Score
Designs and implements training algorithms, pipelines, and data-preparation processes that provide formal differential privacy guarantees for machine learning models, including mechanisms such as noise-calibrated optimization, privacy accounting, and differential privacy mechanisms for data collection, synthesis, and pseudonymization. Builds and analyzes privacy-preserving modeling and training workflows and algorithms, and measures and tunes privacy–utility tradeoffs for deployed privacy-preserving ML systems.
Machine learning systems face significant privacy risks—including membership inference and attribute reconstruction—arising from training data leakage. Method: This paper presents a systematic survey of state-of-the-art privacy-preserving machine learning (PPML) techniques, covering both centralized and collaborative learning settings. It introduces a unified, multi-dimensional threat model and defense-layer mapping framework; proposes a quantitative evaluation framework balancing privacy guarantees and model utility; and clarifies the applicability boundaries and trade-offs among differential privacy, secure multi-party computation, homomorphic encryption, trusted execution environments (TEEs), and federated learning. Contribution/Results: Based on analysis of over 120 studies, the work establishes a comprehensive PPML taxonomy and provides quantitative comparisons across communication overhead, accuracy degradation, and security strength. The findings yield a practical, industry-deployable roadmap for privacy hardening of ML systems.
To address the vulnerability of machine learning models to sensitive data leakage, this paper establishes a unified differential privacy (DP) analysis framework spanning the entire AI stack—from symbolic systems to large language models (LLMs). Methodologically, it integrates DP-SGD, Laplace/Gaussian mechanisms, privacy budget allocation strategies, and tools for privacy-utility trade-off evaluation and adversarial robustness analysis. Innovatively, it proposes a novel DP adaptation paradigm for LLMs, accompanied by feasibility assessment criteria; it further identifies and systematizes the applicability boundaries of twelve mainstream DP-ML approaches—the first such comprehensive taxonomy. The work bridges foundational DP theory with generative AI practice, delivering dual theoretical rigor and engineering practicality to support secure, compliant, and verifiable AI systems. (132 words)
To address the challenge of trustworthy verification of machine learning preprocessing pipelines in privacy-sensitive settings, this paper proposes the first verification framework integrating local differential privacy (LDP) with model-agnostic interpretability methods (LIME/SHAP). The framework operates without access to raw data or model internals, enabling two verification tasks under strong privacy guarantees: (1) binary classification to determine whether preprocessing is correct, and (2) multi-class identification of specific error types. Its key innovation lies in injecting LDP noise into the feature attribution process of interpretability methods, thereby preserving both privacy and diagnostic interpretability. Experiments on the Diabetes, Adult, and Student Record datasets demonstrate that our ML-based binary classifier significantly outperforms baselines; for multi-class error localization, a threshold-based approach exhibits robust performance. Overall, the framework achieves high privacy preservation, strong robustness against noise and distribution shifts, and practical applicability.
Balancing privacy preservation and model accuracy remains challenging in collaborative modeling among multiple data owners. Method: This paper proposes a novel framework that deeply integrates differential privacy (DP) with secure multi-party computation (MPC). It is the first to provably inject Laplacian noise directly within an MPC protocol—performing privacy-parameter perturbation under secret sharing during distributed gradient computation. This ensures strict ε-differential privacy guarantees while avoiding the accuracy degradation typically caused by global noise in conventional DP approaches. Contribution/Results: The method enables privacy-preserving joint training on highly sensitive data (e.g., genomic data) without exposing raw samples. It achieved first place in the iDASH 2021 Track III competition, significantly outperforming pure-DP baselines in accuracy. By unifying formal privacy guarantees with practical efficiency, this work establishes a new paradigm for privacy-enhancing technologies that simultaneously satisfies rigorous security requirements and real-world usability.
Differential privacy (DP) gradient training suffers from excessive noise injection and suboptimal privacy–utility trade-offs due to reliance on global sensitivity, which is overly conservative for modern deep models. Method: This paper proposes the first scalable and verifiable framework for computing upper bounds on both local and smooth sensitivity—novelly integrating convex relaxation with interval-bound propagation to enable precise, efficient estimation of smooth sensitivity during gradient computation in contemporary deep neural networks. Contribution/Results: Our approach overcomes longstanding theoretical and computational barriers in rigorously bounding sensitivity. Experiments across financial risk assessment, medical image classification, and multi-task NLP demonstrate that our method reduces required noise magnitude by an order of magnitude, yielding substantial improvements in prediction accuracy and practical utility under identical privacy budgets (e.g., ε = 2, δ = 10⁻⁵). The framework provides stronger theoretical guarantees for private inference while ensuring engineering feasibility and scalability.
This work addresses the dual challenges of re-identification risks and client drift in federated learning with sensitive tabular data by proposing an end-to-end privacy-preserving framework that integrates data anonymization, differential privacy, and drift detection. The key innovations include a formalized mechanism for detecting client drift and a novel personalized differential privacy budget allocation strategy tailored to each client’s re-identification risk. Experimental evaluation on public medical datasets demonstrates that, compared to fixed-budget approaches, the proposed method significantly reduces model error while maintaining strong privacy guarantees, thereby enhancing overall model performance.
This study addresses the privacy-utility imbalance caused by global sensitivity in differential privacy and the absence of finite privacy guarantees for unbounded regression. It pioneers the extension of abstract interpretation to private prediction for continuous unbounded regression. By proposing an Abstract Gradient Sampling (AGS) algorithm alongside a smooth sensitivity upper-bounding technique, this work reformulates parameter learning as a regression problem, enabling formal certification of private learning via reachability analysis. Experimental results demonstrate that the derived regression bounds are tighter than those obtained using global sensitivity baselines. Furthermore, the proposed approach achieves the first finite privacy guarantees in unbounded settings and yields private learning performance superior to standard algorithms under matched conditions.
This work addresses the risk that third-party applications in federated learning may misuse sensitive data despite claiming to implement differential privacy, forcing users to trust their correct execution. To eliminate this trust assumption, the authors propose DataGuard—a hardware-based privacy enforcement mechanism that embeds differential privacy compliance verification logic directly within systolic array accelerators. This design ensures that only computation results satisfying the prescribed privacy budget can leave the device, without relying on the integrity of third-party software. Evaluated via simulation across four accelerator architectures, DataGuard incurs less than 0.01% area overhead and under 0.3% performance degradation, demonstrating an efficient and practical approach to hardening privacy guarantees at the hardware level.
This work proposes a unified privacy-preserving framework based on the CKKS homomorphic encryption scheme to mitigate the risk of privacy leakage associated with processing sensitive data in plaintext during machine learning. For the first time, it enables encrypted training of both k-nearest neighbors (KNN) and linear regression, as well as encrypted inference for multilayer perceptrons, within a single system. By integrating approximation techniques to handle non-polynomial operations and effectively managing ciphertext noise to enhance computational efficiency, the framework maintains end-to-end data encryption while achieving model accuracy comparable to that of plaintext training. The results demonstrate the practical feasibility of privacy-preserving machine learning and highlight key challenges remaining in computational overhead and functional expressiveness.
This study addresses the challenge in federated learning where single privacy-preserving mechanisms struggle to simultaneously maintain model utility and ensure data security. To overcome this limitation, we propose a novel synergistic framework that integrates homomorphic encryption (HE) for training with differential privacy (DP) for auditing. Methodologically, Markov Chain Monte Carlo (MCMC) Bayesian inference is employed to precisely estimate privacy parameters, thereby transcending the constraints of conventional single-mechanism approaches. Experimental evaluations on the FEMNIST dataset demonstrate that the proposed framework reduces the test loss to 1.09 while optimizing the privacy budget ε to 4.32. These results significantly outperform pure DP baselines, achieving an effective balance between high model utility and robust privacy guarantees.