{"url":"/task/privacy-preserving-deep-learning","name":"Privacy Preserving Deep Learning","slug":"privacy-preserving-deep-learning","description_markdown":"The goal of privacy-preserving (deep) learning is to train a model while preserving privacy of the training dataset. Typically, it is understood that the trained model should be privacy-preserving (e.g., due to the training algorithm being differentially private).","categories":[{"name":"Computer Vision","url":"/area/computer-vision"},{"name":"Methodology","url":"/area/methodology"},{"name":"Miscellaneous","url":"/area/miscellaneous"}],"source":{"archive":"pwc-archive (Hugging Face), CC BY-SA 4.0","snapshot":"2025-07-28","slug_source":"archive_url"},"counts":{"papers_tagged":59,"papers_with_code":30,"benchmarks":0,"benchmark_tables_in_archive":0,"benchmark_tables_shown":0,"benchmark_tables_withheld_as_spam":0,"benchmark_definition":"a leaderboard table with at least one row; benchmark_tables_shown also counts the zero-row tables; benchmark_tables_in_archive adds the tables withheld as spam","datasets":3,"subtasks":2,"parent_tasks":1},"benchmarks":[],"datasets":[{"url":"/dataset/pa-hmdb51","name":"PA-HMDB51","full_name":"Privacy Annotated HMDB51","num_papers_in_archive":7},{"url":"/dataset/simran-arora","name":"ConcurrentQA Benchmark","full_name":"","num_papers_in_archive":3},{"url":"/dataset/ms-fimu","name":"MS-FIMU","full_name":"Mobility Scenario FIMU","num_papers_in_archive":3}],"subtasks":[{"url":"/task/homomorphic-encryption-for-deep-learning","name":"Homomorphic Encryption for Deep Learning"},{"url":"/task/membership-inference-attack","name":"Membership Inference Attack"}],"parent_tasks":[{"url":"/task/de-identification","name":"De-identification"}],"papers":{"order":"repositories listed in the archive (desc), then date (desc); the archive holds no stars","population":"papers tagged with this task that list at least one repository in the archive","shown":30,"of":30,"tagged_in_all":59,"items":[{"url":"/paper/privacy-preserving-deep-visual-recognition-an","title":"Privacy-Preserving Deep Action Recognition: An Adversarial Learning Framework and A New Dataset","date":"2019-06-12","arxiv_id":"1906.05675","repositories_listed":5,"syntology":null},{"url":"/paper/locally-differentially-private-contextual","title":"Locally Differentially Private (Contextual) Bandits Learning","date":"2020-06-01","arxiv_id":"2006.00701","repositories_listed":3,"syntology":null},{"url":"/paper/a-generic-framework-for-privacy-preserving","title":"A generic framework for privacy preserving deep learning","date":"2018-11-09","arxiv_id":"1811.04017","repositories_listed":3,"syntology":{"n":6,"n_ran":0,"n_unverified":6,"n_pointer_only":0}},{"url":"/paper/private-fair-and-accurate-training-large","title":"Private, fair and accurate: Training large-scale, privacy-preserving AI models in medical imaging","date":"2023-02-03","arxiv_id":"2302.01622","repositories_listed":2,"syntology":null},{"url":"/paper/sisyphus-a-cautionary-tale-of-using-low","title":"Sisyphus: A Cautionary Tale of Using Low-Degree Polynomial Activations in Privacy-Preserving Deep Learning","date":"2021-07-26","arxiv_id":"2107.12342","repositories_listed":2,"syntology":null},{"url":"/paper/ariann-low-interaction-privacy-preserving","title":"ARIANN: Low-Interaction Privacy-Preserving Deep Learning via Function Secret Sharing","date":"2020-06-08","arxiv_id":"2006.04593","repositories_listed":2,"syntology":null},{"url":"/paper/a-training-framework-for-optimal-and-stable","title":"A Training Framework for Optimal and Stable Training of Polynomial Neural Networks","date":"2025-05-16","arxiv_id":"2505.11589","repositories_listed":1,"syntology":null},{"url":"/paper/just-a-simple-transformation-is-enough-for","title":"Just a Simple Transformation is Enough for Data Protection in Vertical Federated Learning","date":"2024-12-16","arxiv_id":"2412.11689","repositories_listed":1,"syntology":null},{"url":"/paper/dct-cryptonets-scaling-private-inference-in","title":"DCT-CryptoNets: Scaling Private Inference in the Frequency Domain","date":"2024-08-27","arxiv_id":"2408.15231","repositories_listed":1,"syntology":{"n":2,"n_ran":0,"n_unverified":2,"n_pointer_only":0}},{"url":"/paper/enhancing-the-utility-of-privacy-preserving","title":"Enhancing the Utility of Privacy-Preserving Cancer Classification using Synthetic Data","date":"2024-07-17","arxiv_id":"2407.12669","repositories_listed":1,"syntology":null},{"url":"/paper/privacy-preserving-deep-learning-using","title":"Privacy-Preserving Deep Learning Using Deformable Operators for Secure Task Learning","date":"2024-04-08","arxiv_id":"2404.05828","repositories_listed":1,"syntology":null},{"url":"/paper/mind-the-gap-federated-learning-broadens","title":"Mind the Gap: Federated Learning Broadens Domain Generalization in Diagnostic AI Models","date":"2023-10-01","arxiv_id":"2310.00757","repositories_listed":1,"syntology":null},{"url":"/paper/split-without-a-leak-reducing-privacy-leakage","title":"Split Without a Leak: Reducing Privacy Leakage in Split Learning","date":"2023-08-30","arxiv_id":"2308.15783","repositories_listed":1,"syntology":null},{"url":"/paper/a-study-on-extracting-named-entities-from","title":"Memorization of Named Entities in Fine-tuned BERT Models","date":"2022-12-07","arxiv_id":"2212.03749","repositories_listed":1,"syntology":null},{"url":"/paper/collaborative-training-of-medical-artificial","title":"Collaborative Training of Medical Artificial Intelligence Models with non-uniform Labels","date":"2022-11-24","arxiv_id":"2211.13606","repositories_listed":1,"syntology":null},{"url":"/paper/privacy-in-practice-private-covid-19","title":"Privacy in Practice: Private COVID-19 Detection in X-Ray Images (Extended Version)","date":"2022-11-21","arxiv_id":"2211.11434","repositories_listed":1,"syntology":null},{"url":"/paper/bottlenecks-club-unifying-information","title":"Bottlenecks CLUB: Unifying Information-Theoretic Trade-offs Among Complexity, Leakage, and Utility","date":"2022-07-11","arxiv_id":"2207.04895","repositories_listed":1,"syntology":{"n":7,"n_ran":0,"n_unverified":7,"n_pointer_only":0}},{"url":"/paper/backpropagation-clipping-for-deep-learning","title":"Backpropagation Clipping for Deep Learning with Differential Privacy","date":"2022-02-10","arxiv_id":"2202.05089","repositories_listed":1,"syntology":null},{"url":"/paper/homogeneous-learning-self-attention-1","title":"Homogeneous Learning: Self-Attention Decentralized Deep Learning","date":"2021-10-11","arxiv_id":"2110.05290","repositories_listed":1,"syntology":null},{"url":"/paper/towards-secure-and-practical-machine-learning","title":"Towards Secure and Practical Machine Learning via Secret Sharing and Random Permutation","date":"2021-08-17","arxiv_id":"2108.07463","repositories_listed":1,"syntology":{"n":1,"n_ran":1,"n_unverified":0,"n_pointer_only":1}},{"url":"/paper/antipodes-of-label-differential-privacy-pate","title":"Antipodes of Label Differential Privacy: PATE and ALIBI","date":"2021-06-07","arxiv_id":"2106.03408","repositories_listed":1,"syntology":{"n":7,"n_ran":6,"n_unverified":1,"n_pointer_only":7}},{"url":"/paper/variational-leakage-the-role-of-information","title":"Variational Leakage: The Role of Information Complexity in Privacy Leakage","date":"2021-06-05","arxiv_id":"2106.02818","repositories_listed":1,"syntology":null},{"url":"/paper/cryptgpu-fast-privacy-preserving-machine","title":"CryptGPU: Fast Privacy-Preserving Machine Learning on the GPU","date":"2021-04-22","arxiv_id":"2104.10949","repositories_listed":1,"syntology":null},{"url":"/paper/practical-privacy-filters-and-odometers-with","title":"Practical Privacy Filters and Odometers with Rényi Differential Privacy and Applications to Differentially Private Deep Learning","date":"2021-03-02","arxiv_id":"2103.01379","repositories_listed":1,"syntology":null},{"url":"/paper/towards-generalized-and-distributed-privacy","title":"Can we Generalize and Distribute Private Representation Learning?","date":"2020-10-05","arxiv_id":"2010.01792","repositories_listed":1,"syntology":null},{"url":"/paper/secure-data-sharing-with-flow-model","title":"Secure Data Sharing With Flow Model","date":"2020-09-24","arxiv_id":"2009.11762","repositories_listed":1,"syntology":null},{"url":"/paper/tempered-sigmoid-activations-for-deep","title":"Tempered Sigmoid Activations for Deep Learning with Differential Privacy","date":"2020-07-28","arxiv_id":"2007.14191","repositories_listed":1,"syntology":{"n":1,"n_ran":0,"n_unverified":1,"n_pointer_only":1}},{"url":"/paper/when-differential-privacy-meets-graph-neural","title":"Locally Private Graph Neural Networks","date":"2020-06-09","arxiv_id":"2006.05535","repositories_listed":1,"syntology":{"n":3,"n_ran":1,"n_unverified":2,"n_pointer_only":0}},{"url":"/paper/fawkes-protecting-personal-privacy-against","title":"Fawkes: Protecting Privacy against Unauthorized Deep Learning Models","date":"2020-02-19","arxiv_id":"2002.08327","repositories_listed":1,"syntology":{"n":1,"n_ran":1,"n_unverified":0,"n_pointer_only":0}},{"url":"/paper/towards-fair-and-decentralized-privacy","title":"Towards Fair and Privacy-Preserving Federated Deep Models","date":"2019-06-04","arxiv_id":"1906.01167","repositories_listed":1,"syntology":null}],"syntology_records":8,"syntology_note":"a paper without a record is not a recorded non-run: it may lack an arXiv id or simply be absent from the graph layer"},"description_links":{"kept":0,"unwrapped_to_text":0,"bare_urls_linked":0,"relative_images_dropped":0,"rule":"internal links are kept only when the target slug exists in the catalog"},"syntology":{"read_at":"2026-09-24T18:15:14+00:00","claim":"Per-sample execution status on synthesized fixtures ('ran N of M samples'); not a correctness claim and not a ranking signal.","status_vocabulary":{"ran_honours":"ran, honoured the contract we drafted","ran_violates":"ran, violated the contract we drafted","ran_draft_wrong":"ran; our contract draft was wrong, not the code","ran_fixture":"ran; our fixture could not drive it","ran":"ran on a synthesized input","unverified":"unverified (harvested, no recorded run)"}},"not_shown":{"libraries":"the archive has no per-task library table","trend_sparklines":"the Trend column of the benchmarks table was a rendered image; it is not in the archive","social_and_latest_sorts":"stars and social signals are not in the archive"}}