Can federated learning keep its accuracy once you bolt on HE and DP, or does client heterogeneity still wreck it?
trending23
01 02 Behavioral Privacy Leakage in Agentic Negotiation: Formalizing and Mitigating Inference Attacks via Randomized Policies arxiv.orgCan your negotiation bot's concessions, timing, and convergence leak hidden constraints? This paper formalizes that and randomizes around...03 Randomized buffering turns continual-release DP proofs adaptive, with explicit privacy-latency tradeoffs from buffer size.04 Dithered Gaussian DP keeps Gaussian guarantees while discretizing outputs, cutting randomness needs and floating-point leakage.05 ArXiv paper on Ball-DP, a local-ball variant of DP with noise rules and robustness certificates, because global privacy was too blunt.06 Secure and Efficient Federated Learning with Adaptive Differential Privacy and Verifiable Homomorphic Aggregation eprint.iacr.orgHEAD-FL: federated learning with round-adaptive DP and verifiable homomorphic aggregation, because fixed noise was too honest.07 Paper on DP-DiPP, a diffusion plus stochastic-code compressor for differentially private outputs, because plain compression was too easy.08 The Binary Tree Mechanism is Optimal for Approximate Differentially Private Continual Counting arxiv.orgPaper proves the Gaussian binary tree mechanism is optimal for approximate-DP continual counting, after the lower bound finally shows up.09 Differentially Private Intermediate Result Resizing for Scalable Secure Multi-Party Analytics eprint.iacr.orgResizer swaps worst-case padding for DP noisy bounds on MPC intermediates, with shuffle and sort variants.10 Fine-tuning fewer steps, not DP-SGD, does most of the memorization reduction; HMAC pseudonymization helps on identifiers.11 A Sieve-Accelerated Quadrature Method for Exact Privacy Accounting in the 2020 U.S. Decennial Census arxiv.orgExact privacy accounting for Census DP via sieve-accelerated quadrature and FFTs, since brute force was apparently too fun.12 LinkedIn’s PPRE wraps race/ethnicity estimation in MPC, DP, and homomorphic encryption, turning fairness checks into a privacy puzzle.13 Thread says age checks usually devolve into ID checks, and the new bit is ZK proofs as the only non-creepy escape hatch.14 Sparse structure still doesn't save private PCA here, polynomial-in-d samples can survive the sparsity assumptions.15 Poisoning can make LLMs cough up training records they never saw, with a loss-landscape attack that also pokes at DP defenses.16 Can DP in federated learning hide backdoors? This paper says yes, with RING, and the usual defenses miss it.17 Rényi-DP bounds for releasing GP posterior samples with private covariates and responses, plus membership-inference sanity checks.18 Paper on federated ECG anomaly detection with DP-SGD and INT8 on Raspberry Pi 4, because edge devices needed another headache.19 Cross-Silo De-Anonymization Under Local Differential Privacy: Threat Model, Phase Transition, and Coordination Necessity arxiv.orgDe-anonymization flips on at k*=Θ(log n/ε²), and uncoordinated randomized response stops being the safe default.20 One round, client-efficient DP-to-shuffle compiler, built on balanced additive randomized encodings and less per-client pain.21 Shuffle-model frequency estimation that shrugs off poisoned users with symmetric binomial-sum noise and guided preprocessing.22 Tight bounds on LZ77’s block-edit sensitivity, so the compressor can leak less than the folklore panic suggests.23 Can you get private hierarchical heavy hitters without error blowing up with depth or hitter count? This paper says mostly yes.