf
new file mode 100644
index 0000000..c1e3341
--- /dev/null
+++ b/ACSAC/image/annexe/attack/COMPAS/sex.pdf
Binary files differ
diff --git a/ACSAC/image/annexe/attack/CREDIT/race.pdf b/ACSAC/image/annexe/attack/CREDIT/race.pdf
new file mode 100644
index 0000000..cf0d985
--- /dev/null
+++ b/ACSAC/image/annexe/attack/CREDIT/race.pdf
Binary files differ
diff --git a/ACSAC/image/annexe/attack/CREDIT/sex.pdf b/ACSAC/image/annexe/attack/CREDIT/sex.pdf
new file mode 100644
index 0000000..6131c4d
--- /dev/null
+++ b/ACSAC/image/annexe/attack/CREDIT/sex.pdf
Binary files differ
diff --git a/ACSAC/image/annexe/attack/LAW/race.pdf b/ACSAC/image/annexe/attack/LAW/race.pdf
new file mode 100644
index 0000000..ce0d185
--- /dev/null
+++ b/ACSAC/image/annexe/attack/LAW/race.pdf
Binary files differ
diff --git a/ACSAC/image/annexe/attack/LAW/sex.pdf b/ACSAC/image/annexe/attack/LAW/sex.pdf
new file mode 100644
index 0000000..63c9ef9
--- /dev/null
+++ b/ACSAC/image/annexe/attack/LAW/sex.pdf
Binary files differ
diff --git a/ACSAC/image/annexe/attack/MEPS/race.pdf b/ACSAC/image/annexe/attack/MEPS/race.pdf
new file mode 100644
index 0000000..648ae2c
--- /dev/null
+++ b/ACSAC/image/annexe/attack/MEPS/race.pdf
Binary files differ
diff --git a/ACSAC/image/annexe/attack/MEPS/sex.pdf b/ACSAC/image/annexe/attack/MEPS/sex.pdf
new file mode 100644
index 0000000..a94f7c3
--- /dev/null
+++ b/ACSAC/image/annexe/attack/MEPS/sex.pdf
Binary files differ
diff --git a/ACSAC/image/annexe/mia/CENSUS/race.pdf b/ACSAC/image/annexe/mia/CENSUS/race.pdf
new file mode 100644
index 0000000..1001685
--- /dev/null
+++ b/ACSAC/image/annexe/mia/CENSUS/race.pdf
Binary files differ
diff --git a/ACSAC/image/annexe/mia/CENSUS/sex.pdf b/ACSAC/image/annexe/mia/CENSUS/sex.pdf
new file mode 100644
index 0000000..1949e07
--- /dev/null
+++ b/ACSAC/image/annexe/mia/CENSUS/sex.pdf
Binary files differ
diff --git a/ACSAC/image/annexe/mia/COMPAS/race.pdf b/ACSAC/image/annexe/mia/COMPAS/race.pdf
new file mode 100644
index 0000000..485cf2d
--- /dev/null
+++ b/ACSAC/image/annexe/mia/COMPAS/race.pdf
Binary files differ
diff --git a/ACSAC/image/annexe/mia/COMPAS/sex.pdf b/ACSAC/image/annexe/mia/COMPAS/sex.pdf
new file mode 100644
index 0000000..9cda8f1
--- /dev/null
+++ b/ACSAC/image/annexe/mia/COMPAS/sex.pdf
Binary files differ
diff --git a/ACSAC/image/annexe/mia/CREDIT/race.pdf b/ACSAC/image/annexe/mia/CREDIT/race.pdf
new file mode 100644
index 0000000..c66c7db
--- /dev/null
+++ b/ACSAC/image/annexe/mia/CREDIT/race.pdf
Binary files differ
diff --git a/ACSAC/image/annexe/mia/CREDIT/sex.pdf b/ACSAC/image/annexe/mia/CREDIT/sex.pdf
new file mode 100644
index 0000000..0e23b28
--- /dev/null
+++ b/ACSAC/image/annexe/mia/CREDIT/sex.pdf
Binary files differ
diff --git a/ACSAC/image/annexe/mia/LAW/race.pdf b/ACSAC/image/annexe/mia/LAW/race.pdf
new file mode 100644
index 0000000..816a359
--- /dev/null
+++ b/ACSAC/image/annexe/mia/LAW/race.pdf
Binary files differ
diff --git a/ACSAC/image/annexe/mia/LAW/sex.pdf b/ACSAC/image/annexe/mia/LAW/sex.pdf
new file mode 100644
index 0000000..c61cb49
--- /dev/null
+++ b/ACSAC/image/annexe/mia/LAW/sex.pdf
Binary files differ
diff --git a/ACSAC/image/annexe/mia/MEPS/race.pdf b/ACSAC/image/annexe/mia/MEPS/race.pdf
new file mode 100644
index 0000000..7410a4b
--- /dev/null
+++ b/ACSAC/image/annexe/mia/MEPS/race.pdf
Binary files differ
diff --git a/ACSAC/image/annexe/mia/MEPS/sex.pdf b/ACSAC/image/annexe/mia/MEPS/sex.pdf
new file mode 100644
index 0000000..af13850
--- /dev/null
+++ b/ACSAC/image/annexe/mia/MEPS/sex.pdf
Binary files differ
diff --git a/ACSAC/image/annexe/utility/CENSUS/race.pdf b/ACSAC/image/annexe/utility/CENSUS/race.pdf
new file mode 100644
index 0000000..7de3e85
--- /dev/null
+++ b/ACSAC/image/annexe/utility/CENSUS/race.pdf
Binary files differ
diff --git a/ACSAC/image/annexe/utility/CENSUS/sex.pdf b/ACSAC/image/annexe/utility/CENSUS/sex.pdf
new file mode 100644
index 0000000..fcde46c
--- /dev/null
+++ b/ACSAC/image/annexe/utility/CENSUS/sex.pdf
Binary files differ
diff --git a/ACSAC/image/annexe/utility/COMPAS/race.pdf b/ACSAC/image/annexe/utility/COMPAS/race.pdf
new file mode 100644
index 0000000..b3818ba
--- /dev/null
+++ b/ACSAC/image/annexe/utility/COMPAS/race.pdf
Binary files differ
diff --git a/ACSAC/image/annexe/utility/COMPAS/sex.pdf b/ACSAC/image/annexe/utility/COMPAS/sex.pdf
new file mode 100644
index 0000000..71d6d1b
--- /dev/null
+++ b/ACSAC/image/annexe/utility/COMPAS/sex.pdf
Binary files differ
diff --git a/ACSAC/image/annexe/utility/CREDIT/race.pdf b/ACSAC/image/annexe/utility/CREDIT/race.pdf
new file mode 100644
index 0000000..c3bca9f
--- /dev/null
+++ b/ACSAC/image/annexe/utility/CREDIT/race.pdf
Binary files differ
diff --git a/ACSAC/image/annexe/utility/CREDIT/sex.pdf b/ACSAC/image/annexe/utility/CREDIT/sex.pdf
new file mode 100644
index 0000000..a1c5a11
--- /dev/null
+++ b/ACSAC/image/annexe/utility/CREDIT/sex.pdf
Binary files differ
diff --git a/ACSAC/image/annexe/utility/LAW/race.pdf b/ACSAC/image/annexe/utility/LAW/race.pdf
new file mode 100644
index 0000000..49495fa
--- /dev/null
+++ b/ACSAC/image/annexe/utility/LAW/race.pdf
Binary files differ
diff --git a/ACSAC/image/annexe/utility/LAW/sex.pdf b/ACSAC/image/annexe/utility/LAW/sex.pdf
new file mode 100644
index 0000000..e490f3e
--- /dev/null
+++ b/ACSAC/image/annexe/utility/LAW/sex.pdf
Binary files differ
diff --git a/ACSAC/image/annexe/utility/MEPS/race.pdf b/ACSAC/image/annexe/utility/MEPS/race.pdf
new file mode 100644
index 0000000..ec0a395
--- /dev/null
+++ b/ACSAC/image/annexe/utility/MEPS/race.pdf
Binary files differ
diff --git a/ACSAC/image/annexe/utility/MEPS/sex.pdf b/ACSAC/image/annexe/utility/MEPS/sex.pdf
new file mode 100644
index 0000000..04112fe
--- /dev/null
+++ b/ACSAC/image/annexe/utility/MEPS/sex.pdf
Binary files differ
diff --git a/ACSAC/image/dpvseoo.pdf b/ACSAC/image/dpvseoo.pdf
new file mode 100644
index 0000000..a9fec18
--- /dev/null
+++ b/ACSAC/image/dpvseoo.pdf
Binary files differ
diff --git a/ACSAC/image/hardvsdef.pdf b/ACSAC/image/hardvsdef.pdf
new file mode 100644
index 0000000..0df8814
--- /dev/null
+++ b/ACSAC/image/hardvsdef.pdf
Binary files differ
diff --git a/ACSAC/image/miaeoo.pdf b/ACSAC/image/miaeoo.pdf
new file mode 100644
index 0000000..fff1e97
--- /dev/null
+++ b/ACSAC/image/miaeoo.pdf
Binary files differ
diff --git a/ACSAC/image/rfvsnn.pdf b/ACSAC/image/rfvsnn.pdf
new file mode 100644
index 0000000..c4476bb
--- /dev/null
+++ b/ACSAC/image/rfvsnn.pdf
Binary files differ
diff --git a/ACSAC/image/roc.pdf b/ACSAC/image/roc.pdf
new file mode 100644
index 0000000..ea77206
--- /dev/null
+++ b/ACSAC/image/roc.pdf
Binary files differ
diff --git a/ACSAC/llncs.cls b/ACSAC/llncs.cls
new file mode 100644
index 0000000..ea17bb3
--- /dev/null
+++ b/ACSAC/llncs.cls
@@ -0,0 +1,1244 @@
+% LLNCS DOCUMENT CLASS -- version 2.24 (29-Jan-2024)
+% Springer Verlag LaTeX2e support for Lecture Notes in Computer Science
+%
+%%
+%% \CharacterTable
+%% {Upper-case \A\B\C\D\E\F\G\H\I\J\K\L\M\N\O\P\Q\R\S\T\U\V\W\X\Y\Z
+%% Lower-case \a\b\c\d\e\f\g\h\i\j\k\l\m\n\o\p\q\r\s\t\u\v\w\x\y\z
+%% Digits \0\1\2\3\4\5\6\7\8\9
+%% Exclamation \! Double quote \" Hash (number) \#
+%% Dollar \$ Percent \% Ampersand \&
+%% Acute accent \' Left paren \( Right paren \)
+%% Asterisk \* Plus \+ Comma \,
+%% Minus \- Point \. Solidus \/
+%% Colon \: Semicolon \; Less than \<
+%% Equals \= Greater than \> Question mark \?
+%% Commercial at \@ Left bracket \[ Backslash \\
+%% Right bracket \] Circumflex \^ Underscore \_
+%% Grave accent \` Left brace \{ Vertical bar \|
+%% Right brace \} Tilde \~}
+%%
+\NeedsTeXFormat{LaTeX2e}[1995/12/01]
+\ProvidesClass{llncs}[2024/01/29 v2.24
+^^J LaTeX document class for Lecture Notes in Computer Science]
+% Options
+\let\if@envcntreset\iffalse
+\DeclareOption{envcountreset}{\let\if@envcntreset\iftrue}
+\DeclareOption{citeauthoryear}{\let\citeauthoryear=Y}
+\DeclareOption{oribibl}{\let\oribibl=Y}
+\let\if@custvec\iftrue
+\DeclareOption{orivec}{\let\if@custvec\iffalse}
+\let\if@envcntsame\iffalse
+\DeclareOption{envcountsame}{\let\if@envcntsame\iftrue}
+\let\if@envcntsect\iffalse
+\DeclareOption{envcountsect}{\let\if@envcntsect\iftrue}
+\let\if@runhead\iffalse
+\DeclareOption{runningheads}{\let\if@runhead\iftrue}
+
+\let\if@openright\iftrue
+\let\if@openbib\iffalse
+\DeclareOption{openbib}{\let\if@openbib\iftrue}
+
+% languages
+\let\switcht@@therlang\relax
+\def\ds@deutsch{\def\switcht@@therlang{\switcht@deutsch}}
+\def\ds@francais{\def\switcht@@therlang{\switcht@francais}}
+
+\DeclareOption*{\PassOptionsToClass{\CurrentOption}{article}}
+
+\ProcessOptions
+
+\LoadClass[twoside]{article}
+\RequirePackage{multicol} % needed for the list of participants, index
+\RequirePackage{aliascnt}
+
+\setlength{\textwidth}{12.2cm}
+\setlength{\textheight}{19.3cm}
+\renewcommand\@pnumwidth{2em}
+\renewcommand\@tocrmarg{3.5em}
+%
+\def\@dottedtocline#1#2#3#4#5{%
+ \ifnum #1>\c@tocdepth \else
+ \vskip \z@ \@plus.2\p@
+ {\leftskip #2\relax \rightskip \@tocrmarg \advance\rightskip by 0pt plus 2cm
+ \parfillskip -\rightskip \pretolerance=10000
+ \parindent #2\relax\@afterindenttrue
+ \interlinepenalty\@M
+ \leavevmode
+ \@tempdima #3\relax
+ \advance\leftskip \@tempdima \null\nobreak\hskip -\leftskip
+ {#4}\nobreak
+ \leaders\hbox{$\m@th
+ \mkern \@dotsep mu\hbox{.}\mkern \@dotsep
+ mu$}\hfill
+ \nobreak
+ \hb@xt@\@pnumwidth{\hfil\normalfont \normalcolor #5}%
+ \par}%
+ \fi}
+%
+\def\switcht@albion{%
+\def\abstractname{Abstract.}
+\def\ackname{Acknowledgments.}
+\def\andname{and}
+\def\lastandname{\unskip, and}
+\def\appendixname{Appendix}
+\def\chaptername{Chapter}
+\def\claimname{Claim}
+\def\conjecturename{Conjecture}
+\def\contentsname{Table of Contents}
+\def\corollaryname{Corollary}
+\def\definitionname{Definition}
+\def\discintname{Disclosure of Interests.}
+\def\examplename{Example}
+\def\exercisename{Exercise}
+\def\figurename{Fig.}
+\def\keywordname{{\bf Keywords:}}
+\def\indexname{Index}
+\def\lemmaname{Lemma}
+\def\contriblistname{List of Contributors}
+\def\listfigurename{List of Figures}
+\def\listtablename{List of Tables}
+\def\mailname{{\it Correspondence to\/}:}
+\def\noteaddname{Note added in proof}
+\def\notename{Note}
+\def\partname{Part}
+\def\problemname{Problem}
+\def\proofname{Proof}
+\def\propertyname{Property}
+\def\propositionname{Proposition}
+\def\questionname{Question}
+\def\remarkname{Remark}
+\def\seename{see}
+\def\solutionname{Solution}
+\def\subclassname{{\it Subject Classifications\/}:}
+\def\tablename{Table}
+\def\theoremname{Theorem}}
+\switcht@albion
+% Names of theorem like environments are already defined
+% but must be translated if another language is chosen
+%
+% French section
+\def\switcht@francais{%\typeout{On parle francais.}%
+ \def\abstractname{R\'esum\'e.}%
+ \def\ackname{Remerciements.}%
+ \def\andname{et}%
+ \def\lastandname{ et}%
+ \def\appendixname{Appendice}%
+ \def\chaptername{Chapitre}%
+ \def\claimname{Pr\'etention}%
+ \def\conjecturename{Hypoth\`ese}%
+ \def\contentsname{Table des mati\`eres}%
+ \def\corollaryname{Corollaire}%
+ \def\definitionname{D\'efinition}%
+ \def\discintname{Mention des Int\'{e}r\^{e}ts.}
+ \def\examplename{Exemple}%
+ \def\exercisename{Exercice}%
+ \def\figurename{Fig.}%
+ \def\keywordname{{\bf Mots-cl\'e:}}%
+ \def\indexname{Index}%
+ \def\lemmaname{Lemme}%
+ \def\contriblistname{Liste des contributeurs}%
+ \def\listfigurename{Liste des figures}%
+ \def\listtablename{Liste des tables}%
+ \def\mailname{{\it Correspondence to\/}:}%
+ \def\noteaddname{Note ajout\'ee \`a l'\'epreuve}%
+ \def\notename{Remarque}%
+ \def\partname{Partie}%
+ \def\problemname{Probl\`eme}%
+ \def\proofname{Preuve}%
+ \def\propertyname{Caract\'eristique}%
+%\def\propositionname{Proposition}%
+ \def\questionname{Question}%
+ \def\remarkname{Remarque}%
+ \def\seename{voir}%
+ \def\solutionname{Solution}%
+ \def\subclassname{{\it Subject Classifications\/}:}%
+ \def\tablename{Tableau}%
+ \def\theoremname{Th\'eor\`eme}%
+}
+%
+% German section
+\def\switcht@deutsch{%\typeout{Man spricht deutsch.}%
+ \def\abstractname{Zusammenfassung.}%
+ \def\ackname{Danksagung.}%
+ \def\andname{und}%
+ \def\lastandname{ und}%
+ \def\appendixname{Anhang}%
+ \def\chaptername{Kapitel}%
+ \def\claimname{Behauptung}%
+ \def\conjecturename{Hypothese}%
+ \def\contentsname{Inhaltsverzeichnis}%
+ \def\corollaryname{Korollar}%
+%\def\definitionname{Definition}%
+ \def\discintname{Offenlegung von Interessen.}
+ \def\examplename{Beispiel}%
+ \def\exercisename{\"Ubung}%
+ \def\figurename{Abb.}%
+ \def\keywordname{{\bf Schl\"usselw\"orter:}}%
+ \def\indexname{Index}%
+%\def\lemmaname{Lemma}%
+ \def\contriblistname{Mitarbeiter}%
+ \def\listfigurename{Abbildungsverzeichnis}%
+ \def\listtablename{Tabellenverzeichnis}%
+ \def\mailname{{\it Correspondence to\/}:}%
+ \def\noteaddname{Nachtrag}%
+ \def\notename{Anmerkung}%
+ \def\partname{Teil}%
+%\def\problemname{Problem}%
+ \def\proofname{Beweis}%
+ \def\propertyname{Eigenschaft}%
+%\def\propositionname{Proposition}%
+ \def\questionname{Frage}%
+ \def\remarkname{Anmerkung}%
+ \def\seename{siehe}%
+ \def\solutionname{L\"osung}%
+ \def\subclassname{{\it Subject Classifications\/}:}%
+ \def\tablename{Tabelle}%
+%\def\theoremname{Theorem}%
+}
+
+% Ragged bottom for the actual page
+\def\thisbottomragged{\def\@textbottom{\vskip\z@ plus.0001fil
+\global\let\@textbottom\relax}}
+
+\renewcommand\small{%
+ \@setfontsize\small\@ixpt{11}%
+ \abovedisplayskip 8.5\p@ \@plus3\p@ \@minus4\p@
+ \abovedisplayshortskip \z@ \@plus2\p@
+ \belowdisplayshortskip 4\p@ \@plus2\p@ \@minus2\p@
+ \def\@listi{\leftmargin\leftmargini
+ \parsep 0\p@ \@plus1\p@ \@minus\p@
+ \topsep 8\p@ \@plus2\p@ \@minus4\p@
+ \itemsep0\p@}%
+ \belowdisplayskip \abovedisplayskip
+}
+
+% Switch to small font size for the credits at the end of the paper
+% (i.e. Acknowlegments and Disclosure of Interests)
+\newenvironment{credits}{%
+\begingroup\small%
+\renewcommand\subsubsection{\@startsection{subsubsection}{3}{\z@}%
+ {-12\p@ \@plus -4\p@ \@minus -4\p@}%
+ {-0.5em \@plus -0.22em \@minus -0.1em}%
+ {\normalfont\small\bfseries\boldmath}}
+\renewcommand\paragraph{\@startsection{paragraph}{4}{\z@}%
+ {-8\p@ \@plus -4\p@ \@minus -4\p@}%
+ {-0.5em \@plus -0.22em \@minus -0.1em}%
+ {\normalfont\small\itshape}}%
+}{\endgroup}
+
+\frenchspacing
+\widowpenalty=10000
+\clubpenalty=10000
+
+\setlength\oddsidemargin {63\p@}
+\setlength\evensidemargin {63\p@}
+\setlength\marginparwidth {90\p@}
+
+\setlength\headsep {16\p@}
+
+\setlength\footnotesep{7.7\p@}
+\setlength\textfloatsep{8mm\@plus 2\p@ \@minus 4\p@}
+\setlength\intextsep {8mm\@plus 2\p@ \@minus 2\p@}
+
+\setcounter{secnumdepth}{2}
+
+\newcounter {chapter}
+\renewcommand\thechapter {\@arabic\c@chapter}
+
+\newif\if@mainmatter \@mainmattertrue
+\newcommand\frontmatter{\cleardoublepage
+ \@mainmatterfalse\pagenumbering{Roman}}
+\newcommand\mainmatter{\cleardoublepage
+ \@mainmattertrue\pagenumbering{arabic}}
+\newcommand\backmatter{\if@openright\cleardoublepage\else\clearpage\fi
+ \@mainmatterfalse}
+
+\renewcommand\part{\cleardoublepage
+ \thispagestyle{empty}%
+ \if@twocolumn
+ \onecolumn
+ \@tempswatrue
+ \else
+ \@tempswafalse
+ \fi
+ \null\vfil
+ \secdef\@part\@spart}
+
+\def\@part[#1]#2{%
+ \ifnum \c@secnumdepth >-2\relax
+ \refstepcounter{part}%
+ \addcontentsline{toc}{part}{\thepart\hspace{1em}#1}%
+ \else
+ \addcontentsline{toc}{part}{#1}%
+ \fi
+ \markboth{}{}%
+ {\centering
+ \interlinepenalty \@M
+ \normalfont
+ \ifnum \c@secnumdepth >-2\relax
+ \huge\bfseries \partname~\thepart
+ \par
+ \vskip 20\p@
+ \fi
+ \Huge \bfseries #2\par}%
+ \@endpart}
+\def\@spart#1{%
+ {\centering
+ \interlinepenalty \@M
+ \normalfont
+ \Huge \bfseries #1\par}%
+ \@endpart}
+\def\@endpart{\vfil\newpage
+ \if@twoside
+ \null
+ \thispagestyle{empty}%
+ \newpage
+ \fi
+ \if@tempswa
+ \twocolumn
+ \fi}
+
+\newcommand\chapter{\clearpage
+ \thispagestyle{empty}%
+ \global\@topnum\z@
+ \@afterindentfalse
+ \secdef\@chapter\@schapter}
+\def\@chapter[#1]#2{\ifnum \c@secnumdepth >\m@ne
+ \if@mainmatter
+ \refstepcounter{chapter}%
+ \typeout{\@chapapp\space\thechapter.}%
+ \addcontentsline{toc}{chapter}%
+ {\protect\numberline{\thechapter}#1}%
+ \else
+ \addcontentsline{toc}{chapter}{#1}%
+ \fi
+ \else
+ \addcontentsline{toc}{chapter}{#1}%
+ \fi
+ \chaptermark{#1}%
+ \addtocontents{lof}{\protect\addvspace{10\p@}}%
+ \addtocontents{lot}{\protect\addvspace{10\p@}}%
+ \if@twocolumn
+ \@topnewpage[\@makechapterhead{#2}]%
+ \else
+ \@makechapterhead{#2}%
+ \@afterheading
+ \fi}
+\def\@makechapterhead#1{%
+% \vspace*{50\p@}%
+ {\centering
+ \ifnum \c@secnumdepth >\m@ne
+ \if@mainmatter
+ \large\bfseries \@chapapp{} \thechapter
+ \par\nobreak
+ \vskip 20\p@
+ \fi
+ \fi
+ \interlinepenalty\@M
+ \Large \bfseries #1\par\nobreak
+ \vskip 40\p@
+ }}
+\def\@schapter#1{\if@twocolumn
+ \@topnewpage[\@makeschapterhead{#1}]%
+ \else
+ \@makeschapterhead{#1}%
+ \@afterheading
+ \fi}
+\def\@makeschapterhead#1{%
+% \vspace*{50\p@}%
+ {\centering
+ \normalfont
+ \interlinepenalty\@M
+ \Large \bfseries #1\par\nobreak
+ \vskip 40\p@
+ }}
+
+\renewcommand\section{\@startsection{section}{1}{\z@}%
+ {-18\p@ \@plus -4\p@ \@minus -4\p@}%
+ {12\p@ \@plus 4\p@ \@minus 4\p@}%
+ {\normalfont\large\bfseries\boldmath
+ \rightskip=\z@ \@plus 8em\pretolerance=10000 }}
+\renewcommand\subsection{\@startsection{subsection}{2}{\z@}%
+ {-18\p@ \@plus -4\p@ \@minus -4\p@}%
+ {8\p@ \@plus 4\p@ \@minus 4\p@}%
+ {\normalfont\normalsize\bfseries\boldmath
+ \rightskip=\z@ \@plus 8em\pretolerance=10000 }}
+\renewcommand\subsubsection{\@startsection{subsubsection}{3}{\z@}%
+ {-18\p@ \@plus -4\p@ \@minus -4\p@}%
+ {-0.5em \@plus -0.22em \@minus -0.1em}%
+ {\normalfont\normalsize\bfseries\boldmath}}
+\renewcommand\paragraph{\@startsection{paragraph}{4}{\z@}%
+ {-12\p@ \@plus -4\p@ \@minus -4\p@}%
+ {-0.5em \@plus -0.22em \@minus -0.1em}%
+ {\normalfont\normalsize\itshape}}
+\renewcommand\subparagraph[1]{\typeout{LLNCS warning: You should not use
+ \string\subparagraph\space with this class}\vskip0.5cm
+You should not use \verb|\subparagraph| with this class.\vskip0.5cm}
+
+\DeclareMathSymbol{\Gamma}{\mathalpha}{letters}{"00}
+\DeclareMathSymbol{\Delta}{\mathalpha}{letters}{"01}
+\DeclareMathSymbol{\Theta}{\mathalpha}{letters}{"02}
+\DeclareMathSymbol{\Lambda}{\mathalpha}{letters}{"03}
+\DeclareMathSymbol{\Xi}{\mathalpha}{letters}{"04}
+\DeclareMathSymbol{\Pi}{\mathalpha}{letters}{"05}
+\DeclareMathSymbol{\Sigma}{\mathalpha}{letters}{"06}
+\DeclareMathSymbol{\Upsilon}{\mathalpha}{letters}{"07}
+\DeclareMathSymbol{\Phi}{\mathalpha}{letters}{"08}
+\DeclareMathSymbol{\Psi}{\mathalpha}{letters}{"09}
+\DeclareMathSymbol{\Omega}{\mathalpha}{letters}{"0A}
+
+\let\footnotesize\small
+
+\if@custvec
+\DeclareRobustCommand\vec[1]{\mathchoice{\mbox{\boldmath$\displaystyle#1$}}
+{\mbox{\boldmath$\textstyle#1$}}
+{\mbox{\boldmath$\scriptstyle#1$}}
+{\mbox{\boldmath$\scriptscriptstyle#1$}}}
+\fi
+
+\def\squareforqed{\hbox{\rlap{$\sqcap$}$\sqcup$}}
+\def\qed{\ifmmode\squareforqed\else{\unskip\nobreak\hfil
+\penalty50\hskip1em\null\nobreak\hfil\squareforqed
+\parfillskip=0pt\finalhyphendemerits=0\endgraf}\fi}
+
+\def\getsto{\mathrel{\mathchoice {\vcenter{\offinterlineskip
+\halign{\hfil
+$\displaystyle##$\hfil\cr\gets\cr\to\cr}}}
+{\vcenter{\offinterlineskip\halign{\hfil$\textstyle##$\hfil\cr\gets
+\cr\to\cr}}}
+{\vcenter{\offinterlineskip\halign{\hfil$\scriptstyle##$\hfil\cr\gets
+\cr\to\cr}}}
+{\vcenter{\offinterlineskip\halign{\hfil$\scriptscriptstyle##$\hfil\cr
+\gets\cr\to\cr}}}}}
+\def\lid{\mathrel{\mathchoice {\vcenter{\offinterlineskip\halign{\hfil
+$\displaystyle##$\hfil\cr<\cr\noalign{\vskip1.2pt}=\cr}}}
+{\vcenter{\offinterlineskip\halign{\hfil$\textstyle##$\hfil\cr<\cr
+\noalign{\vskip1.2pt}=\cr}}}
+{\vcenter{\offinterlineskip\halign{\hfil$\scriptstyle##$\hfil\cr<\cr
+\noalign{\vskip1pt}=\cr}}}
+{\vcenter{\offinterlineskip\halign{\hfil$\scriptscriptstyle##$\hfil\cr
+<\cr
+\noalign{\vskip0.9pt}=\cr}}}}}
+\def\gid{\mathrel{\mathchoice {\vcenter{\offinterlineskip\halign{\hfil
+$\displaystyle##$\hfil\cr>\cr\noalign{\vskip1.2pt}=\cr}}}
+{\vcenter{\offinterlineskip\halign{\hfil$\textstyle##$\hfil\cr>\cr
+\noalign{\vskip1.2pt}=\cr}}}
+{\vcenter{\offinterlineskip\halign{\hfil$\scriptstyle##$\hfil\cr>\cr
+\noalign{\vskip1pt}=\cr}}}
+{\vcenter{\offinterlineskip\halign{\hfil$\scriptscriptstyle##$\hfil\cr
+>\cr
+\noalign{\vskip0.9pt}=\cr}}}}}
+\def\grole{\mathrel{\mathchoice {\vcenter{\offinterlineskip
+\halign{\hfil
+$\displaystyle##$\hfil\cr>\cr\noalign{\vskip-1pt}<\cr}}}
+{\vcenter{\offinterlineskip\halign{\hfil$\textstyle##$\hfil\cr
+>\cr\noalign{\vskip-1pt}<\cr}}}
+{\vcenter{\offinterlineskip\halign{\hfil$\scriptstyle##$\hfil\cr
+>\cr\noalign{\vskip-0.8pt}<\cr}}}
+{\vcenter{\offinterlineskip\halign{\hfil$\scriptscriptstyle##$\hfil\cr
+>\cr\noalign{\vskip-0.3pt}<\cr}}}}}
+\def\bbbr{{\rm I\!R}} %reelle Zahlen
+\def\bbbm{{\rm I\!M}}
+\def\bbbn{{\rm I\!N}} %natuerliche Zahlen
+\def\bbbf{{\rm I\!F}}
+\def\bbbh{{\rm I\!H}}
+\def\bbbk{{\rm I\!K}}
+\def\bbbp{{\rm I\!P}}
+\def\bbbone{{\mathchoice {\rm 1\mskip-4mu l} {\rm 1\mskip-4mu l}
+{\rm 1\mskip-4.5mu l} {\rm 1\mskip-5mu l}}}
+\def\bbbc{{\mathchoice {\setbox0=\hbox{$\displaystyle\rm C$}\hbox{\hbox
+to0pt{\kern0.4\wd0\vrule height0.9\ht0\hss}\box0}}
+{\setbox0=\hbox{$\textstyle\rm C$}\hbox{\hbox
+to0pt{\kern0.4\wd0\vrule height0.9\ht0\hss}\box0}}
+{\setbox0=\hbox{$\scriptstyle\rm C$}\hbox{\hbox
+to0pt{\kern0.4\wd0\vrule height0.9\ht0\hss}\box0}}
+{\setbox0=\hbox{$\scriptscriptstyle\rm C$}\hbox{\hbox
+to0pt{\kern0.4\wd0\vrule height0.9\ht0\hss}\box0}}}}
+\def\bbbq{{\mathchoice {\setbox0=\hbox{$\displaystyle\rm
+Q$}\hbox{\raise
+0.15\ht0\hbox to0pt{\kern0.4\wd0\vrule height0.8\ht0\hss}\box0}}
+{\setbox0=\hbox{$\textstyle\rm Q$}\hbox{\raise
+0.15\ht0\hbox to0pt{\kern0.4\wd0\vrule height0.8\ht0\hss}\box0}}
+{\setbox0=\hbox{$\scriptstyle\rm Q$}\hbox{\raise
+0.15\ht0\hbox to0pt{\kern0.4\wd0\vrule height0.7\ht0\hss}\box0}}
+{\setbox0=\hbox{$\scriptscriptstyle\rm Q$}\hbox{\raise
+0.15\ht0\hbox to0pt{\kern0.4\wd0\vrule height0.7\ht0\hss}\box0}}}}
+\def\bbbt{{\mathchoice {\setbox0=\hbox{$\displaystyle\rm
+T$}\hbox{\hbox to0pt{\kern0.3\wd0\vrule height0.9\ht0\hss}\box0}}
+{\setbox0=\hbox{$\textstyle\rm T$}\hbox{\hbox
+to0pt{\kern0.3\wd0\vrule height0.9\ht0\hss}\box0}}
+{\setbox0=\hbox{$\scriptstyle\rm T$}\hbox{\hbox
+to0pt{\kern0.3\wd0\vrule height0.9\ht0\hss}\box0}}
+{\setbox0=\hbox{$\scriptscriptstyle\rm T$}\hbox{\hbox
+to0pt{\kern0.3\wd0\vrule height0.9\ht0\hss}\box0}}}}
+\def\bbbs{{\mathchoice
+{\setbox0=\hbox{$\displaystyle \rm S$}\hbox{\raise0.5\ht0\hbox
+to0pt{\kern0.35\wd0\vrule height0.45\ht0\hss}\hbox
+to0pt{\kern0.55\wd0\vrule height0.5\ht0\hss}\box0}}
+{\setbox0=\hbox{$\textstyle \rm S$}\hbox{\raise0.5\ht0\hbox
+to0pt{\kern0.35\wd0\vrule height0.45\ht0\hss}\hbox
+to0pt{\kern0.55\wd0\vrule height0.5\ht0\hss}\box0}}
+{\setbox0=\hbox{$\scriptstyle \rm S$}\hbox{\raise0.5\ht0\hbox
+to0pt{\kern0.35\wd0\vrule height0.45\ht0\hss}\raise0.05\ht0\hbox
+to0pt{\kern0.5\wd0\vrule height0.45\ht0\hss}\box0}}
+{\setbox0=\hbox{$\scriptscriptstyle\rm S$}\hbox{\raise0.5\ht0\hbox
+to0pt{\kern0.4\wd0\vrule height0.45\ht0\hss}\raise0.05\ht0\hbox
+to0pt{\kern0.55\wd0\vrule height0.45\ht0\hss}\box0}}}}
+\def\bbbz{{\mathchoice {\hbox{$\mathsf\textstyle Z\kern-0.4em Z$}}
+{\hbox{$\mathsf\textstyle Z\kern-0.4em Z$}}
+{\hbox{$\mathsf\scriptstyle Z\kern-0.3em Z$}}
+{\hbox{$\mathsf\scriptscriptstyle Z\kern-0.2em Z$}}}}
+
+\let\ts\,
+
+\setlength\leftmargini {17\p@}
+\setlength\leftmargin {\leftmargini}
+\setlength\leftmarginii {\leftmargini}
+\setlength\leftmarginiii {\leftmargini}
+\setlength\leftmarginiv {\leftmargini}
+\setlength \labelsep {.5em}
+\setlength \labelwidth{\leftmargini}
+\addtolength\labelwidth{-\labelsep}
+
+\def\@listI{\leftmargin\leftmargini
+ \parsep 0\p@ \@plus1\p@ \@minus\p@
+ \topsep 8\p@ \@plus2\p@ \@minus4\p@
+ \itemsep0\p@}
+\let\@listi\@listI
+\@listi
+\def\@listii {\leftmargin\leftmarginii
+ \labelwidth\leftmarginii
+ \advance\labelwidth-\labelsep
+ \topsep 0\p@ \@plus2\p@ \@minus\p@}
+\def\@listiii{\leftmargin\leftmarginiii
+ \labelwidth\leftmarginiii
+ \advance\labelwidth-\labelsep
+ \topsep 0\p@ \@plus\p@\@minus\p@
+ \parsep \z@
+ \partopsep \p@ \@plus\z@ \@minus\p@}
+
+\renewcommand\labelitemi{\normalfont\bfseries --}
+\renewcommand\labelitemii{$\m@th\bullet$}
+
+\setlength\arraycolsep{1.4\p@}
+\setlength\tabcolsep{1.4\p@}
+
+\def\tableofcontents{\chapter*{\contentsname\@mkboth{{\contentsname}}%
+ {{\contentsname}}}
+ \def\authcount##1{\setcounter{auco}{##1}\setcounter{@auth}{1}}
+ \def\lastand{\ifnum\value{auco}=2\relax
+ \unskip{} \andname\
+ \else
+ \unskip \lastandname\
+ \fi}%
+ \def\and{\stepcounter{@auth}\relax
+ \ifnum\value{@auth}=\value{auco}%
+ \lastand
+ \else
+ \unskip,
+ \fi}%
+ \@starttoc{toc}\if@restonecol\twocolumn\fi}
+
+\def\l@part#1#2{\addpenalty{\@secpenalty}%
+ \addvspace{2em plus\p@}% % space above part line
+ \begingroup
+ \parindent \z@
+ \rightskip \z@ plus 5em
+ \hrule\vskip5pt
+ \large % same size as for a contribution heading
+ \bfseries\boldmath % set line in boldface
+ \leavevmode % TeX command to enter horizontal mode.
+ #1\par
+ \vskip5pt
+ \hrule
+ \vskip1pt
+ \nobreak % Never break after part entry
+ \endgroup}
+
+\def\@dotsep{2}
+
+\let\phantomsection=\relax
+
+\def\hyperhrefextend{\ifx\hyper@anchor\@undefined\else
+{}\fi}
+
+\def\addnumcontentsmark#1#2#3{%
+\addtocontents{#1}{\protect\contentsline{#2}{\protect\numberline
+ {\thechapter}#3}{\thepage}\hyperhrefextend}}%
+\def\addcontentsmark#1#2#3{%
+\addtocontents{#1}{\protect\contentsline{#2}{#3}{\thepage}\hyperhrefextend}}%
+\def\addcontentsmarkwop#1#2#3{%
+\addtocontents{#1}{\protect\contentsline{#2}{#3}{0}\hyperhrefextend}}%
+
+\def\@adcmk[#1]{\ifcase #1 \or
+\def\@gtempa{\addnumcontentsmark}%
+ \or \def\@gtempa{\addcontentsmark}%
+ \or \def\@gtempa{\addcontentsmarkwop}%
+ \fi\@gtempa{toc}{chapter}%
+}
+\def\addtocmark{%
+\phantomsection
+\@ifnextchar[{\@adcmk}{\@adcmk[3]}%
+}
+
+\def\l@chapter#1#2{\addpenalty{-\@highpenalty}
+ \vskip 1.0em plus 1pt \@tempdima 1.5em \begingroup
+ \parindent \z@ \rightskip \@tocrmarg
+ \advance\rightskip by 0pt plus 2cm
+ \parfillskip -\rightskip \pretolerance=10000
+ \leavevmode \advance\leftskip\@tempdima \hskip -\leftskip
+ {\large\bfseries\boldmath#1}\ifx0#2\hfil\null
+ \else
+ \nobreak
+ \leaders\hbox{$\m@th \mkern \@dotsep mu.\mkern
+ \@dotsep mu$}\hfill
+ \nobreak\hbox to\@pnumwidth{\hss #2}%
+ \fi\par
+ \penalty\@highpenalty \endgroup}
+
+\def\l@title#1#2{\addpenalty{-\@highpenalty}
+ \addvspace{8pt plus 1pt}
+ \@tempdima \z@
+ \begingroup
+ \parindent \z@ \rightskip \@tocrmarg
+ \advance\rightskip by 0pt plus 2cm
+ \parfillskip -\rightskip \pretolerance=10000
+ \leavevmode \advance\leftskip\@tempdima \hskip -\leftskip
+ #1\nobreak
+ \leaders\hbox{$\m@th \mkern \@dotsep mu.\mkern
+ \@dotsep mu$}\hfill
+ \nobreak\hbox to\@pnumwidth{\hss #2}\par
+ \penalty\@highpenalty \endgroup}
+
+\def\l@author#1#2{\addpenalty{\@highpenalty}
+ \@tempdima=15\p@ %\z@
+ \begingroup
+ \parindent \z@ \rightskip \@tocrmarg
+ \advance\rightskip by 0pt plus 2cm
+ \pretolerance=10000
+ \leavevmode \advance\leftskip\@tempdima %\hskip -\leftskip
+ \textit{#1}\par
+ \penalty\@highpenalty \endgroup}
+
+\setcounter{tocdepth}{0}
+\newdimen\tocchpnum
+\newdimen\tocsecnum
+\newdimen\tocsectotal
+\newdimen\tocsubsecnum
+\newdimen\tocsubsectotal
+\newdimen\tocsubsubsecnum
+\newdimen\tocsubsubsectotal
+\newdimen\tocparanum
+\newdimen\tocparatotal
+\newdimen\tocsubparanum
+\tocchpnum=\z@ % no chapter numbers
+\tocsecnum=15\p@ % section 88. plus 2.222pt
+\tocsubsecnum=23\p@ % subsection 88.8 plus 2.222pt
+\tocsubsubsecnum=27\p@ % subsubsection 88.8.8 plus 1.444pt
+\tocparanum=35\p@ % paragraph 88.8.8.8 plus 1.666pt
+\tocsubparanum=43\p@ % subparagraph 88.8.8.8.8 plus 1.888pt
+\def\calctocindent{%
+\tocsectotal=\tocchpnum
+\advance\tocsectotal by\tocsecnum
+\tocsubsectotal=\tocsectotal
+\advance\tocsubsectotal by\tocsubsecnum
+\tocsubsubsectotal=\tocsubsectotal
+\advance\tocsubsubsectotal by\tocsubsubsecnum
+\tocparatotal=\tocsubsubsectotal
+\advance\tocparatotal by\tocparanum}
+\calctocindent
+
+\def\l@section{\@dottedtocline{1}{\tocchpnum}{\tocsecnum}}
+\def\l@subsection{\@dottedtocline{2}{\tocsectotal}{\tocsubsecnum}}
+\def\l@subsubsection{\@dottedtocline{3}{\tocsubsectotal}{\tocsubsubsecnum}}
+\def\l@paragraph{\@dottedtocline{4}{\tocsubsubsectotal}{\tocparanum}}
+\def\l@subparagraph{\@dottedtocline{5}{\tocparatotal}{\tocsubparanum}}
+
+\def\listoffigures{\@restonecolfalse\if@twocolumn\@restonecoltrue\onecolumn
+ \fi\section*{\listfigurename\@mkboth{{\listfigurename}}{{\listfigurename}}}
+ \@starttoc{lof}\if@restonecol\twocolumn\fi}
+\def\l@figure{\@dottedtocline{1}{0em}{1.5em}}
+
+\def\listoftables{\@restonecolfalse\if@twocolumn\@restonecoltrue\onecolumn
+ \fi\section*{\listtablename\@mkboth{{\listtablename}}{{\listtablename}}}
+ \@starttoc{lot}\if@restonecol\twocolumn\fi}
+\let\l@table\l@figure
+
+\renewcommand\listoffigures{%
+ \section*{\listfigurename
+ \@mkboth{\listfigurename}{\listfigurename}}%
+ \@starttoc{lof}%
+ }
+
+\renewcommand\listoftables{%
+ \section*{\listtablename
+ \@mkboth{\listtablename}{\listtablename}}%
+ \@starttoc{lot}%
+ }
+
+\ifx\oribibl\undefined
+\ifx\citeauthoryear\undefined
+\renewenvironment{thebibliography}[1]
+ {\section*{\refname}
+ \def\@biblabel##1{##1.}
+ \small
+ \list{\@biblabel{\@arabic\c@enumiv}}%
+ {\settowidth\labelwidth{\@biblabel{#1}}%
+ \leftmargin\labelwidth
+ \advance\leftmargin\labelsep
+ \if@openbib
+ \advance\leftmargin\bibindent
+ \itemindent -\bibindent
+ \listparindent \itemindent
+ \parsep \z@
+ \fi
+ \usecounter{enumiv}%
+ \let\p@enumiv\@empty
+ \renewcommand\theenumiv{\@arabic\c@enumiv}}%
+ \if@openbib
+ \renewcommand\newblock{\par}%
+ \else
+ \renewcommand\newblock{\hskip .11em \@plus.33em \@minus.07em}%
+ \fi
+ \sloppy\clubpenalty4000\widowpenalty4000%
+ \sfcode`\.=\@m}
+ {\def\@noitemerr
+ {\@latex@warning{Empty `thebibliography' environment}}%
+ \endlist}
+\def\@lbibitem[#1]#2{\item[{[#1]}\hfill]\if@filesw
+ {\let\protect\noexpand\immediate
+ \write\@auxout{\string\bibcite{#2}{#1}}}\fi\ignorespaces}
+\newcount\@tempcntc
+\def\@citex[#1]#2{\if@filesw\immediate\write\@auxout{\string\citation{#2}}\fi
+ \@tempcnta\z@\@tempcntb\m@ne\def\@citea{}\@cite{\@for\@citeb:=#2\do
+ {\@ifundefined
+ {b@\@citeb}{\@citeo\@tempcntb\m@ne\@citea\def\@citea{,}{\bfseries
+ ?}\@warning
+ {Citation `\@citeb' on page \thepage \space undefined}}%
+ {\setbox\z@\hbox{\global\@tempcntc0\csname b@\@citeb\endcsname\relax}%
+ \ifnum\@tempcntc=\z@ \@citeo\@tempcntb\m@ne
+ \@citea\def\@citea{,}\hbox{\csname b@\@citeb\endcsname}%
+ \else
+ \advance\@tempcntb\@ne
+ \ifnum\@tempcntb=\@tempcntc
+ \else\advance\@tempcntb\m@ne\@citeo
+ \@tempcnta\@tempcntc\@tempcntb\@tempcntc\fi\fi}}\@citeo}{#1}}
+\def\@citeo{\ifnum\@tempcnta>\@tempcntb\else
+ \@citea\def\@citea{,\,\hskip\z@skip}%
+ \ifnum\@tempcnta=\@tempcntb\the\@tempcnta\else
+ {\advance\@tempcnta\@ne\ifnum\@tempcnta=\@tempcntb \else
+ \def\@citea{--}\fi
+ \advance\@tempcnta\m@ne\the\@tempcnta\@citea\the\@tempcntb}\fi\fi}
+\else
+\renewenvironment{thebibliography}[1]
+ {\section*{\refname}
+ \small
+ \list{}%
+ {\settowidth\labelwidth{}%
+ \leftmargin\parindent
+ \itemindent=-\parindent
+ \labelsep=\z@
+ \if@openbib
+ \advance\leftmargin\bibindent
+ \itemindent -\bibindent
+ \listparindent \itemindent
+ \parsep \z@
+ \fi
+ \usecounter{enumiv}%
+ \let\p@enumiv\@empty
+ \renewcommand\theenumiv{}}%
+ \if@openbib
+ \renewcommand\newblock{\par}%
+ \else
+ \renewcommand\newblock{\hskip .11em \@plus.33em \@minus.07em}%
+ \fi
+ \sloppy\clubpenalty4000\widowpenalty4000%
+ \sfcode`\.=\@m}
+ {\def\@noitemerr
+ {\@latex@warning{Empty `thebibliography' environment}}%
+ \endlist}
+ \def\@cite#1{#1}%
+ \def\@lbibitem[#1]#2{\item[]\if@filesw
+ {\def\protect##1{\string ##1\space}\immediate
+ \write\@auxout{\string\bibcite{#2}{#1}}}\fi\ignorespaces}
+ \fi
+\else
+\@cons\@openbib@code{\noexpand\small}
+\fi
+
+\def\idxquad{\hskip 10\p@}% space that divides entry from number
+
+\def\@idxitem{\par\hangindent 10\p@}
+
+\def\subitem{\par\setbox0=\hbox{--\enspace}% second order
+ \noindent\hangindent\wd0\box0}% index entry
+
+\def\subsubitem{\par\setbox0=\hbox{--\,--\enspace}% third
+ \noindent\hangindent\wd0\box0}% order index entry
+
+\def\indexspace{\par \vskip 10\p@ plus5\p@ minus3\p@\relax}
+
+\renewenvironment{theindex}
+ {\@mkboth{\indexname}{\indexname}%
+ \thispagestyle{empty}\parindent\z@
+ \parskip\z@ \@plus .3\p@\relax
+ \let\item\par
+ \def\,{\relax\ifmmode\mskip\thinmuskip
+ \else\hskip0.2em\ignorespaces\fi}%
+ \normalfont\small
+ \begin{multicols}{2}[\@makeschapterhead{\indexname}]%
+ }
+ {\end{multicols}}
+
+\renewcommand\footnoterule{%
+ \kern-3\p@
+ \hrule\@width 2truecm
+ \kern2.6\p@}
+ \newdimen\fnindent
+ \fnindent1em
+\long\def\@makefntext#1{%
+ \parindent \fnindent%
+ \leftskip \fnindent%
+ \noindent
+ \llap{\hb@xt@1em{\hss\@makefnmark\ }}\ignorespaces#1}
+
+\long\def\@makecaption#1#2{%
+ \small
+ \vskip\abovecaptionskip
+ \sbox\@tempboxa{{\bfseries #1.} #2}%
+ \ifdim \wd\@tempboxa >\hsize
+ {\bfseries #1.} #2\par
+ \else
+ \global \@minipagefalse
+ \hb@xt@\hsize{\hfil\box\@tempboxa\hfil}%
+ \fi
+ \vskip\belowcaptionskip}
+
+\def\fps@figure{htbp}
+\def\fnum@figure{\figurename\thinspace\thefigure}
+\def \@floatboxreset {%
+ \reset@font
+ \small
+ \@setnobreak
+ \@setminipage
+}
+\def\fps@table{htbp}
+\def\fnum@table{\tablename~\thetable}
+\renewenvironment{table}
+ {\setlength\abovecaptionskip{0\p@}%
+ \setlength\belowcaptionskip{10\p@}%
+ \@float{table}}
+ {\end@float}
+\renewenvironment{table*}
+ {\setlength\abovecaptionskip{0\p@}%
+ \setlength\belowcaptionskip{10\p@}%
+ \@dblfloat{table}}
+ {\end@dblfloat}
+
+\long\def\@caption#1[#2]#3{\par\addcontentsline{\csname
+ ext@#1\endcsname}{#1}{\protect\numberline{\csname
+ the#1\endcsname}{\ignorespaces #2}}\begingroup
+ \@parboxrestore
+ \@makecaption{\csname fnum@#1\endcsname}{\ignorespaces #3}\par
+ \endgroup}
+
+% LaTeX does not provide a command to enter the authors institute
+% addresses. The \institute command is defined here.
+
+\newcounter{@inst}
+\newcounter{@auth}
+\newcounter{auco}
+\newdimen\instindent
+\newbox\authrun
+\newtoks\authorrunning
+\newtoks\tocauthor
+\newbox\titrun
+\newtoks\titlerunning
+\newtoks\toctitle
+
+\def\clearheadinfo{\gdef\@author{No Author Given}%
+ \gdef\@title{No Title Given}%
+ \gdef\@subtitle{}%
+ \gdef\@institute{No Institute Given}%
+ \gdef\@thanks{}%
+ \global\titlerunning={}\global\authorrunning={}%
+ \global\toctitle={}\global\tocauthor={}}
+
+\def\institute#1{\gdef\@institute{#1}}
+
+\def\institutename{\par
+ \begingroup
+ \parskip=\z@
+ \parindent=\z@
+ \setcounter{@inst}{1}%
+ \def\and{\par\stepcounter{@inst}%
+ \noindent$^{\the@inst}$\enspace\ignorespaces}%
+ \setbox0=\vbox{\def\thanks##1{}\@institute}%
+ \ifnum\c@@inst=1\relax
+ \gdef\fnnstart{0}%
+ \else
+ \xdef\fnnstart{\c@@inst}%
+ \setcounter{@inst}{1}%
+ \noindent$^{\the@inst}$\enspace
+ \fi
+ \ignorespaces
+ \@institute\par
+ \endgroup}
+
+\def\@fnsymbol#1{\ensuremath{\ifcase#1\or\star\or{\star\star}\or
+ {\star\star\star}\or \dagger\or \ddagger\or
+ \mathchar "278\or \mathchar "27B\or \|\or **\or \dagger\dagger
+ \or \ddagger\ddagger \else\@ctrerr\fi}}
+
+\def\inst#1{\unskip$^{#1}$}
+\def\orcidID#1{\unskip$^{[#1]}$} % added MR 2018-03-10
+\def\fnmsep{\unskip$^,$}
+\def\email#1{{\tt#1}}
+
+\AtBeginDocument{\@ifundefined{url}{\def\url#1{#1}}{}%
+\@ifpackageloaded{babel}{%
+\@ifundefined{extrasenglish}{}{\addto\extrasenglish{\switcht@albion}}%
+\@ifundefined{extrasfrenchb}{}{\addto\extrasfrenchb{\switcht@francais}}%
+\@ifundefined{extrasgerman}{}{\addto\extrasgerman{\switcht@deutsch}}%
+\@ifundefined{extrasngerman}{}{\addto\extrasngerman{\switcht@deutsch}}%
+}{\switcht@@therlang}%
+\providecommand{\keywords}[1]{\def\and{{\textperiodcentered} }%
+\par\addvspace\baselineskip
+\noindent\keywordname\enspace\ignorespaces#1}%
+\@ifpackageloaded{hyperref}{%
+\def\doi#1{\href{https://doi.org/\detokenize{#1}}{\url{https://doi.org/#1}}}}{
+\def\doi#1{https://doi.org/\detokenize{#1}}}
+}
+\def\homedir{\~{ }}
+
+\def\subtitle#1{\gdef\@subtitle{#1}}
+\clearheadinfo
+%
+%%% to avoid hyperref warnings
+\providecommand*{\toclevel@author}{999}
+%%% to make title-entry parent of section-entries
+\providecommand*{\toclevel@title}{0}
+%
+\renewcommand\maketitle{\newpage
+\phantomsection
+ \refstepcounter{chapter}%
+ \stepcounter{section}%
+ \setcounter{section}{0}%
+ \setcounter{subsection}{0}%
+ \setcounter{figure}{0}
+ \setcounter{table}{0}
+ \setcounter{equation}{0}
+ \setcounter{footnote}{0}%
+ \begingroup
+ \parindent=\z@
+ \renewcommand\thefootnote{\@fnsymbol\c@footnote}%
+ \if@twocolumn
+ \ifnum \col@number=\@ne
+ \@maketitle
+ \else
+ \twocolumn[\@maketitle]%
+ \fi
+ \else
+ \newpage
+ \global\@topnum\z@ % Prevents figures from going at top of page.
+ \@maketitle
+ \fi
+ \thispagestyle{empty}\@thanks
+%
+ \def\\{\unskip\ \ignorespaces}\def\inst##1{\unskip{}}%
+ \def\thanks##1{\unskip{}}\def\fnmsep{\unskip}%
+ \instindent=\hsize
+ \advance\instindent by-\headlineindent
+ \if!\the\toctitle!\addcontentsline{toc}{title}{\@title}\else
+ \addcontentsline{toc}{title}{\the\toctitle}\fi
+ \if@runhead
+ \if!\the\titlerunning!\else
+ \edef\@title{\the\titlerunning}%
+ \fi
+ \global\setbox\titrun=\hbox{\small\rm\unboldmath\ignorespaces\@title}%
+ \ifdim\wd\titrun>\instindent
+ \typeout{Title too long for running head. Please supply}%
+ \typeout{a shorter form with \string\titlerunning\space prior to
+ \string\maketitle}%
+ \global\setbox\titrun=\hbox{\small\rm
+ Title Suppressed Due to Excessive Length}%
+ \fi
+ \xdef\@title{\copy\titrun}%
+ \fi
+%
+ \if!\the\tocauthor!\relax
+ {\def\and{\noexpand\protect\noexpand\and}%
+ \def\inst##1{}% added MR 2017-09-20 to remove inst numbers from the TOC
+ \def\orcidID##1{}% added MR 2017-09-20 to remove ORCID ids from the TOC
+ \protected@xdef\toc@uthor{\@author}}%
+ \else
+ \def\\{\noexpand\protect\noexpand\newline}%
+ \protected@xdef\scratch{\the\tocauthor}%
+ \protected@xdef\toc@uthor{\scratch}%
+ \fi
+ \addtocontents{toc}{\noexpand\protect\noexpand\authcount{\the\c@auco}}%
+ \addcontentsline{toc}{author}{\toc@uthor}%
+ \if@runhead
+ \if!\the\authorrunning!
+ \value{@inst}=\value{@auth}%
+ \setcounter{@auth}{1}%
+ \else
+ \edef\@author{\the\authorrunning}%
+ \fi
+ \global\setbox\authrun=\hbox{\def\inst##1{}% added MR 2017-09-20 to remove inst numbers from the runninghead
+ \def\orcidID##1{}% added MR 2017-09-20 to remove ORCID ids from the runninghead
+ \small\unboldmath\@author\unskip}%
+ \ifdim\wd\authrun>\instindent
+ \typeout{Names of authors too long for running head. Please supply}%
+ \typeout{a shorter form with \string\authorrunning\space prior to
+ \string\maketitle}%
+ \global\setbox\authrun=\hbox{\small\rm
+ Authors Suppressed Due to Excessive Length}%
+ \fi
+ \xdef\@author{\copy\authrun}%
+ \markboth{\@author}{\@title}%
+ \fi
+ \endgroup
+ \setcounter{footnote}{\fnnstart}%
+ \clearheadinfo}
+%
+\def\@maketitle{\newpage
+ \markboth{}{}%
+ \def\lastand{\ifnum\value{@inst}=2\relax
+ \unskip{} \andname\
+ \else
+ \unskip \lastandname\
+ \fi}%
+ \def\and{\stepcounter{@auth}\relax
+ \ifnum\value{@auth}=\value{@inst}%
+ \lastand
+ \else
+ \unskip,
+ \fi}%
+ \begin{center}%
+ \let\newline\\
+ {\Large \bfseries\boldmath
+ \pretolerance=10000
+ \@title \par}\vskip .8cm
+\if!\@subtitle!\else {\large \bfseries\boldmath
+ \vskip -.65cm
+ \pretolerance=10000
+ \@subtitle \par}\vskip .8cm\fi
+ \setbox0=\vbox{\setcounter{@auth}{1}\def\and{\stepcounter{@auth}}%
+ \def\thanks##1{}\@author}%
+ \global\value{@inst}=\value{@auth}%
+ \global\value{auco}=\value{@auth}%
+ \setcounter{@auth}{1}%
+{\lineskip .5em
+\noindent\ignorespaces
+\@author\vskip.35cm}
+ {\small\institutename}
+ \end{center}%
+ }
+
+% definition of the "\spnewtheorem" command.
+%
+% Usage:
+%
+% \spnewtheorem{env_nam}{caption}[within]{cap_font}{body_font}
+% or \spnewtheorem{env_nam}[numbered_like]{caption}{cap_font}{body_font}
+% or \spnewtheorem*{env_nam}{caption}{cap_font}{body_font}
+%
+% New is "cap_font" and "body_font". It stands for
+% fontdefinition of the caption and the text itself.
+%
+% "\spnewtheorem*" gives a theorem without number.
+%
+% A defined spnewthoerem environment is used as described
+% by Lamport.
+%
+%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%
+
+\edef\@thmcountersep{}
+\edef\@thmcounterend{.}
+
+\def\spnewtheorem{\@ifstar{\@sthm}{\@Sthm}}
+
+% definition of \spnewtheorem with number
+
+\def\@spnthm#1#2{\@ifnextchar[{\@spxnthm{#1}{#2}}{\@spynthm{#1}{#2}}}
+\def\@Sthm#1{\@ifnextchar[{\@spothm{#1}}{\@spnthm{#1}}}
+
+% theorem-like environment with standard counter
+\def\@spynthm#1#2#3#4{\expandafter\@ifdefinable\csname #1\endcsname
+ {\@definecounter{#1}%
+ \expandafter\xdef\csname the#1\endcsname{\@thmcounter{#1}}%
+ \expandafter\xdef\csname #1name\endcsname{#2}%
+ \global\@namedef{#1}{\@spthm{#1}{\csname #1name\endcsname}{#3}{#4}}%
+ \global\@namedef{end#1}{\@endtheorem}}}
+
+% theorem-like environment with section-wise counter (envcountsect)
+\def\@spxnthm#1#2[#3]#4#5{\expandafter\@ifdefinable\csname #1\endcsname
+ {\@definecounter{#1}\@addtoreset{#1}{#3}%
+ \expandafter\xdef\csname the#1\endcsname{\expandafter\noexpand
+ \csname the#3\endcsname \noexpand\@thmcountersep \@thmcounter{#1}}%
+ \expandafter\xdef\csname #1name\endcsname{#2}%
+ \global\@namedef{#1}{\@spthm{#1}{\csname #1name\endcsname}{#4}{#5}}%
+ \global\@namedef{end#1}{\@endtheorem}}}
+
+% theorem-like environment with shared counter (envcountsame)
+\def\@spothm#1[#2]#3#4#5{%
+ \@ifundefined{c@#2}{\@latexerr{No theorem environment `#2' defined}\@eha}%
+ {\expandafter\@ifdefinable\csname #1\endcsname
+ {\newaliascnt{#1}{#2}%
+ \expandafter\xdef\csname #1name\endcsname{#3}%
+ \if@envcntsect
+ % the following line, introduced in v2.24, fixes incorrect hypertexnames
+ % when envcountsect is used in combination with envcountsame
+ \@addtoreset{#1}{section}
+ \fi
+ \global\@namedef{#1}{\@spthm{#1}{\csname #1name\endcsname}{#4}{#5}}%
+ \global\@namedef{end#1}{\@endtheorem}}}}
+
+
+
+\def\@spthm#1#2#3#4{\topsep 7\p@ \@plus2\p@ \@minus4\p@
+\refstepcounter{#1}%
+\@ifnextchar[{\@spythm{#1}{#2}{#3}{#4}}{\@spxthm{#1}{#2}{#3}{#4}}}
+
+\def\@spxthm#1#2#3#4{\@spbegintheorem{#2}{\csname the#1\endcsname}{#3}{#4}%
+ \ignorespaces}
+
+\def\@spythm#1#2#3#4[#5]{\@spopargbegintheorem{#2}{\csname
+ the#1\endcsname}{#5}{#3}{#4}\ignorespaces}
+
+\def\@spbegintheorem#1#2#3#4{\trivlist
+ \item[\hskip\labelsep{#3#1\ #2\@thmcounterend}]#4}
+
+\def\@spopargbegintheorem#1#2#3#4#5{\trivlist
+ \item[\hskip\labelsep{#4#1\ #2}]{#4(#3)\@thmcounterend\ }#5}
+
+% definition of \spnewtheorem* without number
+
+\def\@sthm#1#2{\@Ynthm{#1}{#2}}
+
+\def\@Ynthm#1#2#3#4{\expandafter\@ifdefinable\csname #1\endcsname
+ {\global\@namedef{#1}{\@Thm{\csname #1name\endcsname}{#3}{#4}}%
+ \expandafter\xdef\csname #1name\endcsname{#2}%
+ \global\@namedef{end#1}{\@endtheorem}}}
+
+\def\@Thm#1#2#3{\topsep 7\p@ \@plus2\p@ \@minus4\p@
+\@ifnextchar[{\@Ythm{#1}{#2}{#3}}{\@Xthm{#1}{#2}{#3}}}
+
+\def\@Xthm#1#2#3{\@Begintheorem{#1}{#2}{#3}\ignorespaces}
+
+\def\@Ythm#1#2#3[#4]{\@Opargbegintheorem{#1}
+ {#4}{#2}{#3}\ignorespaces}
+
+\def\@Begintheorem#1#2#3{#3\trivlist
+ \item[\hskip\labelsep{#2#1\@thmcounterend}]}
+
+\def\@Opargbegintheorem#1#2#3#4{#4\trivlist
+ \item[\hskip\labelsep{#3#1}]{#3(#2)\@thmcounterend\ }}
+
+\if@envcntsect
+ \def\@thmcountersep{.}
+ \spnewtheorem{theorem}{Theorem}[section]{\bfseries}{\itshape}
+\else
+ \spnewtheorem{theorem}{Theorem}{\bfseries}{\itshape}
+ \if@envcntreset
+ \@addtoreset{theorem}{section}
+ \else
+ \@addtoreset{theorem}{chapter}
+ \fi
+\fi
+
+%definition of various theorem environments
+\spnewtheorem*{claim}{Claim}{\itshape}{\rmfamily}
+\spnewtheorem*{proof}{Proof}{\itshape}{\rmfamily}
+\if@envcntsame % alle Umgebungen wie Theorem.
+ \def\spn@wtheorem#1#2#3#4{\@spothm{#1}[theorem]{#2}{#3}{#4}}
+\else % alle Umgebungen mit eigenem Zaehler
+ \if@envcntsect % mit section numeriert
+ \def\spn@wtheorem#1#2#3#4{\@spxnthm{#1}{#2}[section]{#3}{#4}}
+ \else % nicht mit section numeriert
+ \if@envcntreset
+ \def\spn@wtheorem#1#2#3#4{\@spynthm{#1}{#2}{#3}{#4}
+ \@addtoreset{#1}{section}}
+ \else
+ \def\spn@wtheorem#1#2#3#4{\@spynthm{#1}{#2}{#3}{#4}
+ \@addtoreset{#1}{chapter}}%
+ \fi
+ \fi
+\fi
+\spn@wtheorem{case}{Case}{\itshape}{\rmfamily}
+\spn@wtheorem{conjecture}{Conjecture}{\itshape}{\rmfamily}
+\spn@wtheorem{corollary}{Corollary}{\bfseries}{\itshape}
+\spn@wtheorem{definition}{Definition}{\bfseries}{\itshape}
+\spn@wtheorem{example}{Example}{\itshape}{\rmfamily}
+\spn@wtheorem{exercise}{Exercise}{\itshape}{\rmfamily}
+\spn@wtheorem{lemma}{Lemma}{\bfseries}{\itshape}
+\spn@wtheorem{note}{Note}{\itshape}{\rmfamily}
+\spn@wtheorem{problem}{Problem}{\itshape}{\rmfamily}
+\spn@wtheorem{property}{Property}{\itshape}{\rmfamily}
+\spn@wtheorem{proposition}{Proposition}{\bfseries}{\itshape}
+\spn@wtheorem{question}{Question}{\itshape}{\rmfamily}
+\spn@wtheorem{solution}{Solution}{\itshape}{\rmfamily}
+\spn@wtheorem{remark}{Remark}{\itshape}{\rmfamily}
+
+\def\@takefromreset#1#2{%
+ \def\@tempa{#1}%
+ \let\@tempd\@elt
+ \def\@elt##1{%
+ \def\@tempb{##1}%
+ \ifx\@tempa\@tempb\else
+ \@addtoreset{##1}{#2}%
+ \fi}%
+ \expandafter\expandafter\let\expandafter\@tempc\csname cl@#2\endcsname
+ \expandafter\def\csname cl@#2\endcsname{}%
+ \@tempc
+ \let\@elt\@tempd}
+
+\def\theopargself{\def\@spopargbegintheorem##1##2##3##4##5{\trivlist
+ \item[\hskip\labelsep{##4##1\ ##2}]{##4##3\@thmcounterend\ }##5}
+ \def\@Opargbegintheorem##1##2##3##4{##4\trivlist
+ \item[\hskip\labelsep{##3##1}]{##3##2\@thmcounterend\ }}
+ }
+
+\renewenvironment{abstract}{%
+ \list{}{\advance\topsep by0.35cm\relax\small
+ \leftmargin=1cm
+ \labelwidth=\z@
+ \listparindent=\z@
+ \itemindent\listparindent
+ \rightmargin\leftmargin}\item[\hskip\labelsep
+ \bfseries\abstractname]}
+ {\endlist}
+
+\newdimen\headlineindent % dimension for space between
+\headlineindent=1.166cm % number and text of headings.
+
+\def\ps@headings{\let\@mkboth\@gobbletwo
+ \let\@oddfoot\@empty\let\@evenfoot\@empty
+ \def\@evenhead{\normalfont\small\rlap{\thepage}\hspace{\headlineindent}%
+ \leftmark\hfil}
+ \def\@oddhead{\normalfont\small\hfil\rightmark\hspace{\headlineindent}%
+ \llap{\thepage}}
+ \def\chaptermark##1{}%
+ \def\sectionmark##1{}%
+ \def\subsectionmark##1{}}
+
+\def\ps@titlepage{\let\@mkboth\@gobbletwo
+ \let\@oddfoot\@empty\let\@evenfoot\@empty
+ \def\@evenhead{\normalfont\small\rlap{\thepage}\hspace{\headlineindent}%
+ \hfil}
+ \def\@oddhead{\normalfont\small\hfil\hspace{\headlineindent}%
+ \llap{\thepage}}
+ \def\chaptermark##1{}%
+ \def\sectionmark##1{}%
+ \def\subsectionmark##1{}}
+
+\if@runhead\ps@headings\else
+\ps@empty\fi
+
+\setlength\arraycolsep{1.4\p@}
+\setlength\tabcolsep{1.4\p@}
+
+\endinput
+%end of file llncs.cls
diff --git a/ACSAC/paper.bib b/ACSAC/paper.bib
new file mode 100644
index 0000000..ec7377e
--- /dev/null
+++ b/ACSAC/paper.bib
@@ -0,0 +1,1204 @@
+@misc{carlini2022membership,
+ title={Membership Inference Attacks From First Principles},
+ author={Nicholas Carlini and Steve Chien and Milad Nasr and Shuang Song and Andreas Terzis and Florian Tramer},
+ year={2022},
+ eprint={2112.03570},
+ archivePrefix={arXiv},
+ primaryClass={cs.CR}
+}
+
+@inproceedings{salem2023sok,
+ title={SoK: Let the privacy games begin! A unified treatment of data inference privacy in machine learning},
+ author={Salem, Ahmed and Cherubin, Giovanni and Evans, David and K{\"o}pf, Boris and Paverd, Andrew and Suri, Anshuman and Tople, Shruti and Zanella-B{\'e}guelin, Santiago},
+ booktitle={2023 IEEE Symposium on Security and Privacy (SP)},
+ pages={327--345},
+ year={2023},
+ organization={IEEE}
+}
+
+
+@inproceedings{ijcai2022p766,
+ title = {Differential Privacy and Fairness in Decisions and Learning Tasks: A Survey},
+ author = {Fioretto, Ferdinando and Tran, Cuong and Van Hentenryck, Pascal and Zhu, Keyu},
+ booktitle = {Proceedings of the Thirty-First International Joint Conference on
+ Artificial Intelligence, {IJCAI-22}},
+ publisher = {International Joint Conferences on Artificial Intelligence Organization},
+ editor = {Lud De Raedt},
+ pages = {5470--5477},
+ year = {2022},
+ month = {7},
+ note = {Survey Track},
+ doi = {10.24963/ijcai.2022/766},
+ url = {https://doi.org/10.24963/ijcai.2022/766},
+}
+
+@article{accfairtradeoff,
+author = {Pinzon, Carlos and Palamidessi, Catuscia and Piantanida, Pablo and Valencia, Frank},
+year = {2023},
+month = {05},
+pages = {1-30},
+title = {On the incompatibility of accuracy and equal opportunity},
+journal = {Machine Learning},
+doi = {10.1007/s10994-023-06331-y}
+}
+
+@article{rodolfa2021empirical,
+ title={Empirical observation of negligible fairness--accuracy trade-offs in machine learning for public policy},
+ author={Rodolfa, Kit T and Lamba, Hemank and Ghani, Rayid},
+ journal={Nature Machine Intelligence},
+ volume={3},
+ number={10},
+ pages={896--904},
+ year={2021},
+ publisher={Nature Publishing Group UK London}
+}
+
+@article{zhai2022understanding,
+ title={Understanding why generalized reweighting does not improve over ERM},
+ author={Zhai, Runtian and Dan, Chen and Kolter, Zico and Ravikumar, Pradeep},
+ booktitle={International Conference on Learning Representation},
+ year={2023}
+}
+
+@article{
+veldanda2022fairness,
+title={Fairness via In-Processing in the Over-parameterized Regime: A Cautionary Tale with MinDiff Loss},
+author={Akshaj Kumar Veldanda and Ivan Brugere and Jiahao Chen and Sanghamitra Dutta and Alan Mishler and Siddharth Garg},
+journal={Transactions on Machine Learning Research},
+issn={2835-8856},
+year={2023},
+url={https://openreview.net/forum?id=f4VyYhkRvi},
+note={}
+}
+
+% general
+% url = {https://arxiv.org/abs/2206.10923},
+@misc{arxivmichael,
+ doi = {10.48550/ARXIV.2206.10923},
+ author = {Maheshwari, Gaurav and Perrot, Michaël},
+ title = {FairGrad: Fairness Aware Gradient Descent},
+ publisher = {arXiv},
+ year = {2022},
+}
+
+
+@InProceedings{classIMb1,
+ title = {Class-Imbalanced Semi-Supervised Learning with Adaptive Thresholding},
+ author = {Guo, Lan-Zhe and Li, Yu-Feng},
+ booktitle = {Proceedings of the 39th International Conference on Machine Learning},
+ pages = {8082--8094},
+ year = {2022},
+ editor = {Chaudhuri, Kamalika and Jegelka, Stefanie and Song, Le and Szepesvari, Csaba and Niu, Gang and Sabato, Sivan},
+ volume = {162},
+ series = {Proceedings of Machine Learning Research},
+ month = {17--23 Jul},
+ publisher = {PMLR},
+ pdf = {https://proceedings.mlr.press/v162/guo22e/guo22e.pdf},
+ url = {https://proceedings.mlr.press/v162/guo22e.html}
+}
+
+@article{classIMb2,
+ title={Deep learning model calibration for improving performance in class-imbalanced medical image classification tasks},
+ author={Sivaramakrishnan Rajaraman and Prasanth Ganesan and Sameer K. Antani},
+ journal={PLoS ONE},
+ year={2021},
+ volume={17},
+ url={https://api.semanticscholar.org/CorpusID:238259577}
+}
+
+@misc{classIMb3,
+ author = {Jason Brownlee},
+ title = {{A} {G}entle {I}ntroduction to {T}hreshold-{M}oving for {I}mbalanced {C}lassification - {M}achine{L}earning{M}astery.com --- machinelearningmastery.com},
+ year = {},
+ note = {[Accessed 31-08-2023]},
+}
+%issn = {0022-0000},
+%url = {https://www.sciencedirect.com/science/article/pii/S002200009791504X},
+@article{saddlepointsolve,
+title = {A Decision-Theoretic Generalization of On-Line Learning and an Application to Boosting},
+journal = {Journal of Computer and System Sciences},
+volume = {55},
+number = {1},
+pages = {119-139},
+year = {1997},
+doi = {10.1006/jcss.1997.1504},
+author = {Yoav Freund and Robert E Schapire}
+}
+
+
+
+%isbn = {1595933832},
+%address = {New York, NY, USA},
+@inproceedings{curves,
+author = {Davis, Jesse and Goadrich, Mark},
+title = {The Relationship between Precision-Recall and ROC Curves},
+year = {2006},
+publisher = {Association for Computing Machinery},
+doi = {10.1145/1143844.1143874},
+booktitle = {International Conference on Machine Learning},
+pages = {233–240},
+location = {Pittsburgh, Pennsylvania, USA},
+series = {ICML '06}
+}
+
+
+@inproceedings{cormode,
+author = {Cormode, Graham},
+title = {Personal Privacy vs Population Privacy: Learning to Attack Anonymization},
+year = {2011},
+publisher = {Association for Computing Machinery},
+doi = {10.1145/2020408.2020598},
+booktitle = {ACM SIGKDD International Conference on Knowledge Discovery and Data Mining},
+pages = {1253–1261},
+location = {San Diego, California, USA},
+series = {KDD '11}
+}
+
+%publisher = {Association for Computing Machinery},
+%address = {New York, NY, USA},
+%issn = {0360-0300},
+%url = {https://doi.org/10.1145/3457607},
+@article{surveyfair,
+author = {Mehrabi, Ninareh and Morstatter, Fred and Saxena, Nripsuta and Lerman, Kristina and Galstyan, Aram},
+title = {A Survey on Bias and Fairness in Machine Learning},
+year = {2021},
+volume = {54},
+number = {6},
+doi = {10.1145/3457607},
+journal = {ACM Comput. Surv.},
+month = {jul},
+articleno = {115},
+numpages = {35},
+}
+
+
+@article{attinfSocial1,
+author = {Gong, Neil Zhenqiang and Talwalkar, Ameet and Mackey, Lester and Huang, Ling and Shin, Eui Chul Richard and Stefanov, Emil and Shi, Elaine (Runting) and Song, Dawn},
+title = {Joint Link Prediction and Attribute Inference Using a Social-Attribute Network},
+year = {2014},
+publisher = {Association for Computing Machinery},
+volume = {5},
+number = {2},
+doi = {10.1145/2594455},
+journal = {ACM Trans. Intell. Syst. Technol.},
+}
+
+
+%address = {New York, NY, USA},
+
+%issn = {2471-2566},
+%url = {https://doi.org/10.1145/3154793},
+%numpages = {30},
+%%month = {jan},
+@article{attinfSocial2,
+author = {Gong, Neil Zhenqiang and Liu, Bin},
+title = {Attribute Inference Attacks in Online Social Networks},
+year = {2018},
+publisher = {Association for Computing Machinery},
+volume = {21},
+number = {1},
+doi = {10.1145/3154793},
+journal = {ACM Trans. Priv. Secur.},
+articleno = {3},
+}
+
+%isbn = {978-1-931971-32-4},
+%address = {Austin, TX},
+%url = {https://www.usenix.org/conference/usenixsecurity16/technical-sessions/presentation/gong},
+%publisher = {USENIX Association},
+%month = aug,
+@inproceedings {attinfSocial3,
+author = {Neil Zhenqiang Gong and Bin Liu},
+title = {You Are Who You Know and How You Behave: Attribute Inference Attacks via Users{\textquoteright} Social Friends and Behaviors},
+booktitle = {USENIX Security Symposium },
+year = {2016},
+pages = {979--995},
+}
+
+
+ %URL = {https://hal.inria.fr/hal-00748162},
+ %ADDRESS = {San Diego, United States},
+ %MONTH = Feb,
+@inproceedings{attinfSocial4,
+ TITLE = {{You Are What You Like! Information Leakage Through Users' Interests}},
+ YEAR = {2012},
+ AUTHOR = {Chaabane, Abdelberi and Acs, Gergely and Kaafar, Mohamed Ali},
+ BOOKTITLE = {Network and Distributed System Security Symposium},
+ PAGES = {1-14},
+}
+
+
+
+
+@inproceedings{attinfSocial5,
+ author={Elena Zheleva and Lise Getoor},
+ title={To join or not to join: the illusion of privacy in social networks with mixed public and private user profiles},
+ year={2009},
+ BOOKTITLE = {International Conference on World Wide Web},
+ pages={531-540},
+ doi={10.1145/1526709.1526781},
+}
+
+
+
+%isbn = {9781450349130},
+%publisher = {International World Wide Web Conferences Steering Committee},
+%address = {Republic and Canton of Geneva, CHE},
+%url = {https://doi.org/10.1145/3038912.3052695},
+@inproceedings{attinfSocial6,
+author = {Jia, Jinyuan and Wang, Binghui and Zhang, Le and Gong, Neil Zhenqiang},
+title = {AttriInfer: Inferring User Attributes in Online Social Networks Using Markov Random Fields},
+year = {2017},
+doi = {10.1145/3038912.3052695},
+booktitle = {nternational Conference on World Wide Web},
+pages = {1561–1569},
+location = {Perth, Australia},
+series = {WWW '17}
+}
+
+
+
+%isbn = {9781450382878},
+%publisher = {Association for Computing Machinery},
+%address = {New York, NY, USA},
+@inbook{dysan,
+author = {Boutet, Antoine and Frindel, Carole and Gambs, S\'{e}bastien and Jourdan, Th\'{e}o and Ngueveu, Rosin Claude},
+title = {DySan: Dynamically Sanitizing Motion Sensor Data Against Sensitive Inferences through Adversarial Networks},
+year = {2021},
+doi = {10.1145/3433210.3453095},
+booktitle = {ACM Asia Conference on Computer and Communications Security},
+pages = {672–686},
+serie = {ASIA CCS '21}
+}
+
+@inproceedings{attprivacy,
+author = {Zhang, Wanrong and Ohrimenko, Olga and Cummings, Rachel},
+title = {Attribute Privacy: Framework and Mechanisms},
+year = {2022},
+isbn = {9781450393522},
+publisher = {Association for Computing Machinery},
+address = {New York, NY, USA},
+url = {https://doi.org/10.1145/3531146.3533139},
+doi = {10.1145/3531146.3533139},
+booktitle = {Proceedings of the 2022 ACM Conference on Fairness, Accountability, and Transparency},
+pages = {757–766},
+numpages = {10},
+keywords = {Pufferfish privacy, attribute privacy, formal privacy frameworks, privacy-preserving mechanisms},
+series = {FAccT '22}
+}
+
+%differential privacy and fairness
+@inproceedings{dispvuln,
+author = {Mohammad Yaghini and Bogdan Kulynych and Carmela Troncoso},
+title = {Disparate Vulnerability: on the Unfairness of Privacy Attacks Against Machine Learning},
+year = {2022},
+booktitle = {Privacy Enhancing Technologies Symposium}
+}
+
+
+%isbn = {9781450391405},
+%publisher = {Association for Computing Machinery},
+%address = {New York, NY, USA},
+@inproceedings{GongMIAUnfair,
+author = {Zhong, Da and Sun, Haipei and Xu, Jun and Gong, Neil and Wang, Wendy Hui},
+title = {Understanding Disparate Effects of Membership Inference Attacks and Their Countermeasures},
+year = {2022},
+doi = {10.1145/3488932.3501279},
+booktitle = {ACM on Asia Conference on Computer and Communications Security},
+pages = {959–974},
+location = {Nagasaki, Japan},
+series = {ASIA CCS '22}
+}
+
+
+%sbn = {9781450311151},
+%publisher = {Association for Computing Machinery},
+%address = {New York, NY, USA},
+%url = {https://doi.org/10.1145/2090236.2090255},
+@inproceedings{indivfairness,
+author = {Dwork, Cynthia and Hardt, Moritz and Pitassi, Toniann and Reingold, Omer and Zemel, Richard},
+title = {Fairness through Awareness},
+year = {2012},
+doi = {10.1145/2090236.2090255},
+booktitle = {Innovations in Theoretical Computer Science Conference},
+pages = {214–226},
+location = {Cambridge, Massachusetts},
+series = {ITCS '12}
+}
+
+@inproceedings{outIndist,
+author = {Dwork, Cynthia and Kim, Michael P. and Reingold, Omer and Rothblum, Guy N. and Yona, Gal},
+title = {Outcome indistinguishability},
+year = {2021},
+isbn = {9781450380539},
+publisher = {Association for Computing Machinery},
+address = {New York, NY, USA},
+url = {https://doi.org/10.1145/3406325.3451064},
+doi = {10.1145/3406325.3451064},
+booktitle = {Proceedings of the 53rd Annual ACM SIGACT Symposium on Theory of Computing},
+pages = {1095–1108},
+numpages = {14},
+keywords = {Prediction, Fairness, Computational Indistinguishability},
+location = {Virtual, Italy},
+series = {STOC 2021}
+}
+
+
+
+
+
+%isbn = {9781450369367},
+%publisher = {Association for Computing Machinery},
+%address = {New York, NY, USA},
+%url = {https://doi.org/10.1145/3351095.3372872},
+@inproceedings{dpfair,
+author = {Pujol, David and McKenna, Ryan and Kuppam, Satya and Hay, Michael and Machanavajjhala, Ashwin and Miklau, Gerome},
+title = {Fair Decision Making Using Privacy-Protected Data},
+year = {2020},
+doi = {10.1145/3351095.3372872},
+booktitle = {Conference on Fairness, Accountability, and Transparency},
+pages = {189–199},
+location = {Barcelona, Spain},
+series = {FAT* '20}
+}
+
+%url={https://ojs.aaai.org/index.php/AAAI/article/view/17193},
+%month={May},
+@article{fairprivatelagrangian,
+title={Differentially Private and Fair Deep Learning: A Lagrangian Dual Approach},
+volume={35},
+number={11},
+journal={AAAI Conference on Artificial Intelligence},
+author={Tran, Cuong and Fioretto, Ferdinando and Van Hentenryck, Pascal},
+year={2021},
+pages={9932-9939}
+}
+
+%editor = {Chaudhuri, Kamalika and Salakhutdinov, Ruslan},
+ %series = {Proceedings of Machine Learning Research},
+ %month = {09--15 Jun},
+ %publisher = {PMLR},
+ %pdf = {http://proceedings.mlr.press/v97/jagielski19a/jagielski19a.pdf},
+ %url = {https://proceedings.mlr.press/v97/jagielski19a.html}
+@InProceedings{dpfairlearn,
+ title = {Differentially Private Fair Learning},
+ author = {Jagielski, Matthew and Kearns, Michael and Mao, Jieming and Oprea, Alina and Roth, Aaron and -Malvajerdi, Saeed Sharifi and Ullman, Jonathan},
+ booktitle = {International Conference on Machine Learning},
+ pages = {3000--3008},
+ year = {2019},
+ volume = {97},
+}
+
+@incollection{dpaccdisp,
+title = {Differential Privacy Has Disparate Impact on Model Accuracy},
+author = {Bagdasaryan, Eugene and Poursaeed, Omid and Shmatikov, Vitaly},
+booktitle = {Advances in Neural Information Processing Systems},
+pages = {15479--15488},
+year = {2019}}
+
+%isbn = {978-1-939133-06-9},
+%address = {Santa Clara, CA},
+%url = {https://www.usenix.org/conference/usenixsecurity19/presentation/jayaraman},
+%publisher = {USENIX Association},
+%month = aug,
+@inproceedings {dpVacc,
+author = {Bargav Jayaraman and David Evans},
+title = {Evaluating Differentially Private Machine Learning in Practice},
+booktitle = {USENIX Security Symposium},
+year = {2019},
+pages = {1895--1912},
+}
+
+%isbn = {9781450367110},
+%publisher = {Association for Computing Machinery},
+%address = {New York, NY, USA},
+%url = {https://doi.org/10.1145/3314183.3323847},
+@inproceedings{cummings,
+author = {Cummings, Rachel and Gupta, Varun and Kimpara, Dhamma and Morgenstern, Jamie},
+title = {On the Compatibility of Privacy and Fairness},
+year = {2019},
+doi = {10.1145/3314183.3323847},
+booktitle = {Conference on User Modeling, Adaptation and Personalization},
+pages = {309–315},
+location = {Larnaca, Cyprus},
+series = {UMAP'19 Adjunct}
+}
+
+
+@techreport{ec2019ethics,
+ address = {Brussels},
+ author = {{High-Level Expert Group on AI}},
+ institution = {European Commission},
+ language = {eng},
+ month = apr,
+ title = {Ethics guidelines for trustworthy AI},
+ type = {Report},
+ url = {https://ec.europa.eu/digital-single-market/en/news/ethics-guidelines-trustworthy-ai},
+ year = {2019}
+}
+
+@inproceedings{nist,
+ title={A Taxonomy and Terminology of Adversarial Machine Learning},
+ author={Elham Tabassi and Kevin J. Burns and M. Hadjimichael and Andres Molina-Markham and Julian Sexton},
+ url = {https://nvlpubs.nist.gov/nistpubs/ir/2019/NIST.IR.8269-draft.pdf},
+ year={2019},
+ booktitle = {NIST Interagency/Internal Report}
+}
+
+@inproceedings{dpia,
+title={Art. 35 {GDPR} Data protection impact assessment},
+url={https://gdpr-info.eu/art-35-gdpr/},
+author={European Union Law},
+year={2018},
+booktitle={General Data Protection Regulation (GDPR)} }
+
+@article{ico,
+title={{AI} auditing and impact assessment: according to the UK information commissioner’s office}, ISSN={2730-5953, 2730-5961}, url={http://link.springer.com/10.1007/s43681-021-00039-2}, DOI={10.1007/s43681-021-00039-2},
+journal={AI and Ethics},
+author={Kazim, Emre and Denny, Danielle Mendes Thame and Koshiyama, Adriano},
+year={2021},
+month={Feb} }
+
+@inproceedings{whitehouse,
+title={Guidance for Regulation of Artificial Intelligence Applications},
+url={https://www.whitehouse.gov/wp-content/uploads/2020/11/M-21-06.pdf},
+author={White House},
+year = {2020},
+booktitle={Memorandum For The Heads Of Executive Departments And Agencies} }
+
+%metrics
+
+@INPROCEEDINGS{memprivNattpriv,
+ author={Zhao, Benjamin Zi Hao and Agrawal, Aviral and Coburn, Catisha and Asghar, Hassan Jameel and Bhaskar, Raghav and Kaafar, Mohamed Ali and Webb, Darren and Dickinson, Peter},
+ booktitle={IEEE European Symposium on Security and Privacy},
+ title={On the (In)Feasibility of Attribute Inference Attacks on Machine Learning Models},
+ year={2021},
+ pages={232-251},
+ doi={10.1109/EuroSP51992.2021.00025}
+}
+
+@article{duddu2023sok,
+ title={SoK: Unintended Interactions among Machine Learning Defenses and Risks},
+ author={Duddu, Vasisht and Szyller, Sebastian and Asokan, N},
+ journal={arXiv preprint arXiv:2312.04542},
+ year={2023}
+}
+
+
+@inproceedings{suri2023dissecting,
+ title={Dissecting distribution inference},
+ author={Suri, Anshuman and Lu, Yifu and Chen, Yanjin and Evans, David},
+ booktitle={2023 IEEE Conference on Secure and Trustworthy Machine Learning (SaTML)},
+ pages={150--164},
+ year={2023},
+ organization={IEEE}
+}
+
+
+@article{de2020overview,
+ title={An overview of privacy in machine learning},
+ author={De Cristofaro, Emiliano},
+ journal={arXiv preprint arXiv:2005.08679},
+ year={2020}
+}
+
+
+@article{pate2021fairness,
+ title={A Fairness Analysis on Private Aggregation of Teacher Ensembles},
+ author={Tran, Cuong and Dinh, My H and Beiter, Kyle and Fioretto, Ferdinando},
+ journal={arXiv preprint arXiv:2109.08630},
+ year={2021}
+}
+
+@article{fioretto2022differential,
+ title={Differential Privacy and Fairness in Decisions and Learning Tasks: A Survey},
+ author={Fioretto, Ferdinando and Tran, Cuong and Van Hentenryck, Pascal and Zhu, Keyu},
+ journal={arXiv preprint arXiv:2202.08187},
+ year={2022}
+}
+
+
+% attribute inference attacks in ML
+%publisher = "Institute of Electrical and Electronics Engineers (IEEE)",
+%address = "United States",
+@inproceedings{zhao2021infeasibility,
+title = "On the (in)feasibility of attribute inference attacks on machine learning models",
+author = "Zhao, {Benjamin Zi Hao} and Aviral Agrawal and Catisha Coburn and Asghar, {Hassan Jameel} and Raghav Bhaskar and Kaafar, {Mohamed Ali} and Darren Webb and Peter Dickinson",
+year = "2021",
+doi = "10.1109/EuroSP51992.2021.00025",
+pages = "232--251",
+booktitle = "IEEE European Symposium on Security and Privacy",
+serie = {EuroS&P '2021},
+}
+
+
+%isbn = {978-1-939133-31-1},
+%address = {Boston, MA},
+%url = {https://www.usenix.org/conference/usenixsecurity22/presentation/mehnaz},
+%publisher = {USENIX Association},
+%month = aug,
+@inproceedings{MehnazAttInf,
+author = {Shagufta Mehnaz and Sayanton V. Dibbo and Ehsanul Kabir and Ninghui Li and Elisa Bertino},
+title = {Are Your Sensitive Attributes Private? Novel Model Inversion Attribute Inference Attacks on Classification Models},
+booktitle = {USENIX Security Symposium},
+year = {2022},
+pages = {4579--4596},
+}
+
+%isbn = {9781450338325},
+%publisher = {Association for Computing Machinery},
+%address = {New York, NY, USA},
+%%url = {https://doi.org/10.1145/2810103.2813677},
+@inproceedings{fredrikson1,
+author = {Fredrikson, Matt and Jha, Somesh and Ristenpart, Thomas},
+title = {Model Inversion Attacks That Exploit Confidence Information and Basic Countermeasures},
+year = {2015},
+doi = {10.1145/2810103.2813677},
+booktitle = {ACM SIGSAC Conference on Computer and Communications Security},
+pages = {1322–1333},
+location = {Denver, Colorado, USA},
+series = {CCS '15}
+}
+
+
+%isbn = {9781931971157},
+@inproceedings{fredrikson2,
+author = {Fredrikson, Matthew and Lantz, Eric and Jha, Somesh and Lin, Simon and Page, David and Ristenpart, Thomas},
+title = {Privacy in Pharmacogenetics: An End-to-End Case Study of Personalized Warfarin Dosing},
+year = {2014},
+booktitle = {USENIX Conference on Security Symposium},
+pages = {17–32},
+location = {San Diego, CA},
+series = {SEC'14}
+}
+
+@inproceedings{Song2020Overlearning,
+title={Overlearning Reveals Sensitive Attributes},
+author={Congzheng Song and Vitaly Shmatikov},
+booktitle={International Conference on Learning Representations},
+year={2020}
+}
+
+
+%isbn = {9781450384544},
+%publisher = {Association for Computing Machinery},
+%address = {New York, NY, USA},
+%url = {https://doi.org/10.1145/3460120.3484533},
+@inproceedings{malekzadeh2021honestbutcurious,
+author = {Malekzadeh, Mohammad and Borovykh, Anastasia and G\"{u}nd\"{u}z, Deniz},
+title = {Honest-but-Curious Nets: Sensitive Attributes of Private Inputs Can Be Secretly Coded into the Classifiers' Outputs},
+year = {2021},
+doi = {10.1145/3460120.3484533},
+booktitle = {ACM SIGSAC Conference on Computer and Communications Security},
+pages = {825–844},
+location = {Virtual Event, Republic of Korea},
+series = {CCS '21}
+}
+
+
+@article{jayaraman2022attribute,
+ title={Are Attribute Inference Attacks Just Imputation?},
+ author={Jayaraman, Bargav and Evans, David},
+ journal={arXiv preprint arXiv:2209.01292},
+ year={2022}
+}
+
+
+@inproceedings{yeom,
+ author={Yeom, Samuel and Giacomelli, Irene and Fredrikson, Matt and Jha, Somesh},
+ booktitle={IEEE Computer Security Foundations Symposium},
+ title={Privacy Risk in Machine Learning: Analyzing the Connection to Overfitting},
+ year={2018},
+ pages={268-282},
+ doi={10.1109/CSF.2018.00027}
+}
+
+
+@inproceedings{Mahajan2020DoesLS,
+ title={Does Learning Stable Features Provide Privacy Benefits for Machine Learning Models?},
+ author={Divyat Mahajan, Shruti Tople, Amit Sharma},
+ booktitle = {NeurIPS PPML Workshop},
+ year={2020}
+}
+
+@inproceedings{Malekzadeh_2021,
+ doi = {10.1145/3460120.3484533},
+ url = {https://doi.org/10.1145%2F3460120.3484533},
+ year = 2021, month = {nov},
+ publisher = {{ACM}},
+ author = {Mohammad Malekzadeh and Anastasia Borovykh and Deniz Gündüz},
+ title = {Honest-but-Curious Nets: Sensitive Attributes of Private Inputs Can Be Secretly Coded into the Classifiers{\textquotesingle} Outputs},
+ booktitle = {Proceedings of the 2021 {ACM} {SIGSAC} Conference on Computer and Communications Security}}
+
+
+
+@INPROCEEDINGS{meminf,
+ author={Shokri, Reza and Stronati, Marco and Song, Congzheng and Shmatikov, Vitaly},
+ booktitle={2017 IEEE Symposium on Security and Privacy (SP)},
+ title={Membership Inference Attacks Against Machine Learning Models},
+ year={2017},
+ pages={3-18},
+ doi={10.1109/SP.2017.41}}
+
+@article{chang2021privacy,
+ title={On the Privacy Risks of Algorithmic Fairness},
+ author={Hongyang Chang and R. Shokri},
+ journal={{2021 }IEEE European Symposium on Security and Privacy},
+ year={2021},
+ pages={292-303}
+}
+
+@article{duddu2022inferring,
+ title={Inferring Sensitive Attributes from Model Explanations},
+ author={Duddu, Vasisht and Boutet, Antoine},
+ journal={arXiv preprint arXiv:2208.09967},
+ year={2022}
+}
+
+%editor = {H. Larochelle and M. Ranzato and R. Hadsell and M. F. Balcan and H. Lin},
+ %publisher = {Curran Associates, Inc.},
+ %url = {https://proceedings.neurips.cc/paper/2020/file/6b8b8e3bd6ad94b985c1b1f1b7a94cb2-Paper.pdf},
+@inproceedings{NEURIPS2020_6b8b8e3b,
+ author = {Zhao, Han and Chi, Jianfeng and Tian, Yuan and Gordon, Geoffrey J},
+ booktitle = {Advances in Neural Information Processing Systems},
+ pages = {9485--9496},
+ title = {Trade-offs and Guarantees of Adversarial Representation Learning for Information Obfuscation},
+ volume = {33},
+ year = {2020}
+}
+
+
+
+@ARTICLE{8515092,
+author={S. A. {Osia} and A. {Taheri} and A. S. {Shamsabadi} and K. {Katevas} and H. {Haddadi} and H. R. {Rabiee}},
+journal={IEEE Transactions on Knowledge and Data Engineering},
+title={Deep Private-Feature Extraction},
+year={2020},
+volume={32},
+number={1},
+pages={54-66},
+}
+
+
+
+%eprint = {1707.00075}
+@article{advfair,
+ author = {Alex Beutel and Jilin Chen and Zhe Zhao and Ed H. Chi},
+ title = {Data Decisions and Theoretical Implications when Adversarially Learning Fair Representations},
+ year = {2017},
+ publisher = {arXiv},
+ doi = {10.48550/ARXIV.1707.00075},
+}
+
+%property inference attack
+
+@article{propinf,
+ title={Dataset-Level Attribute Leakage in Collaborative Learning},
+ author={Zhang, Wanrong and Tople, Shruti and Ohrimenko, Olga},
+ journal={arXiv:2006.07267},
+ year={2020}
+}
+
+%month = sep,
+@article{propinf2,
+author = {Ateniese, Giuseppe and Mancini, Luigi V. and Spognardi, Angelo and Villani, Antonio and Vitali, Domenico and Felici, Giovanni},
+title = {Hacking Smart Machines with Smarter Ones: How to Extract Meaningful Data from Machine Learning Classifiers},
+year = {2015},
+volume = {10},
+number = {3},
+journal = {Int. J. Secur. Netw.},
+pages = {137–150}
+}
+
+
+%isbn = {9781450356930},
+%publisher = {Association for Computing Machinery},
+%address = {New York, NY, USA},
+%url = {https://doi.org/10.1145/3243734.3243834},
+@inproceedings{propinf3,
+author = {Ganju, Karan and Wang, Qi and Yang, Wei and Gunter, Carl A. and Borisov, Nikita},
+title = {Property Inference Attacks on Fully Connected Neural Networks Using Permutation Invariant Representations},
+year = {2018},
+doi = {10.1145/3243734.3243834},
+booktitle = {ACM SIGSAC Conference on Computer and Communications Security},
+pages = {619–633},
+location = {Toronto, Canada},
+series = {CCS '18}
+}
+
+@article{propinf4,
+ title={Formalizing and Estimating Distribution Inference Risks},
+ author={Suri, Anshuman and Evans, David},
+ journal={Proceedings on Privacy Enhancing Technologies},
+ year={2022}
+}
+
+@inproceedings{fedinference,
+author={L. {Melis} and C. {Song} and E. {De Cristofaro} and V. {Shmatikov}},
+booktitle={IEEE Symposium on Security and Privacy},
+title={Exploiting Unintended Feature Leakage in Collaborative Learning},
+year={2019},
+pages={691-706}
+}
+
+@INPROCEEDINGS {ferryExploit,
+author = {J. Ferry and U. Aivodji and S. Gambs and M. Huguet and M. Siala},
+booktitle = {2023 IEEE Conference on Secure and Trustworthy Machine Learning (SaTML)},
+title = {Exploiting Fairness to Enhance Sensitive Attributes Reconstruction},
+year = {2023},
+volume = {},
+issn = {},
+pages = {18-41},
+keywords = {training;measurement;learning systems;privacy;pipelines;training data;machine learning},
+doi = {10.1109/SaTML54575.2023.00012},
+url = {https://doi.ieeecomputersociety.org/10.1109/SaTML54575.2023.00012},
+publisher = {IEEE Computer Society},
+address = {Los Alamitos, CA, USA},
+month = {feb}
+}
+
+
+
+
+% defences against attribute inference attacks
+
+@inproceedings{10.5555/3042817.3042973,
+author = {Zemel, Richard and Wu, Yu and Swersky, Kevin and Pitassi, Toniann and Dwork, Cynthia},
+title = {Learning Fair Representations},
+year = {2013},
+booktitle = {International Conference on Machine Learning},
+serie = {ICML '13},
+}
+
+%month = jan,
+@article{10.5555/3122009.3208010,
+author = {Hamm, Jihun},
+title = {Minimax Filter: Learning to Preserve Privacy from Inference Attacks},
+year = {2017},
+volume = {18},
+number = {1},
+journal = {J. Mach. Learn. Res.},
+pages = {4704–4734}
+}
+
+@inproceedings{10.5555/3327546.3327583,
+author = {Moyer, Daniel and Gao, Shuyang and Brekelmans, Rob and Steeg, Greg Ver and Galstyan, Aram},
+title = {Invariant Representations without Adversarial Training},
+year = {2018},
+booktitle = {Advances in Neural Information Processing Systems}
+}
+
+@inproceedings{10.5555/3294771.3294827,
+author = {Xie, Qizhe and Dai, Zihang and Du, Yulun and Hovy, Eduard and Neubig, Graham},
+title = {Controllable Invariance through Adversarial Feature Learning},
+year = {2017},
+booktitle = {Advances in Neural Information Processing Systems}
+}
+
+@InProceedings{pmlr-v80-madras18a,
+ title = {Learning Adversarially Fair and Transferable Representations},
+ author = {Madras, David and Creager, Elliot and Pitassi, Toniann and Zemel, Richard},
+ pages = {3384--3393},
+ year = {2018},
+ volume = {80},
+ booktitle = {Proceedings of Machine Learning Research},
+}
+
+@inproceedings{censoringadv,
+title = "Censoring Representations with an Adversary",
+author = "Harrison Edwards and Amos Storkey",
+year = "2016",
+booktitle = {International Conference on Learning Representations}
+}
+@inproceedings{NIPS2017_48ab2f9b,
+ author = {Louppe, Gilles and Kagan, Michael and Cranmer, Kyle},
+ booktitle = {Advances in Neural Information Processing Systems},
+ editor = {I. Guyon and U. Von Luxburg and S. Bengio and H. Wallach and R. Fergus and S. Vishwanathan and R. Garnett},
+ pages = {},
+ publisher = {Curran Associates, Inc.},
+ title = {Learning to Pivot with Adversarial Networks},
+ url = {https://proceedings.neurips.cc/paper_files/paper/2017/file/48ab2f9b45957ab574cf005eb8a76760-Paper.pdf},
+ volume = {30},
+ year = {2017}
+}
+
+
+%isbn = {9781450360128},
+%publisher = {Association for Computing Machinery},
+%address = {New York, NY, USA},
+%url = {https://doi.org/10.1145/3278721.3278779},
+@inproceedings{debiase,
+author = {Zhang, Brian Hu and Lemoine, Blake and Mitchell, Margaret},
+title = {Mitigating Unwanted Biases with Adversarial Learning},
+year = {2018},
+doi = {10.1145/3278721.3278779},
+booktitle = {AAAI/ACM Conference on AI, Ethics, and Society},
+pages = {335–340},
+location = {New Orleans, LA, USA},
+series = {AIES '18}
+}
+
+ %month = {10},
+%pages = {},
+@article{preprocessing,
+author = {Kamiran, Faisal and Calders, Toon},
+year = {2011},
+title = {Data Pre-Processing Techniques for Classification without Discrimination},
+volume = {33},
+journal = {Knowledge and Information Systems},
+doi = {10.1007/s10115-011-0463-8}
+}
+
+%series = {Proceedings of Machine Learning Research},
+ %month = {10--15 Jul},
+ %publisher = {PMLR},
+ %pdf = {http://proceedings.mlr.press/v80/agarwal18a/agarwal18a.pdf},
+ %url = {https://proceedings.mlr.press/v80/agarwal18a.html},
+@InProceedings{reductions,
+ title = {A Reductions Approach to Fair Classification},
+ author = {Agarwal, Alekh and Beygelzimer, Alina and Dudik, Miroslav and Langford, John and Wallach, Hanna},
+ booktitle = {International Conference on Machine Learning},
+ pages = {60--69},
+ year = {2018},
+ volume = {80},
+}
+
+@article{kifer2014pufferfish,
+author = {Kifer, Daniel and Machanavajjhala, Ashwin},
+title = {Pufferfish: A framework for mathematical privacy definitions},
+year = {2014},
+issue_date = {January 2014},
+publisher = {Association for Computing Machinery},
+address = {New York, NY, USA},
+volume = {39},
+number = {1},
+issn = {0362-5915},
+url = {https://doi.org/10.1145/2514689},
+doi = {10.1145/2514689},
+journal = {ACM Trans. Database Syst.},
+month = {jan},
+articleno = {3},
+numpages = {36},
+keywords = {Privacy, differential privacy}
+}
+
+@inproceedings{song2017pufferfish,
+ title={Pufferfish privacy mechanisms for correlated data},
+ author={Song, Shuang and Wang, Yizhen and Chaudhuri, Kamalika},
+ booktitle={Proceedings of the 2017 ACM International Conference on Management of Data},
+ pages={1291--1306},
+ year={2017}
+}
+
+@article{grinsztajn2022tree,
+ title={Why do tree-based models still outperform deep learning on typical tabular data?},
+ author={Grinsztajn, L{\'e}o and Oyallon, Edouard and Varoquaux, Ga{\"e}l},
+ journal={Advances in neural information processing systems},
+ volume={35},
+ pages={507--520},
+ year={2022}
+}
+
+
+
+@inproceedings {attriguard,
+author = {Jinyuan Jia and Neil Zhenqiang Gong},
+title = {AttriGuard: A Practical Defense Against Attribute Inference Attacks via Adversarial Machine Learning},
+booktitle = {USENIX Security},
+year = {2018},
+pages = {513--529},
+}
+
+
+% fairness metrics
+
+@article{fairmetric,
+author = {Muhammad Bilal Zafar and Isabel Valera and Manuel Gomez-Rodriguez and Krishna P. Gummadi},
+title = {Fairness Constraints: A Flexible Approach for Fair Classification},
+journal = {Journal of Machine Learning Research},
+year = {2019},
+volume = {20},
+number = {75},
+pages = {1-42}
+}
+
+@inproceedings{fairmetric2,
+author = {Hardt, Moritz and Price, Eric and Srebro, Nathan},
+title = {Equality of Opportunity in Supervised Learning},
+year = {2016},
+booktitle = {Advances in Neural Information Processing Systems},
+pages = {3323–3331}
+}
+
+@article{fairjustice,
+author = {Alikhademi, Kiana and Drobina, Emma and Prioleau, Diandra and Richardson, Brianna and Purves, Duncan and Gilbert, Juan E.},
+title = {A Review of Predictive Policing from the Perspective of Fairness},
+year = {2022},
+issue_date = {Mar 2022},
+publisher = {Kluwer Academic Publishers},
+address = {USA},
+volume = {30},
+number = {1},
+issn = {0924-8463},
+url = {https://doi.org/10.1007/s10506-021-09286-4},
+doi = {10.1007/s10506-021-09286-4},
+journal = {Artif. Intell. Law},
+month = {mar},
+pages = {1–17},
+numpages = {17},
+keywords = {Predictive policing, Algorithmic fairness, Fairness, AI in criminal justice}
+}
+
+
+@article{folk,
+ title={Retiring Adult: New Datasets for Fair Machine Learning},
+ author={Ding, Frances and Hardt, Moritz and Miller, John and Schmidt, Ludwig},
+ journal={Advances in Neural Information Processing Systems},
+ volume={34},
+ year={2021}
+}
+
+@inproceedings{
+ SDV,
+ title={The Synthetic data vault},
+ author={Patki, Neha and Wedge, Roy and Veeramachaneni, Kalyan},
+ booktitle={IEEE International Conference on Data Science and Advanced Analytics (DSAA)},
+ year={2016},
+ pages={399-410},
+ doi={10.1109/DSAA.2016.49},
+ month={Oct}
+}
+
+@misc{dpbad,
+ doi = {10.48550/ARXIV.1104.3913},
+
+ url = {https://arxiv.org/abs/1104.3913},
+
+ author = {Dwork, Cynthia and Hardt, Moritz and Pitassi, Toniann and Reingold, Omer and Zemel, Rich},
+
+ keywords = {Computational Complexity (cs.CC), Computers and Society (cs.CY), FOS: Computer and information sciences, FOS: Computer and information sciences},
+
+ title = {Fairness Through Awareness},
+
+ publisher = {arXiv},
+
+ year = {2011},
+
+ copyright = {arXiv.org perpetual, non-exclusive license}
+}
+
+@INPROCEEDINGS{fairlog,
+
+ author={Radovanović, Sandro and Petrović, Andrija and Delibašić, Boris and Suknović, Milija},
+
+ booktitle={2020 International Conference on INnovations in Intelligent SysTems and Applications (INISTA)},
+
+ title={Enforcing fairness in logistic regression algorithm},
+
+ year={2020},
+
+ volume={},
+
+ number={},
+
+ pages={1-7},
+
+ doi={10.1109/INISTA49547.2020.9194676}}
+
+
+@misc{fairreg,
+ title={Fair Regression: Quantitative Definitions and Reduction-based Algorithms},
+ author={Alekh Agarwal and Miroslav Dudík and Zhiwei Steven Wu},
+ year={2019},
+ eprint={1905.12843},
+ archivePrefix={arXiv},
+ primaryClass={cs.LG}
+}
+
+
+
+@InProceedings{fairaudit1,
+ title = {Blind Justice: Fairness with Encrypted Sensitive Attributes},
+ author = {Kilbertus, Niki and Gascon, Adria and Kusner, Matt and Veale, Michael and Gummadi, Krishna and Weller, Adrian},
+ booktitle = {Proceedings of the 35th International Conference on Machine Learning},
+ pages = {2630--2639},
+ year = {2018},
+ editor = {Dy, Jennifer and Krause, Andreas},
+ volume = {80},
+ series = {Proceedings of Machine Learning Research},
+ month = {10--15 Jul},
+ publisher = {PMLR},
+ pdf = {http://proceedings.mlr.press/v80/kilbertus18a/kilbertus18a.pdf},
+ url = {https://proceedings.mlr.press/v80/kilbertus18a.html},
+}
+
+
+@inproceedings{fairaudit2,
+author = {Park, Saerom and Kim, Seongmin and Lim, Yeon-sup},
+title = {Fairness Audit of Machine Learning Models with Confidential Computing},
+year = {2022},
+isbn = {9781450390965},
+publisher = {Association for Computing Machinery},
+address = {New York, NY, USA},
+url = {https://doi.org/10.1145/3485447.3512244},
+doi = {10.1145/3485447.3512244},
+booktitle = {Proceedings of the ACM Web Conference 2022},
+pages = {3488–3499},
+numpages = {12},
+keywords = {Confidential computing, Algorithmic audit, Security and privacy, Fairness},
+location = {Virtual Event, Lyon, France},
+series = {WWW '22}
+}
+
+@inproceedings{fairaudit3,
+author = {Segal, Shahar and Adi, Yossi and Pinkas, Benny and Baum, Carsten and Ganesh, Chaya and Keshet, Joseph},
+title = {Fairness in the Eyes of the Data: Certifying Machine-Learning Models},
+year = {2021},
+isbn = {9781450384735},
+publisher = {Association for Computing Machinery},
+address = {New York, NY, USA},
+url = {https://doi.org/10.1145/3461702.3462554},
+doi = {10.1145/3461702.3462554},
+booktitle = {Proceedings of the 2021 AAAI/ACM Conference on AI, Ethics, and Society},
+pages = {926–935},
+numpages = {10},
+keywords = {machine-learning, cryptography, privacy, fairness},
+location = {Virtual Event, USA},
+series = {AIES '21}
+}
+
+@article{yadav2024fairproof,
+ title={FairProof: Confidential and Certifiable Fairness for Neural Networks},
+ author={Yadav, Chhavi and Chowdhury, Amrita Roy and Boneh, Dan and Chaudhuri, Kamalika},
+ journal={arXiv preprint arXiv:2402.12572},
+ year={2024}
+}
+
+@inproceedings{khedr2023certifair,
+ title={Certifair: A framework for certified global fairness of neural networks},
+ author={Khedr, Haitham and Shoukry, Yasser},
+ booktitle={Proceedings of the AAAI Conference on Artificial Intelligence},
+ volume={37},
+ number={7},
+ pages={8237--8245},
+ year={2023}
+}
+
+@article{urban20,
+author = {Urban, Caterina and Christakis, Maria and W\"{u}stholz, Valentin and Zhang, Fuyuan},
+title = {Perfectly parallel fairness certification of neural networks},
+year = {2020},
+issue_date = {November 2020},
+publisher = {Association for Computing Machinery},
+address = {New York, NY, USA},
+volume = {4},
+number = {OOPSLA},
+journal = {Proc. ACM Program. Lang.},
+month = {nov},
+articleno = {185},
+numpages = {30},
+keywords = {Static Analysis, Neural Networks, Fairness, Abstract Interpretation}
+}
+
+@inproceedings{
+chugg2023auditing,
+title={Auditing Fairness by Betting},
+author={Ben Chugg and Santiago Cortes-Gomez and Bryan Wilder and Aaditya Ramdas},
+booktitle={Thirty-seventh Conference on Neural Information Processing Systems},
+year={2023},
+url={https://openreview.net/forum?id=EEVpt3dJQj}
+}
+
+@inproceedings{yan2022active,
+ title={Active fairness auditing},
+ author={Yan, Tom and Zhang, Chicheng},
+ booktitle={International Conference on Machine Learning},
+ pages={24929--24962},
+ year={2022},
+ organization={PMLR}
+}
+
+@article{de2024fairness,
+ title={Fairness Auditing with Multi-Agent Collaboration},
+ author={de Vos, Martijn and Dhasade, Akash and Bourr{\'e}e, Jade Garcia and Kermarrec, Anne-Marie and Merrer, Erwan Le and Rottembourg, Benoit and Tredan, Gilles},
+ journal={arXiv preprint arXiv:2402.08522},
+ year={2024}
+}
+
+@inproceedings{ghosh2022algorithmic,
+ title={Algorithmic fairness verification with graphical models},
+ author={Ghosh, Bishwamittra and Basu, Debabrota and Meel, Kuldeep S},
+ booktitle={Proceedings of the AAAI Conference on Artificial Intelligence},
+ volume={36},
+ number={9},
+ pages={9539--9548},
+ year={2022}
+}
+
+@inproceedings{ghosh2023biased,
+ title={“How Biased are Your Features?”: Computing Fairness Influence Functions with Global Sensitivity Analysis},
+ author={Ghosh, Bishwamittra and Basu, Debabrota and Meel, Kuldeep S},
+ booktitle={Proceedings of the 2023 ACM Conference on Fairness, Accountability, and Transparency},
+ pages={138--148},
+ year={2023}
+}
+
+@article{FairSquare,
+author = {Albarghouthi, Aws and D'Antoni, Loris and Drews, Samuel and Nori, Aditya V.},
+title = {FairSquare: probabilistic verification of program fairness},
+year = {2017},
+issue_date = {October 2017},
+publisher = {Association for Computing Machinery},
+address = {New York, NY, USA},
+volume = {1},
+number = {OOPSLA},
+url = {https://doi.org/10.1145/3133904},
+doi = {10.1145/3133904},
+journal = {Proc. ACM Program. Lang.},
+month = {oct},
+articleno = {80},
+numpages = {30},
+keywords = {Algorithmic Fairness, Probabilistic Inference, Probabilistic Programming}
+}
+
+@article{saleiro2018aequitas,
+ title={Aequitas: A bias and fairness audit toolkit},
+ author={Saleiro, Pedro and Kuester, Benedict and Hinkson, Loren and London, Jesse and Stevens, Abby and Anisfeld, Ari and Rodolfa, Kit T and Ghani, Rayid},
+ journal={arXiv preprint arXiv:1811.05577},
+ year={2018}
+}
+
+@article{bastani2019probabilistic,
+ title={Probabilistic verification of fairness properties via concentration},
+ author={Bastani, Osbert and Zhang, Xin and Solar-Lezama, Armando},
+ journal={Proceedings of the ACM on Programming Languages},
+ volume={3},
+ number={OOPSLA},
+ pages={1--27},
+ year={2019},
+ publisher={ACM New York, NY, USA}
+}
+
+@article{adler2018auditing,
+ title={Auditing black-box models for indirect influence},
+ author={Adler, Philip and Falk, Casey and Friedler, Sorelle A and Nix, Tionney and Rybeck, Gabriel and Scheidegger, Carlos and Smith, Brandon and Venkatasubramanian, Suresh},
+ journal={Knowledge and Information Systems},
+ volume={54},
+ pages={95--122},
+ year={2018},
+ publisher={Springer}
+}
+
+@inproceedings{black2020fliptest,
+ title={Fliptest: fairness testing via optimal transport},
+ author={Black, Emily and Yeom, Samuel and Fredrikson, Matt},
+ booktitle={Proceedings of the 2020 Conference on Fairness, Accountability, and Transparency},
+ pages={111--121},
+ year={2020}
+}
+
+@article{Justicia,
+title={Justicia: A Stochastic SAT Approach to Formally Verify Fairness},
+volume={35},
+url={https://ojs.aaai.org/index.php/AAAI/article/view/16925}, DOI={10.1609/aaai.v35i9.16925},
+number={9}, journal={Proceedings of the AAAI Conference on Artificial Intelligence}, author={Ghosh, Bishwamittra and Basu, Debabrota and Meel, Kuldeep S.}, year={2021}, month={May}, pages={7554-7563} } \ No newline at end of file
diff --git a/ACSAC/proofs/proof_advdebias.tex b/ACSAC/proofs/proof_advdebias.tex
new file mode 100644
index 0000000..06212a0
--- /dev/null
+++ b/ACSAC/proofs/proof_advdebias.tex
@@ -0,0 +1,30 @@
+Definition~\ref{def:dp} of \dempar can be written synthetically as the following property:
+$P_{\hat{Y},S}=P_{\hat{Y}}\otimes P_{S}$.
+Where $P_{\hat{Y}}\otimes P_{S}$ is the product measure defined as the unique measure on
+$\mathcal{P}(\mathcal{Y})\times\mathcal{P}(\mathcal{S})$ such that
+$\forall y\in\mathcal{P}(\mathcal{Y})\forall s\in\mathcal{P}(\mathcal{S})\quad P_{\hat{Y}}\otimes P_{S}(y\times s) = P_{\hat{Y}}(y)P_{S}(s)$.
+This is equivalent to definition~\ref{def:dp} for binary labels and sensitive attribute but more general because when $\hat{Y}$ is not binary as in soft labels, this new definition is well defined.
+% We write formally
+\begin{definition}
+\label{def:dps}
+ $\hat{Y}$ satisfies extended \dempar for $S$ if and only if: $P_{\hat{Y},S}=P_{\hat{Y}}\otimes P_{S}$.
+\end{definition}
+This definition is the same as the statistical parity introduced for fair regression~\cite{fairreg}.
+Note that we can not derive a quantity similar to \demparlevel with this definition but this extended \dempar assures indistinguishably of the sensitive attribute when looking at the soft labels.
+We have the following theorem:
+\begin{theorem}\label{th:advdebias}
+ The following propositions are equivalent: ``$\hat{Y}_s$ is independent of $S$'' and ``Balanced accuracy of \aia in \ref{tm:soft} is $\frac{1}{2}$''
+\end{theorem}
+\begin{proof}
+Let's show that it is equivalent to say "all attack models have a balanced accuracy of 0.5" and "the target model satisfies extended demographic parity".
+{\footnotesize
+ \begin{align*}
+ &\forall a~P(\hat{Y}\in a^{-1}(\{0\})|S=0)+P(\hat{Y}\in a^{-1}(\{1\})|S=1) = 1\\
+ \Leftrightarrow&\forall a~P(\hat{Y}\in a^{-1}(\{0\})|S=0)=P(\hat{Y}\in a^{-1}(\{0\})|S=1)\\
+ \Leftrightarrow&\forall A~P(\hat{Y}\in A)|S=0)=P(\hat{Y}\in A|S=1) \\
+ \Leftrightarrow &P_{\hat{Y},S}=P_{\hat{Y}}\otimes P_{S}
+ \end{align*}
+ }
+\end{proof}
+
+%In conclusion, with extended \dempar we can not unconditionally bound the balanced accuracy of the attack without introducing distances in the space of distributions, but it gives us a condition to protect the sensitive attribute in case of an adversary gaining access to soft labels (AS). \ No newline at end of file
diff --git a/ACSAC/proofs/proof_egd_dp.tex b/ACSAC/proofs/proof_egd_dp.tex
new file mode 100644
index 0000000..d0f23f6
--- /dev/null
+++ b/ACSAC/proofs/proof_egd_dp.tex
@@ -0,0 +1,33 @@
+\begin{theorem}
+\label{th:dpgood}
+Maximum attack accuracy achievable by \aia in \ref{tm:hard} is equal to $\frac{1}{2}(1+\text{\demparlevel of }\targetmodel)$.
+\end{theorem}
+\begin{proof}
+The set $B$ of function from $\{0,1\}$ to $\{0,1\}$ contains four elements: $b_0=0$, $b_1=id$, $b_2=1-id$ and $b,3=1$, where $\forall x, id(x) = x$.
+For every $b\in B$ the balanced \aia accuracy is
+$BA(b) = \frac{1}{2}(P(b\circ \hat{Y}=0|S=0) + P(b\circ \hat{Y}=1|S=1))$.
+We have $BA(b_0) = BA(b_3) = \frac{1}{2}$, hence, we can discard those elements when solving the attack optimisation problem.
+This problem writes $\text{max}_{b\in B}B(A(b)) = \text{max}(BA(b_1), BA(b_2))$.
+We remark that $b_1\circ \hat{Y}=\hat{Y}$ and $b_2\circ \hat{Y}=1 - \hat{Y}$.
+Hence,
+{\footnotesize
+\begin{align*}
+ BA(b_1) &= \frac{1}{2}(P(\hat{Y}=0|S=0) + P(\hat{Y}=1|S=1))\\
+ &=\frac{1}{2}(1+P(\hat{Y}=1|S=1) - P(\hat{Y}=1|S=0))\\
+ BA(b_2)&=\frac{1}{2}(1+P(\hat{Y}=1|S=0) - P(\hat{Y}=1|S=1))
+\end{align*}
+}
+Thus,
+{\footnotesize
+\begin{align*}
+ &\text{max}_{b\in B}BA(b)
+ = \frac{1}{2}\left(1+\text{max}\left(
+ \begin{matrix}
+ P(\hat{Y}=0|S=0) -P(\hat{Y}=1|S=1)\\
+ P(\hat{Y}=1|S=0) -P(\hat{Y}=0|S=1)
+ \end{matrix}
+ \right)\right)\\
+ =&\frac{1}{2}(1+|P(\hat{Y}=1|S=1) - P(\hat{Y}=1|S=0)|)
+\end{align*}
+}
+\end{proof}
diff --git a/ACSAC/proofs/proof_egd_eo.tex b/ACSAC/proofs/proof_egd_eo.tex
new file mode 100644
index 0000000..435add2
--- /dev/null
+++ b/ACSAC/proofs/proof_egd_eo.tex
@@ -0,0 +1,35 @@
+\begin{theorem}
+\label{th:eoo}
+If $\hat{Y}$ satisfies \eo for $Y$ and $S$ then the balanced accuracy of \aia in \ref{tm:hard} is $\frac{1}{2}$ iff $Y$ is independent of $S$ or $\hat{Y}$ is independent of $Y$.
+\end{theorem}
+
+\begin{proof}
+Let $\attackmodel$ be the attack model trained for AS: $\hat{S}=a\circ \hat{Y}$.
+By the total probability formula
+{\footnotesize
+\begin{align*}
+P(\hat{S}=0|S=0)=&P(\hat{S}=0|S=0Y=0)P(Y=0|S=0)\\
++&P(\hat{S}=0|S=0Y=1)P(Y=1|S=0)
+\end{align*}
+}
+and as well
+{\footnotesize
+\begin{align*}
+P(\hat{S}=1|S=1)=&P(\hat{S}=1|S=1Y=0)P(Y=0|S=1)\\
+ +&P(\hat{S}=1|S=1Y=1)P(Y=1|S=1)
+\end{align*}
+}
+Then we substitute those terms in the definition of the balanced accuracy of $\targetmodel$.
+{\footnotesize
+\begin{align*}
+ &\frac{P(\hat{S}=0|S=0)+P(\hat{S}=1|S=1)}{2}\\
+ =&\frac{1}{2}+\frac{1}{2}\left(P(Y=0|S=0)-P(Y=0|S=1)\right)\\
+ &\left(P(\hat{Y}\in \attackmodel^{-1}(\{1\})|S=1Y=0) -
+ P(\hat{Y}\in \attackmodel^{-1}(\{1\})|S=1Y=1)\right)
+\end{align*}
+}
+The balanced accuracy is equal to 0.5 if and only if $P(Y=0|S=0)=P(Y=0|S=1)$
+or $\forall \attackmodel~P(\hat{Y}\in \attackmodel^{-1}(\{1\})|S=1Y=0)=P(\hat{Y}\in \attackmodel^{-1}(\{1\})|S=1Y=1)$.
+The first term indicates that $Y$ is independent of $S$ and the second term indicates that $S=1$ the $\targetmodel$ random guess utility.
+We can do the same computing for $S=0$ and obtain a similar conclusion.
+\end{proof} \ No newline at end of file
diff --git a/ACSAC/tables/tab_attack.tex b/ACSAC/tables/tab_attack.tex
new file mode 100644
index 0000000..51974df
--- /dev/null
+++ b/ACSAC/tables/tab_attack.tex
@@ -0,0 +1,30 @@
+\begin{table}[!htb]
+%\vspace{-3mm}
+\caption{\adaptiveAIAHard and \adaptiveAIASoft outperform their respective baselines. We report attack accuracy over ten runs.}
+\begin{center}
+%\footnotesize
+\scriptsize
+\begin{tabular}{ l | c | c }
+\hline
+\rowcolor{LightCyan} & \multicolumn{2}{c}{\ref{tm:hard}}\\
+\rowcolor{LightCyan} \textbf{Dataset} & \textbf{Baseline ($\upsilon$=0.50)} & \textbf{\adaptiveAIAHard}\\
+\rowcolor{LightCyan} & \textbf{\race} | \textbf{\sex}& \textbf{\race} | \textbf{\sex}\\
+\textbf{\census} & 0.50 $\pm$ 0.00 | 0.50 $\pm$ 0.00& \textbf{0.56 $\pm$ 0.01} | \textbf{0.58 $\pm$ 0.01} \\
+\textbf{\compas}& \textbf{0.62 $\pm$ 0.03} | 0.50 $\pm$ 0.00& \textbf{0.62 $\pm$ 0.03} | \textbf{0.57 $\pm$ 0.03} \\
+\textbf{\meps} & 0.51 $\pm$ 0.01 | \textbf{0.55 $\pm$ 0.02} & \textbf{0.53 $\pm$ 0.01} | \textbf{0.55 $\pm$ 0.01} \\
+\textbf{\lfw} & 0.59 $\pm$ 0.00 | 0.64 $\pm$ 0.15& \textbf{0.61 $\pm$ 0.11} | \textbf{0.78 $\pm$ 0.05} \\
+\hline
+\rowcolor{LightCyan} & \multicolumn{2}{c}{\ref{tm:soft}} \\
+\rowcolor{LightCyan} \textbf{Dataset} & \textbf{Baseline ($\upsilon$=0.50)} & \textbf{\adaptiveAIASoft} \\
+ \rowcolor{LightCyan} & \textbf{\race} | \textbf{\sex} & \textbf{\race} | \textbf{\sex}\\
+\hline
+\textbf{\census}& 0.50 $\pm$ 0.02 | 0.56 $\pm$ 0.04 & \textbf{0.61 $\pm$ 0.02} | \textbf{0.68 $\pm$ 0.01} \\
+\textbf{\compas}& \textbf{0.62 $\pm$ 0.03} | 0.50 $\pm$ 0.00 & \textbf{0.62 $\pm$ 0.03} | \textbf{0.57 $\pm$ 0.03} \\
+\textbf{\meps} & 0.52 $\pm$ 0.02 | 0.55 $\pm$ 0.02 & \textbf{0.60 $\pm$ 0.02} | \textbf{0.62 $\pm$ 0.02}\\
+\textbf{\lfw} & 0.50 $\pm$ 0.10 | \textbf{0.77 $\pm$ 0.07} & \textbf{0.61 $\pm$ 0.10} | \textbf{0.79 $\pm$ 0.05}\\
+\hline
+\end{tabular}
+\end{center}
+\label{tab:global_threshold_withoutsattr}
+%\vspace{-5mm}
+\end{table} \ No newline at end of file
diff --git a/ACSAC/tables/tab_datasets.tex b/ACSAC/tables/tab_datasets.tex
new file mode 100644
index 0000000..3dfe024
--- /dev/null
+++ b/ACSAC/tables/tab_datasets.tex
@@ -0,0 +1,17 @@
+\begin{table}[htb]
+\caption{Summary of dataset splits: $\traindata$ to train $\targetmodel$, $\testdata$ to evaluate $\targetmodel$, $\auxtraindata$ to train $\attackmodel$, and $\auxtestdata$ to evaluate $\attackmodel$.}
+\footnotesize
+\begin{center}
+\begin{tabular}{ l | c | c | c | c}
+\hline
+ \textbf{Dataset} & $\traindata$ & $\testdata$ & $\auxtraindata$ & $\auxtestdata$\\
+ \hline
+ \textbf{\census} & 24,752 & 6,188 & 4,950 & 1,238 \\
+ \textbf{\compas} & 4,937 & 1,235 & 988 & 247\\
+ \textbf{\meps} & 12,664 & 3,166 & 2,532 & 634\\
+ \textbf{\lfw} & 10514 & 2629 & 2103 & 526\\
+ \hline
+\end{tabular}
+\end{center}
+\label{tab:summary}
+\end{table} \ No newline at end of file
diff --git a/ACSAC/tables/tab_summary.tex b/ACSAC/tables/tab_summary.tex
new file mode 100644
index 0000000..f9598a4
--- /dev/null
+++ b/ACSAC/tables/tab_summary.tex
@@ -0,0 +1,32 @@
+\setlength\tabcolsep{3pt}
+\begin{table*}[!htb]
+\caption{Comparison of prior \aia{s}: attack vector exploited (e.g., $\targetmodel(X(\omega))$, $X(\omega)$, $Y(\omega)$, distribution over $S$ ($P_S$) and confusion matrix $C(Y,\targetmodel\circ X)$), whether $S$ is censored, i.e., included in $\traindata$ and inputs, whether \aia{s} account for class imbalance in $S$, whether \adv is active or passive and whether the threat model is blackbox or whitebox.}
+\begin{center}
+\footnotesize
+% \resizebox{\textwidth}{!}{%
+\begin{tabular}{ |c|c|c|c|c|c| }
+ \hline
+ \rowcolor{LightCyan}
+ \textbf{Literature} & \textbf{Attack Vector} & \textbf{Is $S$ censored?} & \textbf{Imbalance in $S$?} & \textbf{\adv} & \textbf{Threat Model} \\
+ \hline
+ \rowcolor{LightCyan}
+ \multicolumn{6}{|c|}{\textbf{Imputation-based Attacks}}\\
+ \hline
+ \textbf{Fredrikson et al.}~\cite{fredrikson2} & $X$, $Y$, $\targetmodel\circ X$, \textbf{$P_S$}, $C(Y,\targetmodel\circ X$) & $\checkmark$ & $\times$ & Passive & Blackbox\\
+ \textbf{Yeom et al.}~\cite{yeom} & $X$, $Y$, $\targetmodel$, \textbf{$P_S$} & $\checkmark$ & $\times$ & Passive & Blackbox\\
+ \textbf{Mehnaz et al.}~\cite{MehnazAttInf} & $X$, $Y$, $\targetmodel$, \textbf{$P_S$}, $C(Y,\targetmodel\circ X)$ & $\checkmark$ & $\times$ & Passive & Blackbox\\
+ \textbf{Jayaraman and Evans}~\cite{jayaraman2022attribute} & $X$, $Y$, $\targetmodel$, $P_S$, $C(Y,\targetmodel\circ X)$ & $\times$, $\checkmark$ & $\times$ & Passive & Whitebox\\
+ \hline
+ \rowcolor{LightCyan}
+ \multicolumn{6}{|c|}{\textbf{Representation-based Attacks}}\\
+ \hline
+ \textbf{Song et al.}~\cite{Song2020Overlearning} & $\targetmodel\circ X$ & $\times$ & $\times$ & Passive & Both\\
+ \textbf{Mahajan et al.}~\cite{Mahajan2020DoesLS} & $\targetmodel\circ X$ & $\checkmark$ & $\times$ & Passive & Blackbox\\
+ \textbf{Malekzadeh et al.}~\cite{malekzadeh2021honestbutcurious} & $\targetmodel\circ X$ & $\times$ & $\times$ & Active & Blackbox\\
+ % \textbf{Our Work} & $\targetmodel\circ X$ & $\times$, $\checkmark$ & $\checkmark$ & Passive & Blackbox \\
+ \hline
+\end{tabular}
+% }
+\end{center}
+\label{tab:summary}
+\end{table*} \ No newline at end of file