cs.LGOct 7, 2026

Efficient Provably Private Classification with a Tabular Foundation Model

Authors: Talal Alrawajfeh, Cristiana Diaconu, Ossi Räisä, Sebastian Rodriguez Beltran, Yuan He, John Bronskill, Richard E. Turner, Antti Honkela

Organizations: Department of Computer Science, University of Helsinki, Helsinki, Finland · Department of Engineering, University of Cambridge, Cambridge, United Kingdom · CISPA Helmholtz Center for Information Security, Saarbrücken, Germany · Current address: Vienna, Austria

Abstract

Tabular data underpin prediction and decision-making in medicine, finance, government and science, but often contain sensitive individual-level information, creating a need for accurate prediction while preserving privacy. Traditional private learning provides formal privacy guarantees, but requires slow dataset-specific optimisation, suffers substantial utility loss under strong privacy, and is often difficult to apply correctly. Tabular foundation models adapt rapidly to new datasets, but existing models lack formal privacy guarantees, and are highly vulnerable to membership-inference attacks, limiting their use on sensitive data. Here we introduce PrivTab, an easy to use tabular foundation model for differentially private classification that embeds a privacy mechanism within its architecture. Pretrained on simulated datasets, PrivTab uses in-context learning to transform sensitive rows into compact, provably private summaries---effectively learning how to learn under privacy. PrivTab outperforms private linear and neural-network baselines under moderate-to-strong privacy, shows negligible membership leakage, maintains well-calibrated predictions under strong privacy, and reduces dataset fitting time by 10,000 times, requiring only a single forward pass. By combining formal privacy, speed, and easy of use, PrivTab brings recent advances in AI to applications where sensitive individual-level data have limited their adoption.

Figures & tables

Appendix figures & tables49 assets

Supplementary material from the paper’s appendix.

Appendix

Explore similar work

CardsList
  1. TabPATE: Differentially Private Tabular In-Context Learning Without Public Data

    Jun 30, 2026Dariush Wahdany, Matthew Jagielski, Jesse C. Cresswell +2Privacy-Preserving Machine LearningMembership Inference Attacks

  2. On Privacy Leakage in Tabular Diffusion Models: Influential Factors, Attacker Knowledge, and Metrics

    May 7, 2026Masoumeh Shafieinejad, D. B. Emerson, Behnoosh Zamanlooy +5Membership Inference AttacksPrivacy