VLDB 2026 Research / reviewers in the wild / expert
Jonas Böhler
dblp:202/6734
· DBLP profile ↗
5ranked-venue papers
4as first author
2since 2021 · last 2026
—ORCID · none
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 5 · 4 first-author · 2 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | SPRINT: Scalable Secure & Differentially Private Inference for TransformersabstractMachine learning as a service (MLaaS) enables scalable model deployment and inference on cloud servers. However, MLaaS exposes user queries and model parameters to servers. To guarantee confidentiality of queries and model parameters, multi-party computation (MPC) enables secure inference by distributing data and computations across multiple service providers. MPC eliminates single points of failure, mitigates provider breaches and ensures confidentiality beyond legal agreements. Beyond confidentiality of queries and parameters, the model itself can memorize and leak training data during inference. To mitigate privacy concerns, differential privacy (DP) provides a formal privacy guarantee for training data, which can be satisfied by injecting carefully calibrated noise into gradients during training. However, naive combinations of DP and MPC amplify accuracy loss due to DP noise and MPC approximations, and incur high computational and communication overhead due to cryptographic operations. We present SPRINT, the first scalable solution for efficient MPC inference on DP fine-tuned models with high accuracy. SPRINT fine-tunes public pre-trained models on private data using DP. It integrates DP-specific optimizations, e.g., parameter-efficient fine-tuning and noise-aware optimizers, with MPC optimizations, e.g., cleartext public parameters and efficient approximations of non-linear functions. We evaluate SPRINT on GLUE benchmark with RoBERTa, achieving up to 1.6x faster MPC inference than the state-of-the-art non-DP solution SHAFT, reducing communication by 1.6x. Notably, SPRINT maintains high accuracy during MPC inference, with <1 percentage point gap compared to cleartext accuracy. Francesco Capano, Jonas Böhler, Benjamin Weggenmann |
Proc. Priv. Enhancing Technol. | 2 |
| 2021 | Secure Multi-party Computation of Differentially Private Heavy HittersabstractPrivate learning of top-k, i.e., the k most frequent values also called heavy hitters, is a common industry scenario: Companies want to privately learn, e.g., frequently typed new words to improve suggestions on mobile devices, often used browser settings, telemetry data of frequent crashes, heavily shared articles, etc. Jonas Böhler, Florian Kerschbaum |
CCS | 1 |
| 2020 | Secure Sublinear Time Differentially Private Median Computation
Jonas Böhler, Florian Kerschbaum |
NDSS | 1 |
| 2020 | Secure Multi-party Computation of Differentially Private Median
Jonas Böhler, Florian Kerschbaum |
USENIX Security Symposium | 1 |
| 2017 | Privacy-Preserving Outlier Detection for Data Streams
Jonas Böhler, Daniel Bernau, Florian Kerschbaum |
DBSec | 1 |