Atefeh Gilani

dblp:222/1866 · DBLP profile ↗
← Back
6ranked-venue papers
4as first author
5since 2021 · last 2025
0009-0006-5904-3445ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Theory of computation · 4 · 2 first-author · 3 since 2021Artificial intelligence and machine learning · 2 · 2 first-author · 2 since 2021Security and privacy · 1
YearPublicationVenuePosition
2025 Optimizing Noise Distributions for Differential Privacy
abstract
We propose a unified optimization framework for designing continuous and discrete noise distributions that ensure differential privacy (DP) by minimizing Rényi DP, a variant of DP, under a cost constraint. Rényi DP has the advantage that by considering different values of the Rényi parameter $\alpha$, we can tailor our optimization for any number of compositions. To solve the optimization problem, we reduce it to a finite-dimensional convex formulation and perform preconditioned gradient descent. The resulting noise distributions are then compared to their Gaussian and Laplace counterparts. Numerical results demonstrate that our optimized distributions are consistently better, with significant improvements in $(\varepsilon, \delta)$-DP guarantees in the moderate composition regimes, compared to Gaussian and Laplace distributions with the same variance.
Atefeh Gilani, Juan Felipe Gómez, Shahab Asoodeh, Flávio P. Calmon, Oliver Kosut, Lalitha Sankar
ICML1
2025 Reveal-or-Obscure: A Differentially Private Sampling Algorithm for Discrete Distributions
abstract
We introduce a differentially private (DP) algorithm called reveal-or-obscure (ROO) to generate a single representative sample from a dataset of n observations drawn i.i.d. from an unknown discrete distribution P. Unlike methods that add explicit noise to the estimated empirical distribution, ROO achieves ϵ-differential privacy by randomly choosing whether to "reveal" or "obscure" the empirical distribution. While ROO is structurally identical to the algorithm in a recent work by Cheu and Nayak, we prove a strictly better bound on the sampling complexity than that established by them. To further improve the privacy-utility tradeoff, we propose a novel generalized sampling algorithm called Data-Specific ROO (DS-ROO), where the probability of obscuring the empirical distribution of the dataset is chosen adaptively. We prove that DS-ROO satisfies ϵ-DP, and provide empirical evidence that DS-ROO can achieve better utility under the same privacy budget of vanilla ROO.
Naima Tasnim, Atefeh Gilani, Lalitha Sankar, Oliver Kosut
ITW2
2025 GeoClip: Geometry-Aware Clipping for Differentially Private SGD
abstract
Differentially private stochastic gradient descent (DP-SGD) is the most widely used method for training machine learning models with provable privacy guarantees. A key challenge in DP-SGD is setting the per-sample gradient clipping threshold, which significantly affects the trade-off between privacy and utility. While recent adaptive methods improve performance by adjusting this threshold during training, they operate in the standard coordinate system and fail to account for correlations across the coordinates of the gradient. We propose GeoClip, a geometry-aware framework that clips and perturbs gradients in a transformed basis aligned with the geometry of the gradient distribution. GeoClip adaptively estimates this transformation using only previously released noisy gradients, incurring no additional privacy cost. We provide convergence guarantees for GeoClip and derive a closed-form solution for the optimal transformation that minimizes the amount of noise added while keeping the probability of gradient clipping under control. Experiments on both tabular and image datasets demonstrate that GeoClip consistently outperforms existing adaptive clipping methods under the same privacy budget.
Atefeh Gilani, Naima Tasnim, Lalitha Sankar, Oliver Kosut
NeurIPS1
2024 Unifying Privacy Measures via Maximal (α, β)-Leakage (MαbeL)
abstract
We introduce a family of information leakage measures calledmaximal(α, β)-leakage(MαbeL), parameterized by real numbers α and β greater than or equal to 1. The measure is formalized via an operational definition involving an adversary guessing an unknown (randomized) function of the data given the released data. We obtain a simplified computable expression for the measure and show that it satisfies several basic properties such as monotonicity in β for a fixed α, non-negativity, data processing inequalities, and additivity over independent releases. We highlight the relevance of this family by showing that it bridges several known leakage measures, including maximal α-leakage (β = 1), maximal leakage (α = ∞, β = 1), local differential privacy (LDP) (α = ∞, β = ∞), and local Rényi differential privacy (LRDP) (α = β), thereby giving an operational interpretation to local Rényi differential privacy. We also study a conditional version of MαbeL on leveraging which we recover differential privacy and Rényi differential privacy. A new variant of LRDP, which we callmaximal Rényi leakage, appears as a special case of MαbeL for α = ∞ that smoothly tunes between maximal leakage (β = 1) and LDP (β = ∞). Finally, we show that a vector form of the maximal Rényi leakage relaxes differential privacy under Gaussian and Laplacian mechanisms.
Atefeh Gilani, Gowtham R. Kurri, Oliver Kosut, Lalitha Sankar
IEEE Trans. Inf. Theory1
2022 An Alphabet of Leakage Measures
abstract
We introduce a family of information leakage measures called maximal α, β-leakage, parameterized by real numbers α and β. The measure is formalized via an operational definition involving an adversary guessing an unknown function of the data given the released data. We obtain a simple, computable expression for the measure and show that it satisfies several basic properties such as monotonicity in β for a fixed α, non-negativity, data processing inequalities, and additivity over independent releases. Finally, we highlight the relevance of this family by showing that it bridges several known leakage measures, including maximal α-leakage (β = 1), maximal leakage (α = ∞, β = 1), local differential privacy (α = ∞, β = ∞), and local Rényi differential privacy (α = β).
Atefeh Gilani, Gowtham R. Kurri, Oliver Kosut, Lalitha Sankar
ITW1
2018 Distributed Hypothesis Testing with Privacy Constraints
abstract
We revisit the hypothesis testing with communication constraints problem, also called distributed hypothesis testing, from the viewpoint of privacy. Instead of observing the raw data directly, the transmitter observes a sanitized or randomized version of it. We impose an upper bound on the mutual information between the raw and randomized data. Under this scenario, the decoder, which is also provided with side information, is required to make a decision on whether the null or alternative hypothesis is in effect. First, we provide a general lower bound on the type-II exponent for arbitrary hypotheses, privacy mechanism, rates, and leakage parameters. Second, we consider the testing against independence scenario in which the distribution under the alternative hypothesis is the product of the marginals of the distribution under the null hypothesis. In this setup, we show that the exponent is known exactly and the strong converse property holds. Finally, the trade-offs between the exponent, compression rate, and leakage parameter are illustrated through a binary example.
Selma Belhadj Amor, Atefeh Gilani, Sadaf Salehkalaibar, Vincent Y. F. Tan
ISITA2