cs.LGSep 30, 2026

Certification-Based Differentially Private Learning

Authors: Mihnea Ghitu, Matthew Wicker

Organizations: Department of Computing Imperial College London London, United Kingdom

Abstract

Differential privacy (DP) in machine learning is typically achieved by adding noise to model parameters (private learning) or to model outputs (private prediction). Recent work uses formal methods, namely abstract interpretation, to provide tighter privacy guarantees, but only for private prediction in classification settings. In this work, we investigate the use of formal methods as a general tool for tighter privacy analysis. First, we generalize the abstract gradient training (AGT) framework to private prediction in continuous, unbounded regression. Second, by reducing learning in parameterized models to a regression problem over the parameter space, we introduce Abstract Gradient Sampling (AGS), an algorithm that enables reachability-based analysis to provide guarantees for private learning. In both private prediction and private learning, we provide tightened privacy accounting for the AGT framework and a theoretical analysis demonstrating when our smooth sensitivity upper-bounds yield favourable privacy-utility trade-off. In practice, we validate that our regression bounds are tighter than global-sensitivity baselines on regression benchmarks, and, notably, yield the first finite privacy guarantees in settings where global prediction sensitivity is a priori unbounded. We also find that under matched conditions, our private learning algorithm can outperform standard private learners.

Figures & tables

Appendix figures & tables7 assets

Supplementary material from the paper’s appendix.

Appendix

Explore similar work

CardsList
  1. From Privacy to Generalization: Linear Max-Information Bounds for Differentially Private Learning Algorithms

    May 25, 2026Christoph H. Lampert, Max Cairney-Leeming, Hossein ZakeriniaStandard Differential-PrivacyGeneralization Bounds

  2. Revisiting ML Training under Fully Homomorphic Encryption: Convergence Guarantees, Differential Privacy, and Efficient Algorithms

    May 27, 2026Yvonne Zhou, Mingyu Liang, Ivan Brugere +5Homomorphic EncryptionConvergence

  3. Label Differential Privacy via Aggregation

    Date pendingAnand Brahmbhatt, Rishi Saket, Shreyas Havaldar +3Standard Differential-PrivacyΔ)$-Differential Privacy