Workshop 2

Privacy-preserving Machine Learning and Privacy in Distributed Settings

Aarhus, Denmark

November 2-4, 2026

Overview

Workshop 2 is part of the Data Privacy in Machine Learning P1 program. It will focus on privacy in limited-trust settings, with particular interest in approaches that bring together ideas from differential privacy, decentralized learning, secure computation, and cryptography.

The program includes invited talks by Christoph Lampert, Christian Rechberger, Edwige Cyffers, Christian Weinert, and Tamer Mour, as well as contributed talks selected through the call for contributions. The first day of the workshop will be a day of tutorials on differentially private machine learning and cryptography.

Registration

Registration deadline: October 28, 2026

Cost: 675 DKK

Register for the workshop

Speakers

Christoph Lampert

Christoph Lampert

Professor, Institute of Science and Technology Austria

Christian Rechberger

Christian Rechberger

Professor, TU Graz

Edwige Cyffers

Edwige Cyffers

CNRS Researcher, Lamsade at Dauphine University in Paris

Christian Weinert

Christian Weinert

Associate Professor, Royal Holloway, University of London

Tamer Mour

Tamer Mour

Principal Investigator, The Italian Institute of Artificial Intelligence (AI4I)

Call for Contributions

We are seeking submissions for 20-30 minute talks on topics related to privacy-preserving machine learning and privacy in distributed settings. The workshop will not have a poster session.

Topics of interest include:

Submission deadline September 10, 2026
Decisions sentSeptember 17, 2026
Submission formSubmit a talk
Registration formRegister for the workshop by October 28, 2026

Preliminary Agenda

Tutorial: Primer on Differentially Private Machine Learning IHannah Keller
Coffee break
Tutorial: Primer on Differentially Private Machine Learning IITamalika Mukherjee
Lunch break
Tutorial: Cryptography Primer ITamer Mour
Coffee break
Tutorial: Cryptography Primer II

Invited TalkEdwige Cyffers
Coffee break
Contributed TalksDithered Gaussian Mechanism for Randomness-Efficient Differential PrivacyNikita Kalinin, Rasmus Pagh Lower Bounds for Private Graph Optimization Problems using Reconstruction AttacksJacob Imola, Rasmus Pagh, Lukas Retschmeier Edit-Neighboring Data Streams and Privacy under Continual ObservationJoel Daniel Andersson, Anamay Chaturvedi, Monika Henzinger, Roodabeh Safavi
Lunch break
Invited TalkRecent Advances in MPC-based Secure Neural Network InferenceChristian Weinert Efficient secure neural network inference (SNNI) has been extensively studied over the past 10 years. However, recent foundational improvements have stagnated in favour of exploring the intricacies of transformer architectures. In this talk, we revisit SNNI in the context of emerging real-world deployment scenarios, including settings in which the model owner, or even all parties, know the model parameters in the clear. We show how a combination of improved function-dependent preprocessing, new MPC primitives, aggressive ML/MPC co-design, and implementation-level optimisations can substantially improve performance. Together, these techniques enable privacy-preserving evaluation of ResNet50 on ImageNet samples with amortized online runtimes below 0.1 seconds.
Contributed Talks Accelerating Multiparty Noise Generation Using LookupsFredrik Meisingseth, Christian Rechberger, Fabian Schmid Secret Shared Floating Point Computation for Private Neural Network Fine-TuningHendrik Eerikson, Sona Kravtšenko, Hiroki Kaminaga, Pille Pullonen-Raudvere, Liina Kamm, Sven Laur Binarized Neural Network Inference with Half-Authenticated TriplesSebastian Hasler
Coffee break
Invited TalkTamer Mour

Invited TalkChristoph Lampert
Coffee break
Contributed Talks When Topology Betrays Privacy: Lattice-Based Reconstruction Attacks on Secure Aggregation in Decentralized Federated LearningWenrui Yu, Changlong Ji, Johannes Bjerva, Qiongxiu Li Towards Practical vFHE: Privacy-preserving and Verifiable Machine Learning Ignacio Cascudo, Anamaria Costache, Daniele Cozzo, Dario Fiore, Antonio Guimaraes, Eduardo Soria-Vazquez Encrypted neural networks without overflowsPhilipp Kern, Lorenzo Rovida, Samuel Teuber, Edoardo Manino, Carsten Sinz, Alberto Leporati
Lunch break
Invited TalkChristian Rechberger

Venue

Location: Aarhus, Denmark

More details to come

Organizers

Hannah Keller

Hannah Keller

Claudio Orlandi

Claudio Orlandi

Rasmus Pagh

Rasmus Pagh

Amartya Sanyal

Amartya Sanyal