Hadal: Centralized Label DP without a Trusted Party
James Choncholas, Stanislav Peceny, Amit Agarwal, Mariana Raykova, Baiyu Li, Karn Seth
Abstract
We explore distributed training in a setting where features are held by one party and labels are held by another. In this context, we focus on label Differential Privacy (DP), where the labels require privacy protection from the other party who learns the trained model. Previous approaches struggle to train accurate models in high-privacy settings (i.e. when ), or typically require a trusted third party. To eliminate this trusted party while preserving model utility, we present PostScale, a novel Homomorphic Encryption (HE)based protocol suited for high-privacy regimes with ciphertext multiplicative depth of two. Our protocol is suitable for a wide variety of models in the semi-honest setting and avoids leaking the model architecture as well as costly ciphertext operations like bootstrapping and rotations. We also present a multiparty sampling protocol for generating DP noise, and Hadal, a general-purpose dataflow-based framework for encrypted computation implementing our protocols. Hadal repurposes existing tools for use with HE, including comprehensive performance profiling capabilities, dual execution modes (eager and deferred), graph compiler-based optimization, and hyperparameter tuning. Our techniques achieve model utility similar to centralized DP while reducing communication by over 90 % (from 1 TB to 8 GB per batch) and training time by 99 % (from 54 minutes to 33 seconds) compared to related work that protects both features and labels. These improvements unlock larger models; we train Bert-tiny of Devlin et al. (2019), with of parameters, in 20 ms per example in a LAN setting.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get 2551e202-178d-46ab-85da-2a2cf6071c8aRelated papers
- All Rivers Run to the Sea: Private Learning with Asymmetric FlowsYue Niu, Ramy E. Ali, Saurav Prakash, Salman AvestimehrCVPR 2024
- Federated Boosted Decision Trees with Differential PrivacySamuel Maddock, Graham Cormode, Tianhao Wang, Carsten Maple et al.CCS 2022 · 31 citations
- ReBoot: Encrypted Training of Deep Neural Networks with CKKS BootstrappingAlberto Pirillo, Luca ColomboAAAI 2026
- Revisiting ML Training under Fully Homomorphic Encryption: Convergence Guarantees, Differential Privacy, and Efficient AlgorithmsYvonne Zhou, Mingyu Liang, Ivan Brugere, Danial Dervovic et al.ICML 2026
- DictPFL: Efficient and Private Federated Learning on Encrypted GradientsJiaqi Xue, Mayank Kumar, Yuzhang Shang, Shangqian Gao et al.NeurIPS 2025 · 4 citations
