EDBT 2026 Demo / reviewers in the wild / expert
Georgi Ganev
dblp:284/8917
· DBLP profile ↗
8ranked-venue papers
4as first author
8since 2021 · last 2025
0009-0004-4287-7473ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 6 · 3 first-author · 6 since 2021Artificial intelligence and machine learning · 2 · 1 first-author · 2 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | The Importance of Being Discrete: Measuring the Impact of Discretization in End-to-End Differentially Private Synthetic Data
Georgi Ganev, Meenatchi Sundaram Muthu Selva Annamalai, Sofiane Mahiou, Emiliano De Cristofaro |
CCS | 1 |
| 2025 | The DCR Delusion: Measuring the Privacy Risk of Synthetic Data
Zexi Yao, Natasa Krco, Georgi Ganev, Yves-Alexandre de Montjoye |
ESORICS (1) | 3 |
| 2025 | The Inadequacy of Similarity-Based Privacy Metrics: Privacy Attacks Against "Truly Anonymous" Synthetic DatasetsabstractGenerative models producing synthetic data are meant to provide a privacy-friendly approach to releasing data. However, their privacy guarantees are only considered robust when models satisfy Differential Privacy (DP). Alas, this is not a ubiquitous standard, as many leading companies (and, in fact, research papers) use ad-hoc privacy metrics based on testing the statistical similarity between synthetic and real data. In this paper, we examine the privacy metrics used in real-world synthetic data deployments and demonstrate their unreliability in several ways. First, we provide counter-examples where severe privacy violations occur even if the privacy tests pass and instantiate accurate membership and attribute inference attacks with minimal cost. We then introduce Recon-Syn, a reconstruction attack that generates multiple synthetic datasets that are considered private by the metrics but actually leak information unique to individual records. We show that ReconSyn recovers 78-100% of the outliers in the train data with only black-box access to a single fitted generative model and the privacy metrics. In the process, we show that applying DP only to the model does not mitigate this attack, as using privacy metrics breaks the end-to-end DP pipeline. Georgi Ganev, Emiliano De Cristofaro |
SP | 1 |
| 2024 | Graphical vs. Deep Generative Models: Measuring the Impact of Differentially Private Mechanisms and Budgets on UtilityabstractCCS ’24, October 14–18, 2024, Salt Lake City, UT, USA. Georgi Ganev, Emiliano De Cristofaro |
CCS | 1 |
| 2024 | "What do you want from theory alone?" Experimenting with Tight Auditing of Differentially Private Synthetic Data Generation
Meenatchi Sundaram Muthu Selva Annamalai, Georgi Ganev, Emiliano De Cristofaro |
USENIX Security Symposium | 2 |
| 2023 | Synthetic Data Generation of Many-to-Many Datasets via Random Graph Generation
Georgi Ganev, Emile Joubert, Rees Davison, Olivier Van Acker, Luke Robinson |
ICLR | 2 |
| 2022 | Robin Hood and Matthew Effects: Differential Privacy Has Disparate Impact on Synthetic DataabstractGenerative models trained with Differential Privacy (DP) can be used to generate synthetic data while minimizing privacy risks. We analyze the impact of DP on these models vis-a-vis underrepresented classes/subgroups of data, specifically, studying: 1) the size of classes/subgroups in the synthetic data, and 2) the accuracy of classification tasks run on them. We also evaluate the effect of various levels of imbalance and privacy budgets. Our analysis uses three state-of-the-art DP models (PrivBayes, DP-WGAN, and PATE-GAN) and shows that DP yields opposite size distributions in the generated synthetic data. It affects the gap between the majority and minority classes/subgroups; in some cases by reducing it (a "Robin Hood" effect) and, in others, by increasing it (a "Matthew" effect). Either way, this leads to (similar) disparate impacts on the accuracy of classification tasks on the synthetic data, affecting disproportionately more the underrepresented subparts of the data. Consequently, when training models on synthetic data, one might incur the risk of treating different subpopulations unevenly, leading to unreliable or unfair conclusions. Georgi Ganev, Bristena Oprisanu, Emiliano De Cristofaro |
ICML | 1 |
| 2022 | On Utility and Privacy in Synthetic Genomic Data
Bristena Oprisanu, Georgi Ganev, Emiliano De Cristofaro |
NDSS | 2 |