Federated Boosted Decision Trees with Differential Privacy
Samuel Maddock, Graham Cormode, Tianhao Wang, Carsten Maple, Somesh Jha
Abstract
There is great demand for scalable, secure, and efficient privacy-preserving machine learning models that can be trained over distributed data. While deep learning models typically achieve the best results in a centralized non-secure setting, different models can excel when privacy and communication constraints are imposed. Instead, tree-based approaches such as XGBoost have attracted much attention for their high performance and ease of use; in particular, they often achieve state-of-the-art results on tabular data. Consequently, several recent works have focused on translating Gradient Boosted Decision Tree (GBDT) models like XGBoost into federated settings, via cryptographic mechanisms such as Homomorphic Encryption (HE) and Secure Multi-Party Computation (MPC). However, these do not always provide formal privacy guarantees, or consider the full range of hyperparameters and implementation settings. In this work, we implement the GBDT model under Differential Privacy (DP). We propose a general framework that captures and extends existing approaches for differentially private decision trees. Our framework of methods is tailored to the federated setting, and we show that with a careful choice of techniques it is possible to achieve very high utility while maintaining strong levels of privacy.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 869bf2e4-de91-4b49-ad5f-422ef0782b9bCited by top-tier papers7
- Cross-silo Federated Learning with Record-level Personalized Differential PrivacyJunxu Liu, Jian Lou, Li Xiong, Jinfei Liu et al.CCS 2024 · 15 citations
- Effective and Efficient Federated Tree Learning on Hybrid DataQinbin Li, Chulin Xie, Xiaojun Xu, Xiaoyuan Liu et al.ICLR 2024 · 4 citations
- Clustering Sensitive Data through SeparationJohannes Liebenow, Yara Schütt, Tanya Braun, Marcel Gehrke et al.CCS 2024 · 1 citation
- S-BDT: Distributed Differentially Private Boosted Decision TreesThorsten Peinemann, Moritz Kirschte, Joshua Stock, Carlos Cotrini et al.CCS 2024 · 1 citation
- FP-Fed: Privacy-Preserving Federated Detection of Browser FingerprintingMeenatchi Sundaram Muthu Selva Annamalai, Igor Bilogrevic, Emiliano De CristofaroNDSS 2024
Builds on16
- Deep Learning with Differential PrivacyMartín Abadi, Andy Chu, Ian J. Goodfellow, H. Brendan McMahan et al.CCS 2016 · 7,620 citations
- Membership Inference Attacks Against Machine Learning ModelsReza Shokri, Marco Stronati, Congzheng Song, Vitaly ShmatikovS&P 2017 · 5,137 citations
- Practical Secure Aggregation for Privacy-Preserving Machine LearningKallista A. Bonawitz, Vladimir Ivanov, Ben Kreuter, Antonio Marcedone et al.CCS 2017 · 3,936 citations
- Revisiting Deep Learning Models for Tabular DataYury Gorishniy, Ivan Rubachev, Valentin Khrulkov, Artem BabenkoNeurIPS 2021 · 1,847 citations
- Membership Inference Attacks From First PrinciplesNicholas Carlini, Steve Chien, Milad Nasr, Shuang Song et al.S&P 2022 · 1,049 citations
Related papers
- Practical Federated Gradient Boosting Decision TreesQinbin Li, Zeyi Wen, Bingsheng HeAAAI 2020 · 215 citations
- SecureXGB: A Secure and Efficient Multi-party Protocol for Vertical Federated XGBoostZongda Han, Xiang Cheng, Wenhong Zhao, Jiaxin Fu et al.SIGMOD 2025 · 3 citations
- Gibbon: Faster Secure Two-party Training of Gradient Boosting Decision TreeLichun Li, Zecheng Wu, Yuan Zhao, Zhihao Li et al.CCS 2025
- Hadal: Centralized Label DP without a Trusted PartyJames Choncholas, Stanislav Peceny, Amit Agarwal, Mariana Raykova et al.S&P 2026
- Squirrel: A Scalable Secure Two-Party Computation Framework for Training Gradient Boosting Decision TreeWen-jie Lu, Zhicong Huang, Qizhi Zhang, Yuchen Wang et al.USENIX Security 2023
