Skip to content

On the Privacy-Preserving Capabilities of PAVE Specifications in Learnware ∗

· 0 citations · 24 references

TL;DR

This paper formalizes two specification-induced risks in the learnware paradigm and shows that the resulting DP guarantees control both disclosure risk and amplification risk, and analyzes the induced privacy–utility trade-off to guide effective learn-ware identification while preserving privacy.

View source

Similar papers

Preprint Aug 2026

Privacy-Preserving AI Verification via Minimal Information Disclosure

This work introduces minimal information disclosure (MID), which designs and quantifies the information content of verifier-facing evidence itself and measures collateral leakage with conditional mutual information.

S. Abdelghafar, Gabriel Kulp · 0 citations
#federated learning Open access Oct 2026

SoK: Verifiable Integrity Claims for Privacy-Preserving Federated Learning

This SoK model federated learning as an append-only transcript of submissions, admissions, aggregation, and finalization events, and formalize verifiability as a collection of integrity claims issued by clients and the aggregator, and checked by different verifier classes.

Andrea Rizzini, Marco Esposito, Tommaso Gagliardoni et al. · 0 citations
Preprint Aug 2026

The Anonymity Gap: Understanding Real Privacy in Shielded UTXO-based Protocols for DeFi

A layered system model and an analysis pipeline that uses prior history as the temporal baseline, applies cumulative pruning and cross-proof propagation to each proof's Commitment Set, and recursively traces the survivors through historical hidden-state transitions to derive the final transaction-level Anonymity Set Size is proposed.

Hanze Guo, Stefanos Chaliasos, Yebo Feng et al. · 0 citations
Preprint Jul 2026

Certified in Theory, Broken in Practice: Assumption Gaps in Cryptographic Model Certification

This work formalizes rigorous cryptographic security notions tailored to CMC frameworks, introduces a generic protocol template, and proves that it satisfies these requirements, which offer both cautionary evidence about existing approaches and constructive guidance for designing secure, privacy-preserving ML auditing protocols.

Carter Luck, Olive Franzese-McLaughlin, Elisaweta Masserova et al. · 0 citations
Open access Oct 2026

Privacy Pass is Anamorphic: Practical Consequences and Attacks in the Black-box Model

It is proved that the three most prominent variants of Privacy Pass are anamorphic, which makes it insecure in a model where user's device or client application is working against them and can also be used to achieve a private metadata-like functionality.

Mirosław Kutyłowski, Oliwer Sobolewski · 0 citations
Open access Oct 2026

Beyond the Output: Inference Attacks on Private Set Union and Multi-Key Private Matching

Recent work (Falzon and Tang USENIX 2025) has shown that a protocol participant who behaves honestly but strategically chooses its inputs can break input privacy in the Private Join and Compute functionality. In this work, we expand our understanding of attacks in this setting by investigating a broader class of functionalities, namely: Private Set Union (PSU), PSU-Cardinality (PSU-CA), and Meta’s multi-key private matching (MKPM) functionality. We begin with a simple yet novel attack on PSU that fully reconstructs the intersection using only two protocol invocations and forms the conceptual foundation for our more complex attacks. We also show that any attack on PSI-Cardinality, such as that of Guo et al. (USENIX 2023), lifts to an attack on PSU-CA that recovers the intersection with only three additional queries. For the MKPM protocol, we distinguish its intended matching functionality from the protocol-specific leakage, give an attack against the intended functionality, and then show that exploiting the additional leakage enables even stronger attacks, including partial reconstruction of the other party’s records from a single protocol invocation. We conclude by discussing possible mitigations for deploying such systems. Our analysis demonstrates limitations of existing secure multi-party computation security definitions and highlights the real-world privacy risks associated with deploying these functionalities in practice.

Andrea Raguso, Francesca Falzon, Tianxin Tang et al. · 0 citations