Latest Privacy-Preserving ML Research Papers
The newest Privacy-Preserving ML papers from across the field — arXiv, NeurIPS, CVPR, Nature, and more — refreshed daily and ranked by relevance. Distill AI tracks Privacy-Preserving ML so you don’t have to: get the standout work delivered to your inbox every morning, with 2-sentence summaries and the option to chat with any paper.
Get the latest Privacy-Preserving ML papers in your inbox — free →Recent papers
- Beyond GDPR: The Architectural Challenge of Data Sovereignty and Confidential Computing in the Post-2024 EraMr. Tayabur Rahman Laskar · Zenodo (CERN European Organ... · Dec 18, 2026
As organizations migrate legacy datasets to cloud-native architectures, the tension between Big Data analytics and data privacy regulations has reached a critical inflection point. With the full operationalization of India’s Digital Persona…
- Beyond GDPR: The Architectural Challenge of Data Sovereignty and Confidential Computing in the Post-2024 EraMr. Tayabur Rahman Laskar · Zenodo (CERN European Organ... · Dec 18, 2026
As organizations migrate legacy datasets to cloud-native architectures, the tension between Big Data analytics and data privacy regulations has reached a critical inflection point. With the full operationalization of India’s Digital Persona…
- From Specs to Apps: Verifying and Monitoring Models of Signal and WhatsAppMoustafa Said, Aurora Naska, Kevin Morio, Robert Künnemann · arXiv · Sep 10, 2026
The Signal protocol is a prominent messaging protocol that secures communication for billions of users. It powers WhatsApp, the most widely used messaging application worldwide, and the Signal app, popular among privacy-conscious users. Ext…
- Predicting Privacy Leakage from Weight Spectral DensityRichard J. Preen, Jim Smith · arXiv · Sep 10, 2026
Membership inference attacks (MIAs) are widely used to audit the privacy disclosure risk of machine learning models, however current state-of-the-art attacks require training computationally expensive shadow models, making large-scale priva…
- Differentially Private EEG Feature Anonymization: A Privacy-Utility Case Study in Clinical NeurophysiologyNoman Sadiq, Mohsen Toorani · arXiv · Sep 10, 2026
Clinical electroencephalography (EEG) data are valuable for healthcare research and for developing artificial intelligence (AI)-based clinical decision-support systems, but EEG recordings and derived features may contain sensitive patient-s…
- PHAT: PHotonic Accelerator for TFHEGuowei Yang, Farbin Fayza, Beren Aydoğan, Carlos A. Ríos Ocampo et al. · arXiv · Sep 10, 2026
Fully Homomorphic Encryption (FHE) enables secure computation on encrypted data, making it a promising solution for privacy-preserving applications in the cloud. Among various FHE schemes, FHE over the Torus (TFHE) stands out due to its sup…
- Demystifying the Privacy-Utility Trade-off in LLM InteractionsZhenhua Liu, Zhanxu Xie, Junjie Yu, Tong Zhu et al. · arXiv · Sep 10, 2026
The integration of Large Language Models into daily tasks relies on context-rich instructions, inevitably exposing sensitive user information. Current privacy-preserving methods typically employ context-agnostic static rules, causing severe…
- Empirical Evaluation of Membership Inference Attacks on NLP Text Classifiers: A Baseline Study on SST-2William Novak, Muhammad Abusaqer · arXiv · Sep 10, 2026
Membership inference attacks (MIAs) try to determine whether a specific record was used to train a model, a privacy risk that matters in natural language processing (NLP), where training data can contain sensitive user text. This paper pres…
- Privacy-Preserving Transfer Learning for Community Detection using Locally Distributed Multiple NetworksXiao Guo, Xuming He, Xiangyu Chang, Shujie Ma · Journal of the American Sta... · Sep 10, 2026
Modern applications increasingly involve highly sensitive network data, where raw edges cannot be shared due to privacy constraints. We propose \texttt{TransNet}, a new spectral clustering-based transfer learning framework that improves com…
- AspisAI: A Canonical, Machine-Interpretable Governance Framework for Automated Multi-Standard Compliance MonitoringTsafac Nkombong Regine Cyrille, Hasan Dag, Reiner Creutzburg, Knut Haufe · arXiv · Sep 9, 2026
Organisations operating in regulated and critical-infrastructure sectors must satisfy multiple, heterogeneous cybersecurity and privacy instruments simultaneously, including but not limited to ISO/IEC~27001, the NIST Cybersecurity Framework…
- Lower Bounds for Private Graph Optimization Problems using Reconstruction AttacksJacob Imola, Rasmus Pagh, Lukas Retschmeier · arXiv · Sep 9, 2026
This paper studies fundamental graph optimization problems under differential privacy (DP) and shows new, reconstruction-based lower bounds. We consider a graph $G = (V, E, \vec{w})$ where the vertex set $V$ and edges $E$ are public and the…
- Towards Tackling Application Logic Flaws through Autonomous Formal-Logic Modeling and Automated ReasoningYiwei Fang, Yichen Liu, Ze Jin, Haoqiang Wang et al. · arXiv · Sep 9, 2026
Logic flaws pose significant challenges in the design and implementation of modern, semantically rich systems and applications, impacting security, privacy, and trust. These flaws are inherently tied to business-specific semantics and threa…
- Maverick: Private and Verifiable LLM Inference Made Practical via Matrix-Vector Multiplication DelegationBen Merbaum, Mohammad Amin Raeisi, Wenhao Wang, Charalampos Papamanthou et al. · arXiv · Sep 9, 2026
Open-source large language models (LLMs) are increasingly competitive with closed-source models while offering transparency and the ability to run inference without exposing user inputs to a service provider. However, running large-scale mo…
- Distributed and Private Textual Data Synthesis from EmbeddingsErgute Bao, Hongyan Chang, Ali Shahin Shamsabadi, Ting Yu et al. · arXiv · Sep 9, 2026
We revisit differentially private (DP) text synthesis in the realistic setting of distributed users, where privacy concerns preclude a trusted curator with access to raw user texts. Existing DP text synthesis pipelines are designed for a tr…
- CrossLink: Breaking Location Privacy by Linking Device Identifiers Across ProtocolsAneet Kumar Dutta, Mihirraj Dixit, Kevin Gni, Wouter Lueks et al. · arXiv · Sep 9, 2026
Smartphones simultaneously transmit temporary identifiers over LTE, WiFi, and BLE. Existing privacy defenses analyze identifier randomization per protocol, implicitly assuming that these protections compose across protocols. We show that th…
- Subgroup Membership Inference Audits of Differentially Private Synthetic TextYidan Sun, Viktor Schlegel, Srinivasan Nandakumar, Siew Kei Lam et al. · arXiv · Sep 9, 2026
Synthetic data releases are increasingly proposed in the literature as a means of sharing realistic data replicas in lieu of sensitive private datasets. Even when the worst-case privacy leakage of such releases is bounded by means of differ…
- PrivAudit: A Dual-Lens Auditing Framework for Website Privacy Practices under the CCPAMohamed Moustafa Dawoud, Riya Aggarwal, Likith Rahul Krishnamurthy, Ram Sundara Raman · arXiv · Sep 9, 2026
Five years after the enforcement of the California Consumer Privacy Act (CCPA), understanding how website privacy practices evolve at scale in response to regulation remains a key challenge for both researchers and regulators. Prior work an…
- SoK: Privacy Attacks on Machine Learning via Explainable AIAbdullah Caglar Oksuz, Anisa Halimi, Erman Ayday · arXiv · Sep 9, 2026
Machine learning explanations reveal model behavior beyond predictions, creating attack surfaces for model confidentiality and data privacy. We systematize 25 studies that exploit explanations for model extraction, membership inference, and…
- Evidence-Grounded Multi-Agent RAG for Automated Regulatory Compliance and Policy Auditing on Google Cloud: A Human-Governed Reference Architecture for GxP, FDA 21 CFR Part 11, HIPAA, and ICH E6(R3)Sarika Singh · Zenodo (CERN European Organ... · Sep 9, 2026
Regulated life-sciences and healthcare organizations increasingly need to evaluate large volumes of electronic records, standard operating procedures, clinical-trial artifacts, and policy evidence while preserving traceability, temporal val…
- Optimal Federated Learning for Nonparametric Regression with Heterogeneous Distributed Differential Privacy ConstraintsTommaso Cai, Abhinav Chakraborty, Lasse Vuursteen · Journal of the American Sta... · Sep 8, 2026
This paper studies federated learning for nonparametric regression in the context of distributed samples across different servers, each adhering to distinct differential privacy constraints. The setting we consider is heterogeneous, encompa…
- Privacy-Preserving Federated Learning for Crimes Against Humanity in Uganda: Robustness Under Distribution Shift and Sparse LabelsPamela Adong Laker · Zenodo (CERN European Organ... · Sep 7, 2026
The documentation and analysis of crimes against humanity in Uganda confront a dual computational challenge: data are distributed across sensitive, institutionally siloed repositories, and the labels required for supervised learning are exc…
- Privacy-Preserving Federated Learning for Creative Clusters Districts in Uganda: Robustness Under Distribution Shift and Sparse LabelsAchilles Byaruhanga Mwesigwa, Doreen Atuhaire Twinomujuni, Muzamiru Ssebuufu Kiggundu · Zenodo (CERN European Organ... · Sep 7, 2026
Federated learning offers a promising paradigm for training machine learning models across distributed creative industry clusters without centralising sensitive cultural or commercial data. However, its deployment in Ugandan creative distri…
- Construction of a federated learning-based privacy-preserving and intelligent recommendation model for educational dataXi Zhang, Baiying Yang, Chuan Li, Yong Wang · Scientific Reports · Sep 7, 2026
- Privacy-Preserving Federated Learning for Creative Clusters Districts in Uganda: Robustness Under Distribution Shift and Sparse LabelsAchilles Byaruhanga Mwesigwa, Doreen Atuhaire Twinomujuni, Muzamiru Ssebuufu Kiggundu · Zenodo (CERN European Organ... · Sep 7, 2026
Federated learning offers a promising paradigm for training machine learning models across distributed creative industry clusters without centralising sensitive cultural or commercial data. However, its deployment in Ugandan creative distri…
- A Privacy-Preserving Distributed Machine Learning Aggregation SchemeMingyuan Li · Applied and Computational E... · Sep 1, 2026
Federated Learning enables data to remain on local devices, yet malicious servers can still infer sensitive user information by analyzing client-uploaded model updates, posing significant privacy leakage risks. Existing secure aggregation s…
- Training Without Gathering the Data: A Historical Development Review of Federated Learning and Privacy-Preserving AIZen Revista, 10 IA · Zenodo (CERN European Organ... · Sep 1, 2026
This article presents a narrative review of Federated Learning and Privacy-Preserving AI in the context of Artificial Intelligence. The literature on this topic has expanded substantially over recent decades, yet it remains fragmented acros…
- Training Without Gathering the Data: A Historical Development Review of Federated Learning and Privacy-Preserving AIZen Revista, 10 IA · Zenodo (CERN European Organ... · Sep 1, 2026
This article presents a narrative review of Federated Learning and Privacy-Preserving AI in the context of Artificial Intelligence. The literature on this topic has expanded substantially over recent decades, yet it remains fragmented acros…
- Sublinear Space Graph Algorithms in the Continual Release ModelAlessandro Epasto, Quanquan C. Liu, Tamalika Mukherjee, Felix Zhou · Journal of Privacy and Conf... · Aug 31, 2026
The graph continual release model of differential privacy seeks to produce differentially private solutions to graph problems under a stream of edge updates where new private solutions are released after each update. Previously known edge d…
- Are Synthetic Data and Privacy Protection the Future of Artificial Intelligence Development?Istiarsyah Istiarsyah, Tina Isnaeni, Rival Pahrijal · West Science Information Sy... · Aug 31, 2026
The rapid advancement of Artificial Intelligence (AI) has created increasing dependence on large-scale datasets, while simultaneously generating significant legal challenges related to privacy protection, data governance, and individual rig…
- Integrating Particle Swarm Dynamics into Federated Learning: A Promising Hybrid to Counter Client Drift under Non-IID ConditionsMarwa K. Farhan, Ruslan Saad Abdulrahman, Aseel B. Alnajjar, Karam S. Khalid · International journal of in... · Aug 29, 2026
Federated learning (FL) enables distributed model training without centralizing raw data, making it attractive for privacy-sensitive Internet of Things (IoT) environments.However, conventional FL algorithms suffer from slow convergence and …