← Search

Aurélien Bellet

41 accepted papers

2026

Adaptive Personalized Federated Learning via Multi-task Averaging of Kernel Mean Embeddings

ICML 2026poster

Personalized Federated Learning enables a collection of agents to collaboratively learn individual models without sharing raw data. We propose a new approach in which each agent optimizes a weighted combination of all agents' empirical risks, with the weights learned from data rather than specified …

Cited by 0SourceScholar
2026

Federated Causal Inference on Multi-Site Observational Data via Propensity Score Aggregation

ICML 2026poster

Causal inference typically assumes centralized access to individual-level data. Yet, in practice, data are often decentralized across multiple sites, making centralization infeasible due to privacy, logistical, or legal constraints. We address this problem by estimating the Average Treatment Effect …

Cited by 0SourceScholar
2026

Optimal Transport under Group Fairness Constraints

ICML 2026spotlight

Ensuring fairness in matching algorithms is a key challenge in allocating scarce resources and positions. Focusing on Optimal Transport (OT), we introduce a novel notion of group fairness requiring that the probability of matching two individuals from any two given groups in the OT plan satisfies a …

Cited by 0SourceScholar
2026

Private Rate-Constrained Optimization with Applications to Fair Learning

ICLR 2026poster

Many problems in trustworthy ML can be expressed as constraints on prediction rates across subpopulations, including group fairness constraints (demographic parity, equalized odds, etc.). In this work, we study such constrained minimization problems under differential privacy (DP). Standard DP optim…

Cited by 0SourceScholar
2026

Tight Stability Bounds for Robust Distributed Learning: Byzantine Failures Hurt Generalization More than Data Poisoning

ICML 2026poster

Robust distributed learning algorithms aim to maintain reliable performance despite the presence of misbehaving workers. Such misbehaviors are commonly modeled as *Byzantine failures*, allowing arbitrarily corrupted communication, or as *data poisoning*, a weaker form of corruption restricted to loc…

Cited by 0SourceScholar
2026

Unified Privacy Guarantees for Decentralized Learning via Matrix Factorization

ICLR 2026poster

Decentralized Learning (DL) enables users to collaboratively train models without sharing raw data by iteratively averaging local updates with neighbors in a network graph. This setting is increasingly popular for its scalability and its ability to keep data local under user control. Strong privacy…

Cited by 0SourcecodeScholar
2025

Federated Causal Inference: Multi-Study ATE Estimation beyond Meta-Analysis

AISTATS 2025poster

We study Federated Causal Inference, an approach to estimate treatment effects from decentralized data across centers. We compare three classes of Average Treatment Effect (ATE) estimators derived from the Plug-in G-Formula, ranging from simple meta-analysis to one-shot and multi-shot federated lear…

Cited by 0SourceScholar
2025

Privacy Amplification Through Synthetic Data: Insights from Linear Regression

ICML 2025poster

Synthetic data inherits the differential privacy guarantees of the model used to generate it. Additionally, synthetic data may benefit from privacy amplification when the generative model is kept hidden. While empirical studies suggest this phenomenon, a rigorous theoretical understanding is still l…

Cited by 0SourcePDFScholar
2025

Tighter Privacy Auditing of DP-SGD in the Hidden State Threat Model

ICLR 2025poster

Machine learning models can be trained with formal privacy guarantees via differentially private optimizers such as DP-SGD. In this work, we focus on a threat model where the adversary has access only to the final model, with no visibility into intermediate updates. In the literature, this ``hidden…

Cited by 12SourcePDFScholar
2024

Confidential-DPproof: Confidential Proof of Differentially Private Training

ICLR 2024spotlight

Post hoc privacy auditing techniques can be used to test the privacy guarantees of a model, but come with several limitations: (i) they can only establish lower bounds on the privacy loss, (ii) the intermediate model updates and some data must be shared with the auditor to get a better approximation…

Cited by 5SourcePDFScholar
2024

DP-SGD Without Clipping: The Lipschitz Neural Network Way

ICLR 2024poster

State-of-the-art approaches for training Differentially Private (DP) Deep Neural Networks (DNN) face difficulties to estimate tight bounds on the sensitivity of the network's layers, and instead rely on a process of per-sample gradient clipping. This clipping process not only biases the direction of…

2024

Differentially Private Decentralized Learning with Random Walks

ICML 2024poster

The popularity of federated learning comes from the possibility of better scalability and the ability for participants to keep control of their data, improving data security and sovereignty. Unfortunately, sharing model updates also creates a new privacy attack surface. In this work, we characterize…

2024

Improved Stability and Generalization Guarantees of the Decentralized SGD Algorithm

ICML 2024poster

This paper presents a new generalization error analysis for Decentralized Stochastic Gradient Descent (D-SGD) based on algorithmic stability. The obtained results overhaul a series of recent works that suggested an increased instability due to decentralization and a detrimental impact of poorly-conn…

Cited by 6SourcePDFScholar
2024

Rényi Pufferfish Privacy: General Additive Noise Mechanisms and Privacy Amplification by Iteration via Shift Reduction Lemmas

ICML 2024poster

Pufferfish privacy is a flexible generalization of differential privacy that allows to model arbitrary secrets and adversary's prior knowledge about the data. Unfortunately, designing general and tractable Pufferfish mechanisms that do not compromise utility is challenging. Furthermore, this framewo…

Cited by 3SourcePDFScholar
2024

The Relative Gaussian Mechanism and its Application to Private Gradient Descent

AISTATS 2024poster

The Gaussian Mechanism (GM), which consists in adding Gaussian noise to a vector-valued query before releasing it, is a standard privacy protection mechanism. In particular, given that the query respects some L2 sensitivity property (the L2 distance between outputs on any two neighboring inputs is b…

Cited by 2SourcePDFScholar
2023

Differential Privacy has Bounded Impact on Fairness in Classification

ICML 2023poster

We theoretically study the impact of differential privacy on fairness in classification. We prove that, given a class of models, popular group fairness measures are pointwise Lipschitz-continuous with respect to the parameters of the model. This result is a consequence of a more general statement on…

2023

Fair Without Leveling Down: A New Intersectional Fairness Definition

EMNLP 2023long main

In this work, we consider the problem of intersectional group fairness in the classification setting, where the objective is to learn discrimination-free models in the presence of several intersecting sensitive groups. First, we illustrate various shortcomings of existing fairness measures commonly…

Cited by 0SourceScholar
2023

From Noisy Fixed-Point Iterations to Private ADMM for Centralized and Federated Learning

ICML 2023poster

We study differentially private (DP) machine learning algorithms as instances of noisy fixed-point iterations, in order to derive privacy and utility results from this well-studied framework. We show that this new perspective recovers popular private gradient-based methods like DP-SGD and provides a…

2023

High-Dimensional Private Empirical Risk Minimization by Greedy Coordinate Descent

AISTATS 2023poster

In this paper, we study differentially private empirical risk minimization (DP-ERM). It has been shown that the worst-case utility of DP-ERM reduces polynomially as the dimension increases. This is a major obstacle to privately learning large machine learning models. In high dimension, it is common…

Cited by 7SourcePDFScholar
2023

One-Shot Federated Conformal Prediction

ICML 2023poster

In this paper, we present a Conformal Prediction method that computes prediction sets in a one-shot Federated Learning (FL) setting. More specifically, we introduce a novel quantile-of-quantiles estimator and prove that for any distribution, it is possible to compute prediction sets with desired cov…

2023

Refined Convergence and Topology Learning for Decentralized SGD with Heterogeneous Data

AISTATS 2023poster

One of the key challenges in decentralized and federated learning is to design algorithms that efficiently deal with highly heterogeneous data distributions across agents. In this paper, we revisit the analysis of Decentralized Stochastic Gradient Descent algorithm (D-SGD) under data heterogeneity.…

Cited by 42SourcePDFScholar
2022

Differentially Private Coordinate Descent for Composite Empirical Risk Minimization

ICML 2022spotlight

Machine learning models can leak information about the data used to train them. To mitigate this issue, Differentially Private (DP) variants of optimization algorithms like Stochastic Gradient Descent (DP-SGD) have been designed to trade-off utility for privacy in Empirical Risk Minimization (ERM) p…

Cited by 21SourcePDFScholar
2022

Differentially Private Federated Learning on Heterogeneous Data

AISTATS 2022poster

Federated Learning (FL) is a paradigm for large-scale distributed learning which faces two key challenges: (i) training efficiently from highly heterogeneous user data, and (ii) protecting the privacy of participating users. In this work, we propose a novel FL approach (DP-SCAFFOLD) to tackle these…

2022

FLamby: Datasets and Benchmarks for Cross-Silo Federated Learning in Realistic Healthcare Settings

NeurIPS 2022accept

Federated Learning (FL) is a novel approach enabling several clients holding sensitive data to collaboratively train machine learning models, without centralizing data. The cross-silo FL setting corresponds to the case of few ($2$--$50$) reliable clients, each holding medium to large datasets, and i…

2022

Fair NLP Models with Differentially Private Text Encoders

EMNLP 2022finding

Encoded text representations often capture sensitive attributes about individuals (e.g., race or gender), which raise privacy concerns and can make downstream models unfair to certain groups. In this work, we propose FEDERATE, an approach that combines ideas from differential privacy and adversarial…

2022

Muffliato: Peer-to-Peer Privacy Amplification for Decentralized Optimization and Averaging

NeurIPS 2022accept

Decentralized optimization is increasingly popular in machine learning for its scalability and efficiency. Intuitively, it should also provide better privacy guarantees, as nodes only observe the messages sent by their neighbors in the network graph. But formalizing and quantifying this gain is chal…

2021

Federated Multi-Task Learning under a Mixture of Distributions

NeurIPS 2021poster

The increasing size of data generated by smartphones and IoT devices motivated the development of Federated Learning (FL), a framework for on-device collaborative training of machine learning models. First efforts in FL focused on learning a single global model with good average performance across c…

2021

Learning Fair Scoring Functions: Bipartite Ranking under ROC-based Fairness Constraints

AISTATS 2021poster

Many applications of AI involve scoring individuals using a learned function of their attributes. These predictive risk scores are then used to take decisions based on whether the score exceeds a certain threshold, which may vary depending on the context. The level of delegation granted to such syst…

Cited by 35SourcePDFScholar
2020

Evaluating Voice Conversion-Based Privacy Protection against Informed Attackers

ICASSP 2020accepted

Speech data conveys sensitive speaker attributes like identity or accent. With a small amount of found data, such attributes can be inferred and exploited for malicious purposes: voice cloning, spoofing, etc. Anonymization aims to make the data unlinkable, i.e., ensure that no utterance can be linke…

Cited by 0SourceScholar
2020

Fully Decentralized Joint Learning of Personalized Models and Collaboration Graphs

AISTATS 2020poster

We consider the fully decentralized machine learning scenario where many users with personal datasets collaborate to learn models through local peer-to-peer exchanges, without a central coordinator. We propose to train personalized models that leverage a collaboration graph describing the relationsh…

2020

Private Protocols for U-Statistics in the Local Model and Beyond

AISTATS 2020poster

In this paper, we study the problem of computing $U$-statistics of degree $2$, i.e., quantities that come in the form of averages over pairs of data points, in the local model of differential privacy (LDP). The class of $U$-statistics covers many statistical estimates of interest, including Gini mea…

Cited by 12SourcePDFScholar
2018

A Probabilistic Theory of Supervised Similarity Learning for Pointwise ROC Curve Optimization

ICML 2018oral

The performance of many machine learning techniques depends on the choice of an appropriate similarity or distance measure on the input space. Similarity learning (or metric learning) aims at building such a measure from training data so that observations with the same (resp. different) label are as…

Cited by 24SourcePDFScholar
2018

Personalized and Private Peer-to-Peer Machine Learning

AISTATS 2018poster

The rise of connected personal devices together with privacy concerns call for machine learning algorithms capable of leveraging the data of a large number of agents to learn personalized models under strong privacy requirements. In this paper, we introduce an efficient algorithm to address the abov…

Cited by 0SourcePDFScholar
2017

Decentralized Collaborative Learning of Personalized Models over Networks

AISTATS 2017poster

We consider a set of learning agents in a collaborative peer-to-peer network, where each agent learns a personalized model according to its own learning objective. The question addressed in this paper is: how can agents improve upon their locally trained model by communicating with other agents that…

Cited by 288SourcePDFScholar
2016

A comparison between deep neural nets and kernel acoustic models for speech recognition

ICASSP 2016accepted

We study large-scale kernel methods for acoustic modeling and compare to DNNs on performance metrics related to both acoustic modeling and recognition. Measuring perplexity and frame-level classification accuracy, kernel-based acoustic models are as effective as their DNN counterparts. However, on t…

Cited by 0SourceScholar
2016

On Graph Reconstruction via Empirical Risk Minimization: Fast Learning Rates and Scalability

NeurIPS 2016poster

The problem of predicting connections between a set of data points finds many applications, in systems biology and social network analysis among others. This paper focuses on the \textit{graph reconstruction} problem, where the prediction rule is obtained by minimizing the average error over all n(n…

Cited by 10SourcePDFScholar
2015

Extending Gossip Algorithms to Distributed Estimation of U-statistics

NeurIPS 2015spotlight

Efficient and robust algorithms for decentralized estimation in networks are essential to many distributed systems. Whereas distributed estimation of sample mean statistics has been the subject of a good deal of attention, computation of U-statistics, relying on more expensive averaging over pairs o…

Cited by 15SourcePDFScholar
2015

SGD Algorithms based on Incomplete U-statistics: Large-Scale Minimization of Empirical Risk

NeurIPS 2015poster

In many learning problems, ranging from clustering to ranking through metric learning, empirical estimates of the risk functional consist of an average over tuples (e.g., pairs or triplets) of observations, rather than over individual observations. In this paper, we focus on how to best implement a…

Cited by 23SourcePDFScholar