Privacy-Preserving Machine Learning with Privacy-Enhancing Technologies: From Foundations to Practical Systems

Presenters and Affiliations

Imtiyazuddin Shaik — TCS Research, India

Delton Myalil — TCS Research, India

Meena Singh Dilip Thakur — TCS Research, India

Overview / Abstract

Machine learning increasingly uses sensitive, regulated, or distributed data. This hands-on tutorial introduces privacy-preserving machine learning (PPML) through three complementary privacy-enhancing technologies (PETs): Fully Homomorphic Encryption (FHE), Secure Multi-Party Computation (MPC), and Federated Learning (FL). Participants build encrypted inference pipelines using OpenFHE and TFHE-rs, secure computation using MPyC and MP-SPDZ, and FL workflows using PyTorch. The tutorial examines noise growth and multiplicative depth in FHE, communication and adversarial models in MPC, and privacy leakage and mitigation in FL. It emphasizes how PETs can be selected and combined for practical systems.

Target Audience

  • Graduate students, researchers, and industry practitioners interested in PPML, applied cryptography, and PETs.
  • Advanced undergraduate students with prior exposure to machine learning.
  • No prior experience with homomorphic encryption, MPC, or federated learning is assumed.

Prerequisites

Participants should be comfortable with basic programming and have introductory knowledge of machine-learning concepts. Python is helpful for MPC and FL; C++ or Rust experience may benefit the FHE session. Hands-on exercises are guided and supported by pre-configured environments and tutorial material.

Learning Outcomes

  • Articulate PPML threat models and distinguish FHE, MPC, FL, trusted execution environments, and differential privacy by assumptions and cost profile.
  • Implement encrypted computation in OpenFHE and TFHE-rs, including key generation, evaluation, packing, noise/depth budgeting, and an encrypted-inference pipeline.
  • Implement secret-shared computation in MPyC and MP-SPDZ while accounting for communication rounds, security model, and number of parties.
  • Implement federated training in PyTorch, compose differential privacy, and estimate privacy leakage.
  • Map threat models and non-functional requirements to combinations of PETs.

Tutorial Structure / Technical Details

The tutorial comprises three 90-minute sessions. Each combines an introduction to concepts with guided hands-on exercises and closes with deployment considerations and practical trade-offs.

Minutes Segment Indicative focus
30 FHE foundations (lecture) Scheme families and operating envelopes; noise growth and multiplicative depth
50 FHE practice (hands-on) Key generation, evaluation, packing, parameter selection, encrypted inference
10 FHE synthesis (discussion) Depth and expansion limits; where FHE does and does not fit
Minutes Segment Indicative focus
30 MPC foundations (lecture) Secret sharing and garbled circuits; adversary and majority models; round-cost model
50 MPC practice (hands-on) Secret-shared arithmetic and comparison; multi-party setup; round and bandwidth accounting
10 MPC synthesis (discussion) Network sensitivity; choosing protocol and security model
Minutes Segment Indicative focus
30 FL foundations (lecture) Cross-device and cross-silo; vertical, horizontal, and transfer FL; attacks against FL
50 FL practice (hands-on) Federated averaging; hardening with Opacus differential privacy; extracting ε and δ privacy guarantees
10 FL synthesis (discussion) FL threat landscape, design decisions, and trade-offs

Tools and topics

  • FHE: OpenFHE and TFHE-rs; key generation, homomorphic evaluation, packing, noise and depth budgeting, and encrypted inference.
  • MPC: MPyC and MP-SPDZ; communication rounds, security model, number of parties, secret-shared arithmetic, and comparison.
  • FL: PyTorch; federated averaging, privacy leakage, differential-privacy mitigation, and system-design trade-offs.

Materials / Demonstration

Guided hands-on exercises are part of all three tracks: FHE encrypted inference, MPC secret-shared computation, and FL training with differential-privacy hardening.

Biography

Imtiyazuddin Shaik — TCS Research, India

Delton Myalil — TCS Research, India

Meena Singh Dilip Thakur — TCS Research, India

References

  1. C. Gentry. “Fully homomorphic encryption using ideal lattices.” Proceedings of the 41st ACM Symposium on Theory of Computing (STOC), pp. 169–178. ACM, 2009.
  2. J. H. Cheon, A. Kim, M. Kim, and Y. Song. “Homomorphic encryption for arithmetic of approximate numbers.” Advances in Cryptology—ASIACRYPT 2017, LNCS 10624, pp. 409–437. Springer, 2017.
  3. I. Chillotti, N. Gama, M. Georgieva, and M. Izabachène. “TFHE: Fast fully homomorphic encryption over the torus.” Journal of Cryptology 33(1), 34–91, 2020.
  4. A. Al Badawi et al. “OpenFHE: Open-source fully homomorphic encryption library.” Proceedings of the 10th Workshop on Encrypted Computing & Applied Homomorphic Cryptography (WAHC), pp. 53–63. ACM, 2022.
  5. M. Keller. “MP-SPDZ: A versatile framework for multi-party computation.” Proceedings of ACM SIGSAC CCS, pp. 1575–1590, 2020.
  6. A. Shamir. “How to share a secret.” Communications of the ACM 22(11), 612–613, 1979.
  7. B. Schoenmakers. “MPyC — Python package for secure multiparty computation.” Workshop on the Theory and Practice of MPC (TPMPC), 2018. https://github.com/lschoe/mpyc
  8. H. B. McMahan, E. Moore, D. Ramage, S. Hampson, and B. Agüera y Arcas. “Communication-efficient learning of deep networks from decentralized data.” AISTATS, PMLR 54, pp. 1273–1282, 2017.
  9. D. J. Beutel et al. “Flower: A friendly federated learning research framework.” arXiv:2007.14390, 2020. https://flower.ai
  10. K. Bonawitz et al. “Practical secure aggregation for privacy-preserving machine learning.” Proceedings of ACM SIGSAC CCS, pp. 1175–1191, 2017.
  11. L. Zhu, Z. Liu, and S. Han. “Deep leakage from gradients.” NeurIPS 32, pp. 14747–14756, 2019.
  12. M. Abadi et al. “Deep learning with differential privacy.” Proceedings of ACM SIGSAC CCS, pp. 308–318, 2016.
  13. A. K. Jindal et al. “Secure and privacy preserving method for biometric template protection using fully homomorphic encryption.” IEEE TrustCom, pp. 1127–1134, 2020.
  14. I. Shaik et al. “Privacy preserving machine learning for malicious URL detection.” Information Integration and Web Intelligence (iiWAS 2021). Springer, 2021.
  15. D. Myalil et al. “Robust Collaborative Fraudulent Transaction Detection using Federated Learning.” IEEE ICMLA, pp. 373–378, 2021.
  16. D. Myalil et al. “Robust Cross-Silo Federated Fraudulent Transaction Detection in Banks Using Epsilon Cluster Selection.” SN Computer Science 4, 422, 2023.
  17. D. Myalil et al. “Private Feature Delivery for Fraud Detection Using Federated Representation Learning.” PAKDD 2026, LNCS 16617, 2027.
  18. D. Myalil et al. “Decentralized Inter-Hospital Motor Imagery Detection using Robust Multiparty Model Aggregation.” CODS-COMAD ’24, 2025.
  19. Government of India. The Digital Personal Data Protection Act, 2023.

Views: 9