Jonas Böhler

dblp:202/6734 · DBLP profile ↗
← Back
5ranked-venue papers
4as first author
2since 2021 · last 2026
—ORCID · none

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 5 · 4 first-author · 2 since 2021
YearPublicationVenuePosition
2026 SPRINT: Scalable Secure & Differentially Private Inference for Transformers
abstract
Machine learning as a service (MLaaS) enables scalable model deployment and inference on cloud servers. However, MLaaS exposes user queries and model parameters to servers. To guarantee confidentiality of queries and model parameters, multi-party computation (MPC) enables secure inference by distributing data and computations across multiple service providers. MPC eliminates single points of failure, mitigates provider breaches and ensures confidentiality beyond legal agreements. Beyond confidentiality of queries and parameters, the model itself can memorize and leak training data during inference. To mitigate privacy concerns, differential privacy (DP) provides a formal privacy guarantee for training data, which can be satisfied by injecting carefully calibrated noise into gradients during training. However, naive combinations of DP and MPC amplify accuracy loss due to DP noise and MPC approximations, and incur high computational and communication overhead due to cryptographic operations. We present SPRINT, the first scalable solution for efficient MPC inference on DP fine-tuned models with high accuracy. SPRINT fine-tunes public pre-trained models on private data using DP. It integrates DP-specific optimizations, e.g., parameter-efficient fine-tuning and noise-aware optimizers, with MPC optimizations, e.g., cleartext public parameters and efficient approximations of non-linear functions. We evaluate SPRINT on GLUE benchmark with RoBERTa, achieving up to 1.6x faster MPC inference than the state-of-the-art non-DP solution SHAFT, reducing communication by 1.6x. Notably, SPRINT maintains high accuracy during MPC inference, with <1 percentage point gap compared to cleartext accuracy.
Francesco Capano, Jonas Böhler, Benjamin Weggenmann
Proc. Priv. Enhancing Technol.2
2021 Secure Multi-party Computation of Differentially Private Heavy Hitters
abstract
Private learning of top-k, i.e., the k most frequent values also called heavy hitters, is a common industry scenario: Companies want to privately learn, e.g., frequently typed new words to improve suggestions on mobile devices, often used browser settings, telemetry data of frequent crashes, heavily shared articles, etc.
Jonas Böhler, Florian Kerschbaum
CCS1
2020 Secure Sublinear Time Differentially Private Median Computation
Jonas Böhler, Florian Kerschbaum
NDSS1
2020 Secure Multi-party Computation of Differentially Private Median
Jonas Böhler, Florian Kerschbaum
USENIX Security Symposium1
2017 Privacy-Preserving Outlier Detection for Data Streams
Jonas Böhler, Daniel Bernau, Florian Kerschbaum
DBSec1