Skip to content
Conference Open access

Privacy-Preserving Counterfactual Explanations for Federated AI

2026 · Proceedings of the 23rd International Conference on Security and Cryptography · 0 citations · 34 references

Abstract

: As the usage of Artificial Intelligence (AI) for sensitive purposes increases, there is a growing need for privacy-aware explainable AI (XAI) tools. In this paper, we present a privacy-preserving counterfactual explanation algorithm . Our starting point is a decision-support model that is able to operate on vertically partitioned datasets, meaning that each party holds a different subset of datapoint attributes. The goal of a counterfactual algorithm is to find, given an observation , a datapoint from the (virtual) dataset that is closest to the observation but has a different label. Our algorithm fully preserves the privacy of the n datapoints belonging to the different parties by combining the strengths of homomorphic encryption and secret sharing . Through a number of experiments, we demonstrate the added value of combining multiple datasets in a realistic scenario and show that the privacy-preserving solution does not affect the accuracy. We fully implement our solution and demonstrate that it scales as to thousands of datapoints.

Read PDF

Similar papers

#federated learning Open access Oct 2026

SoK: Verifiable Integrity Claims for Privacy-Preserving Federated Learning

This SoK model federated learning as an append-only transcript of submissions, admissions, aggregation, and finalization events, and formalize verifiability as a collection of integrity claims issued by clients and the aggregator, and checked by different verifier classes.

Andrea Rizzini, Marco Esposito, Tommaso Gagliardoni et al. · 0 citations
Open access Oct 2026

Privacy Pass is Anamorphic: Practical Consequences and Attacks in the Black-box Model

It is proved that the three most prominent variants of Privacy Pass are anamorphic, which makes it insecure in a model where user's device or client application is working against them and can also be used to achieve a private metadata-like functionality.

Mirosław Kutyłowski, Oliwer Sobolewski · 0 citations
Conference Jul 2026

Quantifying and Preventing AI-Aware Privacy Leakage in Large-Scale Data Ecosystems: A Systematic Review

Now, AI runs on cloud platforms, edge systems with federated settings, and in large language model (LLM) pipelines or data-sharing services, creating even wider privacy leakage paths beyond classical database disclosure. This paper offers a systematic, structured review of the literature on a curated, cost-effective reference corpus for quantifying and preventing privacy leakage in AI-enabled data ecosystems. The review ties together four strands of research that are often treated separately. Firstly, the privacy risk throughout the AI life cycle. Secondly, the measurement of the quantitative leakage. Thirdly, architectures of the privacy-preserving models, and finally, operational governance for real-world deployment. Our analysis demonstrates that state-of-the-art approaches are moving from static mechanisms based on anonymization to metric-aware protections, including information-theoretic leakage scores, cumulative differential privacy accounting, personalized privacy budgets, and benchmark-driven attack evaluation. In parallel, prevention methods are evolving beyond single homomorphic noise injection and are becoming multi-layered defenses that combine differential privacy, federated learning, weight quantization, synthetic data generation, policy-driven automation, and LLM controls. The review uncovers four itchy gaps: fractured assessment metrics, shaky privacy-utility trade-offs, flimsy integration of technological controls and compliance processes, and low cross-context validation across cloud-based computing, edge computing (data processing at or near the source), federated learning (distributed machine-learning methods), and generative AI systems. The paper concludes by outlining a unified research agenda to build AI-aware, quantifiable, and usable privacy protection stacks.

Prodip Kumer Das, Amardeep Singh · 0 citations
Preprint Aug 2026

Privacy-Preserving AI Verification via Minimal Information Disclosure

This work introduces minimal information disclosure (MID), which designs and quantifies the information content of verifier-facing evidence itself and measures collateral leakage with conditional mutual information.

S. Abdelghafar, Gabriel Kulp · 0 citations
Review Jul 2026

Privacy-Preserving Framework Using Isolation Forest for Security

A systematic literature review of 50 studies published between 2018 and 2026 that combine machine-learningbased anomaly detection with privacy-enhancing technologies finds that FL combined with the lightweight Isolation Forest is the approach most frequently associated with a favourable trade-off between detection quality, privacy protection and computational cost.

Mahnoor Fatima, Ahmad Ijaz, Aoun E. Muhammad et al. · 0 citations
Preprint Jul 2026

Federated Learning Architecture: Data Privacy and System Security Approaches

It was concluded that strategies such as the careful selection of differential privacy parameters and training settings, along with the use of larger datasets, can improve the efficiency of FL and demonstrate that privacy-preserving and high-performance artificial intelligence systems can be securely applied in sensitive domains such as healthcare and finance.

Cagdas Karatas, Hibanur Karadogan, A. Ertug et al. · 0 citations