Results 1081 - 1090 of 24600
WIP abstract: The recent revolution in advanced data analytics and machine learning have made it possible to extract unprecedented value from user data. However, this comes at the cost of user privacy in many application workflows. In this talk, I will discuss some ideas around building privacy-preserving inference systems via a co-design of systems and cryptography. In the first part of the talk, I will present Bolt (IEEE S&P 2024), a new system for privacy-preserving two-party inference for a large language model like BERT using secure multiparty computation (MPC). With our system, a user can safely outsource prediction to a third party without revealing their sensitive data and or learning about the third party’s proprietary model parameters. In the second part, I will talk about building systems that can enable the development of programmable privacy-preserving inference systems. In Rotom (USENIX Security 2026), we develop a compilation framework that autovectorizes tensor programs into optimized homomorphic encryption (HE) programs. Rotom systematically explores a wide range of layout assignments, applies state-of-the-art optimizations, and automatically generates an equivalent, efficient HE program.
We present differentially private algorithms for high-dimensional mean estimation. Previous private estimators on distributions over ℝd suffer from a curse of dimensionality, as they require Ω(d1/2) samples to achieve non-trivial error, even in cases where O(1) samples suffice without privacy. This rate is unavoidable when the distribution is isotropic, namely, when the covariance is a multiple of the identity matrix, or when accuracy is measured with respect to the affine-invariant Mahalanobis distance. Yet, real-world data is often highly anisotropic, with signals concentrated on a small number of principal components. We develop estimators that are appropriate for such signals–our estimators are (ε,δ)-differentially private and have sample complexity that is dimension-independent for anisotropic subgaussian distributions. Given n samples from a distribution with known covariance-proxy Σ and unknown mean μ, we present an estimator μ̂ that achieves error ‖μ̂ −μ‖2≤α, as long as n≳tr(Σ)/α2+tr(Σ1/2)/(αε). In particular, when σσ2=(σ21,…,σ2d) are the singular values of Σ, we have tr(Σ)=‖σσ‖22 and tr(Σ1/2)=‖σσ‖1, and hence our bound avoids dimension-dependence when the signal is concentrated in a few principal components. We show that this is the optimal sample complexity for this task up to logarithmic factors. Moreover, for the case of unknown covariance, we present an algorithm whose sample complexity has improved dependence on the dimension, from d1/2 to d1/4.
Federated learning (FL) enables collaborative AI development without centralizing sensitive data. This talk highlights its real-world use in predicting COVID-19 outcomes while preserving patient privacy and data governance. I then introduce the latest innovations in NVIDIA FLARE, the open-source SDK for production-ready FL. New APIs simplify workflow design, while upgrades such as message quantization, native tensor transfer, and model streaming improve communication efficiency. Combined with privacy-preserving techniques like differential privacy, homomorphic encryption, and confidential computing, FLARE integrates seamlessly with popular training libraries and supports customizable workflows—empowering scalable applications in healthcare, biopharma, financial services, and large-scale language models.
I'll discuss models for distributed and private analysis of network data in which nodes retain control of their data. I'll focus particularly on the *local* node-private model, which is a good fit for distributed social network data. We provide the first formulation and systematic investigation of the model, design a new algorithmic framework tailored to it, and develop new lower bound techniques that show fundamental limitations on its power. Joint work with Sofya Raskhodnikova, Connor Wagaman, and Anatoly Zavyalov.