Privacy-Preserving Machine Learning for Secure Artificial Intelligence Services

Authors

  • Genoveva Siering Department of Computer Science and Engineering, University of Nevada, Reno, Reno, NV, USA. Author
  • Qushi Sethi Department of Computer Science, University of North Texas, Denton, TX, USA. Author

Keywords:

privacy-preserving machine learning; secure artificial intelligence; federated learning; differential privacy; trustworthy infrastructure; AI governance

Abstract

Privacy-preserving machine learning has become a central concern for secure artificial intelligence services as organizations increasingly rely on sensitive data to train, adapt, and deploy predictive systems. Conventional centralized learning pipelines concentrate data, model parameters, and inference inputs within a single administrative domain, creating systemic exposure to membership inference, model extraction, unauthorized reuse, and regulatory noncompliance. This paper examines privacy-preserving machine learning as a system-level challenge rather than a purely cryptographic or statistical problem. It analyzes architectural patterns such as federated learning, secure aggregation, differential privacy, homomorphic encryption, secure multiparty computation, and trusted execution environments, while emphasizing the structural trade-offs they introduce in latency, utility, auditability, fairness, and operational resilience. The discussion extends to socio-technical infrastructures, governance mechanisms, and policy implications, arguing that secure artificial intelligence services require layered protections, clear accountability, and lifecycle oversight. Particular attention is given to federated learning as an infrastructure that redistributes computation and trust but does not eliminate privacy risk. Differential privacy is treated as an operational governance instrument whose utility costs must be negotiated across stakeholders. The paper also considers adversarial robustness, fairness, environmental sustainability, and cross-jurisdictional compliance. It concludes that privacy-preserving machine learning must be designed as an integrated service capability, combining secure computation, transparent governance, and continuous risk assessment. Without such integration, privacy protections may become fragmented, difficult to audit, or economically unsustainable, weakening public trust in artificial intelligence services.

References

1. Shokri, R., Stronati, M., Song, C., & Shmatikov, V. (2017). Membership inference attacks against machine learning models. In 2017 IEEE Symposium on Security and Privacy (SP) (pp. 3–18). IEEE. https://doi.org/10.1109/SP.2017.41

2. McMahan, H. B., Moore, E., Ramage, D., Hampson, S., & y Arcas, B. A. (2017). Communication-efficient learning of deep networks from decentralized data. In Proceedings of the 20th International Conference on Artificial Intelligence and Statistics (AISTATS) (pp. 1273–1282). PMLR.

3. Dwork, C., & Roth, A. (2014). The algorithmic foundations of differential privacy. Foundations and Trends in Theoretical Computer Science, 9(3–4), 211–407. https://doi.org/10.1561/0400000042

4. Abadi, M., Chu, A., Goodfellow, I., McMahan, H. B., Mironov, I., Talwar, K., & Zhang, L. (2016). Deep learning with differential privacy. In Proceedings of the 2016 ACM SIGSAC Conference on Computer and Communications Security (pp. 308–318). ACM. https://doi.org/10.1145/2976749.2978318

5. Bonawitz, K., Ivanov, V., Kreuter, B., Marcedone, A., McMahan, H. B., Patel, S., Ramage, D., Segal, A., & Seth, K. (2017). Practical secure aggregation for privacy-preserving machine learning. In Proceedings of the 2017 ACM SIGSAC Conference on Computer and Communications Security (pp. 1175–1191). ACM. https://doi.org/10.1145/3133956.3133982

6. Kairouz, P., McMahan, H. B., Avent, B., Bellet, A., Bennis, M., Bhagoji, A. N., ... Zhao, S. (2021). Advances and open problems in federated learning. Foundations and Trends in Machine Learning, 14(1–2), 1–210. https://doi.org/10.1561/2200000083

7. Li, T., Sahu, A. K., Talwalkar, A., & Smith, V. (2020). Federated learning: Challenges, methods, and future directions. IEEE Signal Processing Magazine, 37(3), 50–60. https://doi.org/10.1109/MSP.2020.2975749

8. Gentry, C. (2009). Fully homomorphic encryption using ideal lattices. In Proceedings of the 41st Annual ACM Symposium on Theory of Computing (pp. 169–178). ACM. https://doi.org/10.1145/1536414.1536440

9. Yao, A. C. (1986). How to generate and exchange secrets. In 27th Annual Symposium on Foundations of Computer Science (pp. 162–167). IEEE. https://doi.org/10.1109/SFCS.1986.25

10. Goldreich, O., Micali, S., & Wigderson, A. (1987). How to play any mental game. In Proceedings of the 19th Annual ACM Symposium on Theory of Computing (pp. 218–229). ACM. https://doi.org/10.1145/28395.28420

11. Costan, V., & Devadas, S. (2016). Intel SGX explained. IACR Cryptology ePrint Archive, 2016, 86. https://eprint.iacr.org/2016/086

12. Tramèr, F., Zhang, F., Juels, A., Reiter, M. K., & Ristenpart, T. (2016). Stealing machine learning models via prediction APIs. In 25th USENIX Security Symposium (pp. 601–618). USENIX Association.

13. Papernot, N., McDaniel, P., Sinha, A., & Wellman, M. P. (2018). SoK: Security and privacy in machine learning. In 2018 IEEE European Symposium on Security and Privacy (EuroS&P) (pp. 399–414). IEEE. https://doi.org/10.1109/EuroSP.2018.00035

14. Barocas, S., Hardt, M., & Narayanan, A. (2019). Fairness and machine learning: Limitations and opportunities. https://fairmlbook.org

15. Floridi, L., Cowls, J., Beltrametti, M., Chatila, R., Chazerand, P., Dignum, V., ... Vayena, E. (2018). AI4People—An ethical framework for a good AI society: Opportunities, risks, principles, and recommendations. Minds and Machines, 28(4), 689–707. https://doi.org/10.1007/s11023-018-9482-5

16. Veale, M., & Borgesius, F. Z. (2021). Demystifying the draft EU Artificial Intelligence Act. Computer Law Review International, 22(4), 97–112. https://doi.org/10.9785/cri-2021-220402

17. Mittelstadt, B. (2019). Principles alone cannot guarantee ethical AI. Nature Machine Intelligence, 1(11), 501–507. https://doi.org/10.1038/s42256-019-0114-4

18. Schwartz, R., Dodge, J., Smith, N. A., & Etzioni, O. (2020). Green AI. Communications of the ACM, 63(12), 54–63. https://doi.org/10.1145/3381831

19. Strubell, E., Ganesh, A., & McCallum, A. (2019). Energy and policy considerations for deep learning in NLP. In Proceedings of the 57th Annual Meeting of the Association for Computational Linguistics (pp. 3645–3650). ACL. https://doi.org/10.18653/v1/P19-1355

20. Narayanan, A., & Shmatikov, V. (2008). Robust de-anonymization of large sparse datasets. In 2008 IEEE Symposium on Security and Privacy (pp. 111–125). IEEE. https://doi.org/10.1109/SP.2008.33

Downloads

Published

2026-04-05