2026· Proceedings of the 23rd International Conference on Security and Cryptography· 0 citations· 34 references
Abstract
: As the usage of Artificial Intelligence (AI) for sensitive purposes increases, there is a growing need for privacy-aware explainable AI (XAI) tools. In this paper, we present a privacy-preserving counterfactual explanation algorithm . Our starting point is a decision-support model that is able to operate on vertically partitioned datasets, meaning that each party holds a different subset of datapoint attributes. The goal of a counterfactual algorithm is to find, given an observation , a datapoint from the (virtual) dataset that is closest to the observation but has a different label. Our algorithm fully preserves the privacy of the n datapoints belonging to the different parties by combining the strengths of homomorphic encryption and secret sharing . Through a number of experiments, we demonstrate the added value of combining multiple datasets in a realistic scenario and show that the privacy-preserving solution does not affect the accuracy. We fully implement our solution and demonstrate that it scales as to thousands of datapoints.
This SoK model federated learning as an append-only transcript of submissions, admissions, aggregation, and finalization events, and formalize verifiability as a collection of integrity claims issued by clients and the aggregator, and checked by different verifier classes.
Andrea Rizzini, Marco Esposito, Tommaso Gagliardoni et al.· Proceedings on Privacy Enhan...· 0 citations
It is proved that the three most prominent variants of Privacy Pass are anamorphic, which makes it insecure in a model where user's device or client application is working against them and can also be used to achieve a private metadata-like functionality.
Mirosław Kutyłowski, Oliwer Sobolewski· Proceedings on Privacy Enhan...· 0 citations
Now, AI runs on cloud platforms, edge systems with federated settings, and in large language model (LLM) pipelines or data-sharing services, creating even wider privacy leakage paths beyond classical database disclosure. This paper offers a systematic, structured review of the literature on a curated, cost-effective reference corpus for quantifying and preventing privacy leakage in AI-enabled data ecosystems. The review ties together four strands of research that are often treated separately. Firstly, the privacy risk throughout the AI life cycle. Secondly, the measurement of the quantitative leakage. Thirdly, architectures of the privacy-preserving models, and finally, operational governance for real-world deployment. Our analysis demonstrates that state-of-the-art approaches are moving from static mechanisms based on anonymization to metric-aware protections, including information-theoretic leakage scores, cumulative differential privacy accounting, personalized privacy budgets, and benchmark-driven attack evaluation. In parallel, prevention methods are evolving beyond single homomorphic noise injection and are becoming multi-layered defenses that combine differential privacy, federated learning, weight quantization, synthetic data generation, policy-driven automation, and LLM controls. The review uncovers four itchy gaps: fractured assessment metrics, shaky privacy-utility trade-offs, flimsy integration of technological controls and compliance processes, and low cross-context validation across cloud-based computing, edge computing (data processing at or near the source), federated learning (distributed machine-learning methods), and generative AI systems. The paper concludes by outlining a unified research agenda to build AI-aware, quantifiable, and usable privacy protection stacks.
This work introduces minimal information disclosure (MID), which designs and quantifies the information content of verifier-facing evidence itself and measures collateral leakage with conditional mutual information.
A systematic literature review of 50 studies published between 2018 and 2026 that combine machine-learningbased anomaly detection with privacy-enhancing technologies finds that FL combined with the lightweight Isolation Forest is the approach most frequently associated with a favourable trade-off between detection quality, privacy protection and computational cost.
Mahnoor Fatima, Ahmad Ijaz, Aoun E. Muhammad et al.· ICACNC 2026 Proceedings· 0 citations
It was concluded that strategies such as the careful selection of differential privacy parameters and training settings, along with the use of larger datasets, can improve the efficiency of FL and demonstrate that privacy-preserving and high-performance artificial intelligence systems can be securely applied in sensitive domains such as healthcare and finance.
Cagdas Karatas, Hibanur Karadogan, A. Ertug et al.· 0 citations