← Search

Jonathan Ullman

18 accepted papers

2026

Black-Box Privacy Attacks on Shared Representations in Multitask Learning

ICLR 2026poster

The proliferation of diverse data across users and organizations has driven the development of machine learning methods that enable multiple entities to jointly train models while minimizing data sharing. Among these, *multitask learning* (MTL) is a powerful paradigm that leverages similarities amon…

Cited by 0SourceScholar
2025

Privacy in Metalearning and Multitask Learning: Modeling and Separations

AISTATS 2025poster

Model personalization allows a set of individuals, each facing a different learning task, to train models that are more accurate for each person than those they could develop individually. The goals of personalization are captured in a variety of formal frameworks, such as multitask learning and met…

Cited by 0SourceScholar
2024

Chameleon: Increasing Label-Only Membership Leakage with Adaptive Poisoning

ICLR 2024poster

The integration of Machine Learning (ML) in numerous critical applications introduces a range of privacy concerns for individuals who provide their datasets for ML training purposes. One such privacy risk is Membership Inference (MI), in which an adversary seeks to determine whether a particular dat…

Cited by 7SourcePDFScholar
2024

How to Make the Gradients Small Privately: Improved Rates for Differentially Private Non-Convex Optimization

ICML 2024poster

We provide a simple and flexible framework for designing differentially private algorithms to find approximate stationary points of non-convex loss functions. Our framework is based on using a private approximate risk minimizer to "warm start" another private algorithm for finding stationary points.…

2021

Covariance-Aware Private Mean Estimation Without Private Covariance Estimation

NeurIPS 2021spotlight

We present two sample-efficient differentially private mean estimators for $d$-dimensional (sub)Gaussian distributions with unknown covariance. Informally, given $n \gtrsim d/\alpha^2$ samples from such a distribution with mean $\mu$ and covariance $\Sigma$, our estimators output $\tilde\mu$ such th…

Cited by 75SourcePDFScholar
2021

Leveraging Public Data for Practical Private Query Release

ICML 2021spotlight

In many statistical problems, incorporating priors can significantly improve performance. However, the use of prior knowledge in differentially private query release has remained underexplored, despite such priors commonly being available in the form of public datasets, such as previous US Census re…

2020

Auditing Differentially Private Machine Learning: How Private is Private SGD?

NeurIPS 2020poster

We investigate whether Differentially Private SGD offers better privacy in practice than what is guaranteed by its state-of-the-art analysis. We do so via novel data poisoning attacks, which we show correspond to realistic privacy attacks. While previous work (Ma et al., arXiv 2019) proposed this co…

2020

CoinPress: Practical Private Mean and Covariance Estimation

NeurIPS 2020poster

We present simple differentially private estimators for the parameters of multivariate sub-Gaussian data that are accurate at small sample sizes. We demonstrate the effectiveness of our algorithms both theoretically and empirically using synthetic and real-world datasets---showing that their asympt…

2020

Private Identity Testing for High-Dimensional Distributions

NeurIPS 2020spotlight

In this work we present novel differentially private identity (goodness-of-fit) testers for natural and widely studied classes of multivariate product distributions: Gaussians in R^d with known covariance and product distributions over {\pm 1}^d. Our testers have improved sample complexity compared…

Cited by 51SourcePDFScholar
2020

Private Query Release Assisted by Public Data

ICML 2020poster

We study the problem of differentially private query release assisted by access to public data. In this problem, the goal is to answer a large class $\mathcal{H}$ of statistical queries with error no more than $\alpha$ using a combination of public and private samples. The algorithm is required to s…

Cited by 68SourcePDFScholar
2019

Differentially Private Algorithms for Learning Mixtures of Separated Gaussians

NeurIPS 2019poster

Learning the parameters of Gaussian mixture models is a fundamental and widely studied problem with numerous applications. In this work, we give new algorithms for learning the parameters of a high-dimensional, well separated, Gaussian mixture model subject to the strong constraint of differential p…

Cited by 63SourcePDFScholar
2019

Differentially Private Fair Learning

ICML 2019oral

Motivated by settings in which predictive models may be required to be non-discriminatory with respect to certain attributes (such as race), but even collecting the sensitive attribute may be forbidden or restricted, we initiate the study of fair learning under the constraint of differential privacy…

Cited by 202SourcePDFScholar
2016

Privacy Odometers and Filters: Pay-as-you-Go Composition

NeurIPS 2016poster

In this paper we initiate the study of adaptive composition in differential privacy when the length of the composition, and the privacy parameters themselves can be chosen adaptively, as a function of the outcome of previously run analyses. This case is much more delicate than the setting covered by…

Cited by 122SourcePDFScholar