Sara Saeidian

dblp:271/5345 · DBLP profile ↗
← Back
13ranked-venue papers
8as first author
12since 2021 · last 2026
0000-0001-6908-559XORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Applied, interdisciplinary, general and emerging computing · 5 · 2 first-author · 5 since 2021Theory of computation · 3 · 3 first-author · 3 since 2021Security and privacy · 2 · 1 first-author · 2 since 2021Graphics, computer vision, multimedia, augmented reality and games · 2 · 1 first-author · 2 since 2021Computer networks · 1 · 1 first-author
YearPublicationVenuePosition
2026 Dobrushin Coefficients of Private Mechanisms Beyond Local Differential Privacy
abstract
We investigate Dobrushin coefficients of discrete Markov kernels that have bounded pointwise maximal leakage (PML) with respect to all distributions with a minimum probability mass bounded away from zero by a constant $c>0$. This definition recovers local differential privacy (LDP) for $c\to 0$. We derive achievable bounds on contraction in terms of a kernels PML guarantees, and provide mechanism constructions that achieve the presented bounds. Further, we extend the results to general $f$-divergences by an application of Binette's inequality. Our analysis yields tighter bounds for mechanisms satisfying LDP and extends beyond the LDP regime to any discrete kernel.
Leonhard Grosse, Sara Saeidian, Tobias J. Oechtering, Mikael Skoglund
ISIT2
2026 Context-aware Privacy Bounds for Linear Queries
abstract
Linear queries, as the basis of broad analysis tasks, are often released through privacy mechanisms based on differential privacy (DP), the most popular framework for privacy protection. However, DP adopts a context-free definition that operates independently of the data-generating distribution. In this paper, we revisit the privacy analysis of the Laplace mechanism through the lens of pointwise maximal leakage (PML). We demonstrate that the distribution-agnostic definition of the DP framework often mandates excessive noise. To address this, we incorporate an assumption about the prior distribution by lower-bounding the probability of any single record belonging to any specific class. With this assumption, we derive a tight, context-aware leakage bound for general linear queries, and prove that our derived bound is strictly tighter than the standard DP guarantee and converges to the DP guarantee as this probability lower bound approaches zero. Numerical evaluations demonstrate that by exploiting this prior knowledge, the required noise scale can be reduced while maintaining privacy guarantees.
Sara Saeidian, Tobias J. Oechtering
ISIT2
2026 Pointwise Maximal Leakage of Markov Processes
Tobias J. Oechtering, Sara Saeidian
IEEE Signal Process. Lett.2
2026 Information Density Bounds for Privacy
abstract
This paper explores the implications of guaranteeing privacy by imposing a lower bound on the information density between the private and the public data. We introduce a novel and operationally meaningful privacy measure calledpointwise maximal cost(PMC) and demonstrate that imposing an upper bound on PMC is equivalent to enforcing a lower bound on the information density. PMC quantifies the information leakage about a secret to adversaries who aim to minimize non-negative cost functions after observing the outcome of a privacy mechanism. When restricted to finite alphabets, PMC can equivalently be defined as the information leakage to adversaries aiming to minimize the probability of incorrectly guessing randomized functions of the secret. We study the properties of PMC and apply it to standard privacy mechanisms to demonstrate its practical relevance. Through a detailed examination, we connect PMC with other privacy measures that impose upper or lower bounds on the information density. These are pointwise maximal leakage (PML), local differential privacy (LDP), and (asymmetric) local information privacy. In particular, we show that a mechanism satisfies LDP if and only if it has both bounded PMC and bounded PML. Overall, our work fills a conceptual and operational gap in the taxonomy of privacy measures, bridges existing disconnects between different frameworks, and offers insights for selecting a suitable notion of privacy in a given application.
Sara Saeidian, Leonhard Grosse, Parastoo Sadeghi, Mikael Skoglund, Tobias J. Oechtering
IEEE Trans. Inf. Theory1
2025 A Tight Context-Aware Privacy Bound for Histogram Publication
abstract
We analyze the privacy guarantees of the Laplace mechanism releasing the histogram of a dataset through the lens of pointwise maximal leakage (PML). While differential privacy is commonly used to quantify the privacy loss, it is a context free definition that does not depend on the data distribution. In contrast, PML enables a more refined analysis by incorporating assumptions about the data distribution. We show that when the probability of each histogram bin is bounded away from zero, stronger privacy protection can be achieved for a fixed level of noise. Our results demonstrate the advantage of context-aware privacy measures and show that incorporating assumptions about the data can improve privacy-utility tradeoffs.
Sara Saeidian, Ata Yavuzyilmaz, Leonhard Grosse, Georg Friedrich Schuppe, Tobias J. Oechtering
IEEE Signal Process. Lett.1
2024 Quantifying Privacy via Information Density
abstract
We examine the relationship between privacy metrics that utilize information density to measure information leakage between a private and a disclosed random variable. Firstly, we prove that bounding the information density from above or below in turn implies a lower or upper bound on the information density, respectively. Using this result, we establish new relationships between local information privacy, asymmetric local information privacy, pointwise maximal leakage and local differential privacy. We further provide applications of these relations to privacy mechanism design. Secondly, we provide equivalence statements of lower bounds on information density and risk-averse adversaries. More specifically, we prove an equivalence between a guessing framework and a cost-function framework that both result in the same lower bound on the information density.
Leonhard Grosse, Sara Saeidian, Parastoo Sadeghi, Tobias J. Oechtering, Mikael Skoglund
ISIT2
2024 Extremal Mechanisms for Pointwise Maximal Leakage
abstract
Data publishing under privacy constraints can be achieved with mechanisms that add randomness to data points when released to an untrusted party, thereby decreasing the data’s utility. In this paper, we analyze this privacy-utility tradeoff for the pointwise maximal leakage (PML) privacy measure and provide optimal privacy mechanisms for a general class of convex utility functions. PML was recently proposed as an operationally meaningful privacy measure based on two equivalent threat models: An adversary guessing a randomized function and an adversary aiming to maximize a general gain function. We prove a cardinality bound, showing that output alphabets of optimal mechanisms in this context need not to be larger than the size of their inputs. Then, we characterize the optimization region as a (convex) polytope. We derive closed-form optimal privacy mechanisms for arbitrary priors in the high privacy regime (when the privacy parameter is sufficiently small) and uniform priors for all ranges of the privacy parameter using tools from convex analysis. Furthermore, we present a linear program that can compute optimal mechanisms for PML in a general setting. We conclude by demonstrating the performance of the closed-form mechanisms through numerical simulations.
Leonhard Grosse, Sara Saeidian, Tobias J. Oechtering
IEEE Trans. Inf. Forensics Secur.2
2023 Pointwise Maximal Leakage on General Alphabets
abstract
Pointwise maximal leakage (PML) is an operationally meaningful privacy measure that quantifies the amount of information leaking about a secret X to a single outcome of a related random variable Y. In this paper, we extend the notion of PML to random variables on arbitrary probability spaces. We develop two new definitions: First, we extend PML to countably infinite random variables by considering adversaries who aim to guess the value of discrete (finite or countably infinite) functions of X. Then, we consider adversaries who construct estimates of X that maximize the expected value of their corresponding gain functions. We use this latter setup to introduce a highly versatile form of PML that captures many scenarios of practical interest whose definition requires no assumptions about the underlying probability spaces.
Sara Saeidian, Giulia Cervia, Tobias J. Oechtering, Mikael Skoglund
ISIT1
2023 Pointwise Maximal Leakage
abstract
We introduce a privacy measure called pointwise maximal leakage, generalizing the pre-existing notion of maximal leakage, which quantifies the amount of information leaking about a secret$X$by disclosing a single outcome of a (randomized) function calculated on$X$. Pointwise maximal leakage is a robust and operationally meaningful privacy measure that captures the largest amount of information leaking about$X$to adversaries seeking to guess arbitrary (possibly randomized) functions of$X$, or equivalently, aiming to maximize arbitrary gain functions. We study several properties of pointwise maximal leakage, e.g., how it composes over multiple outcomes, how it is affected by pre- and post-processing, etc. Furthermore, we propose to view information leakage as a random variable which, in turn, allows us to regard privacy guarantees as requirements imposed on different statistical properties of the information leakage random variable. We define several privacy guarantees and study how they behave under pre-processing, post-processing and composition. Finally, we examine the relationship between pointwise maximal leakage and other privacy notions such as local differential privacy, local information privacy,$f$-information, and so on. Overall, our paper constructs a robust and flexible framework for privacy risk assessment whose central notion has a strong operational meaning which can be adapted to a variety of applications and practical scenarios.
Sara Saeidian, Giulia Cervia, Tobias J. Oechtering, Mikael Skoglund
IEEE Trans. Inf. Theory1
2022 Pointwise Maximal Leakage
abstract
Pointwise maximal leakage (PML) is a robust and operationally meaningful privacy measure that quantifies the amount of information leaking about a secret X by disclosing a single outcome of a (randomized) function calculated on X. In this paper, we define a new privacy measure called event maximal leakage (EML), which generalizes PML by quantifying the amount of information leaking about X to arbitrary events. Then, we use our new privacy measure to define a new probabilistic privacy guarantee called (ϵ, δ)-EML. We study the data-processing and composition properties of (ϵ, δ)-EML and other privacy guarantees, where our goal is to understand whether or not they are closed under pre- and post-processing, and how they change as a result of adaptively composing privacy mechanisms.
Sara Saeidian, Giulia Cervia, Tobias J. Oechtering, Mikael Skoglund
ISIT1
2021 Optimal Maximal Leakage-Distortion Tradeoff
abstract
Most methods for publishing data with privacy guarantees introduce randomness into datasets which reduces the utility of the published data. In this paper, we study the privacy-utility tradeoff by taking maximal leakage as the privacy measure and the expected Hamming distortion as the utility measure. We study three different but related problems. First, we assume that the data-generating distribution (i.e., the prior) is known, and we find the optimal privacy mechanism that achieves the smallest distortion subject to a constraint on maximal leakage. Then, we assume that the prior belongs to some set of distributions, and we formulate a min-max problem for finding the smallest distortion achievable for the worst-case prior in the set, subject to a maximal leakage constraint. Lastly, we define a partial order on privacy mechanisms based on the largest distortion they generate. Our results show that when the prior distribution is known, the optimal privacy mechanism fully discloses symbols with the largest prior probabilities, and suppresses symbols with the smallest prior probabilities. Furthermore, we show that sets of priors that contain more uniform distributions lead to larger distortion, while privacy mechanisms that distribute the privacy budget more uniformly over the symbols create smaller worst-case distortion. A full version of this paper is accessible at: https://arxiv.org/pdf/2105.01033.pdf
Sara Saeidian, Giulia Cervia, Tobias J. Oechtering, Mikael Skoglund
ITW1
2021 Quantifying Membership Privacy via Information Leakage
abstract
Machine learning models are known to memorize the unique properties of individual data points in a training set. This memorization capability can be exploited by several types of attacks to infer information about the training data, most notably, membership inference attacks. In this paper, we propose an approach based on information leakage for guaranteeing membership privacy. Specifically, we propose to use a conditional form of the notion of maximal leakage to quantify the information leaking about individual data entries in a dataset, i.e., the entrywise information leakage. We apply our privacy analysis to the Private Aggregation of Teacher Ensembles (PATE) framework for privacy-preserving classification of sensitive data and prove that the entrywise information leakage of its aggregation mechanism is Schur-concave when the injected noise has a log-concave probability density. The Schur-concavity of this leakage implies that increased consensus among teachers in labeling a query reduces its associated privacy cost. Finally, we derive upper bounds on the entrywise information leakage when the aggregation mechanism uses Laplace distributed noise.
Sara Saeidian, Giulia Cervia, Tobias J. Oechtering, Mikael Skoglund
IEEE Trans. Inf. Forensics Secur.1
2020 Downlink Power Control in Dense 5G Radio Access Networks Through Deep Reinforcement Learning
abstract
During the past decades, a myriad of inter/intracell interference mitigation techniques has been suggested for different wireless technologies. Nevertheless, the concept of downlink power control for interference mitigation has yet to be explored in 5G radio access networks. In this paper, we propose a data-driven approach based on deep reinforcement learning for downlink power control in dense 5G networks. The solution builds upon the well-known DQN algorithm and its recent extensions, aiming to maximize user rates. Using a 5Gcompliant system-level simulator, we compare the performance of our proposed method to fixed power allocation approaches. Test results show that the proposed method is successful at improving data rates at the cell-edge while reducing total transmitted power compared to the baseline.
Sara Saeidian, Soma Tayamon, Euhanna Ghadimi
ICC1