Edwige Cyffers

dblp:281/6734 · DBLP profile ↗
← Back
9ranked-venue papers
6as first author
9since 2021 · last 2026
0009-0006-2823-6850ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Artificial intelligence and machine learning · 8 · 6 first-author · 8 since 2021Databases, data management, data science and information retrieval · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021

Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.

Artificial intelligence
6 papers
Efficient and distributed learning · 47% Trustworthy machine learning · 29% Optimization for machine learning · 24%
Network and information security
5 papers
Privacy and data protection · 85% Security and privacy of machine learning · 15%
Databases, data mining, and information retrieval
1 paper
Web and social media mining · 77% Graph data management · 23%

Topics — the 18 heaviest of 20, each with the papers that count most for it

TopicWeightPapersLastEvidence papers
Privacy and data protection
differential privacy
2.442025
Setting ε is not the Issue in Differential Privacy · NeurIPS 2025
Differentially Private Decentralized Learning with Random Walks · ICML 2024
Muffliato: Peer-to-Peer Privacy Amplification for Decentralized Optimization and Averaging · NeurIPS 2022
Machine learning › Efficient and distributed learning › distributed training
decentralized learning
1.522024
Privacy Attacks in Decentralized Learning · ICML 2024
Differentially Private Decentralized Learning with Random Walks · ICML 2024
Machine learning › Optimization for machine learning
distributed optimization
1.222023
From Noisy Fixed-Point Iterations to Private ADMM for Centralized and Federated Learning · ICML 2023
Muffliato: Peer-to-Peer Privacy Amplification for Decentralized Optimization and Averaging · NeurIPS 2022
Machine learning › Efficient and distributed learning
federated learning
1.222023
From Noisy Fixed-Point Iterations to Private ADMM for Centralized and Federated Learning · ICML 2023
FLamby: Datasets and Benchmarks for Cross-Silo Federated Learning in Realistic Healthcare Settings · NeurIPS 2022
Privacy and data protection › differential privacy
privacy parameter selection
0.912025
Setting ε is not the Issue in Differential Privacy · NeurIPS 2025
Machine learning › Trustworthy machine learning › robustness › adversarial robustness › adversarially robust generalization
adversarially robust classification
0.812024
Optimal Classification under Performative Distribution Shift · NeurIPS 2024
Machine learning › Optimization for machine learning › distributed optimization
distributed gradient descent
0.812024
Privacy Attacks in Decentralized Learning · ICML 2024
Machine learning › Trustworthy machine learning
performative prediction
0.812024
Optimal Classification under Performative Distribution Shift · NeurIPS 2024
Machine learning › Trustworthy machine learning › robustness › robust learning
robust classification
0.812024
Optimal Classification under Performative Distribution Shift · NeurIPS 2024
Privacy and data protection › inference attack
data reconstruction
0.812024
Privacy Attacks in Decentralized Learning · ICML 2024
Security and privacy of machine learning
privacy attack
0.812024
Privacy Attacks in Decentralized Learning · ICML 2024
Machine learning › Efficient and distributed learning › federated learning › privacy-preserving federated learning
differentially private federated learning
0.712023
From Noisy Fixed-Point Iterations to Private ADMM for Centralized and Federated Learning · ICML 2023
Machine learning › Efficient and distributed learning › federated learning › federated learning systems
cross-silo federated learning
0.612022
FLamby: Datasets and Benchmarks for Cross-Silo Federated Learning in Realistic Healthcare Settings · NeurIPS 2022
Distributed systems
distributed coordination
0.212024
Differentially Private Decentralized Learning with Random Walks · ICML 2024
Distributed systems
gossip protocols
0.212024
Differentially Private Decentralized Learning with Random Walks · ICML 2024
Privacy and data protection › differential privacy
privacy amplification
0.212023
From Noisy Fixed-Point Iterations to Private ADMM for Centralized and Federated Learning · ICML 2023
Machine learning › Trustworthy machine learning › privacy
privacy-preserving machine learning
0.212022
FLamby: Datasets and Benchmarks for Cross-Silo Federated Learning in Realistic Healthcare Settings · NeurIPS 2022
Medical and health informatics › clinical informatics › clinical AI
clinical machine learning
0.212022
FLamby: Datasets and Benchmarks for Cross-Silo Federated Learning in Realistic Healthcare Settings · NeurIPS 2022

Methods — techniques the papers use, named apart from their topics

random walk · 2.3graph theory · 2.3reconstruction attack · 1.5gossip averaging · 1.5privacy amplification by iteration · 1.3fixed-point iteration · 1.3alternating direction method of multipliers · 1.3variational autoencoder · 0.8push-forward measures · 0.8normalizing flow · 0.8privacy amplification by subsampling · 0.7gradient descent · 0.6gossip protocol · 0.6federated averaging · 0.6benchmark suite · 0.6
YearPublicationVenuePosition
2026 Fedivertex: a Graph Dataset based on Decentralized Social Media
abstract
International audience
Marc Damie, Edwige Cyffers
WWW2
2025 Setting ε is not the Issue in Differential Privacy
Edwige Cyffers
NeurIPS1
2024 Differentially Private Decentralized Learning with Random Walks
abstract
The popularity of federated learning comes from the possibility of better scalability and the ability for participants to keep control of their data, improving data security and sovereignty. Unfortunately, sharing model updates also creates a new privacy attack surface. In this work, we characterize the privacy guarantees of decentralized learning with random walk algorithms, where a model is updated by traveling from one node to another along the edges of a communication graph. Using a recent variant of differential privacy tailored to the study of decentralized algorithms, namely Pairwise Network Differential Privacy, we derive closed-form expressions for the privacy loss between each pair of nodes where the impact of the communication topology is captured by graph theoretic quantities. Our results further reveal that random walk algorithms tends to yield better privacy guarantees than gossip algorithms for nodes close from each other. We supplement our theoretical results with empirical evaluation on synthetic and real-world graphs and datasets.
Edwige Cyffers, Aurélien Bellet, Jalaj Upadhyay
ICML1
2024 Privacy Attacks in Decentralized Learning
abstract
Decentralized Gradient Descent (D-GD) allows a set of users to perform collaborative learning without sharing their data by iteratively averaging local model updates with their neighbors in a network graph. The absence of direct communication between non-neighbor nodes might lead to the belief that users cannot infer precise information about the data of others. In this work, we demonstrate the opposite, by proposing the first attack against D-GD that enables a user (or set of users) to reconstruct the private data of other users outside their immediate neighborhood. Our approach is based on a reconstruction attack against the gossip averaging protocol, which we then extend to handle the additional challenges raised by D-GD. We validate the effectiveness of our attack on real graphs and datasets, showing that the number of users compromised by a single or a handful of attackers is often surprisingly large. We empirically investigate some of the factors that affect the performance of the attack, namely the graph topology, the number of attackers, and their position in the graph.
Abdellah El Mrini, Edwige Cyffers, Aurélien Bellet
ICML2
2024 Optimal Classification under Performative Distribution Shift
abstract
Performative learning addresses the increasingly pervasive situations in which algorithmic decisions may induce changes in the data distribution as a consequence of their public deployment. We propose a novel view in which these performative effects are modelled as push forward measures. This general framework encompasses existing models and enables novel performative gradient estimation methods, leading to more efficient and scalable learning strategies. For distribution shifts, unlike previous models which require full specification of the data distribution, we only assume knowledge of the shift operator that represents the performative changes. This approach can also be integrated into various change-of-variable-based models, such as VAEs or normalizing flows. Focusing on classification with a linear-in-parameters performative effect, we prove the convexity of the performative risk under a new set of assumptions. Notably, we do not limit the strength of performative effects but rather their direction, requiring only that classification becomes harder when deploying more accurate models. In this case, we also establish a connection with adversarially robust classification by reformulating the performative risk as a min-max variational problem. Finally, we illustrate our approach on synthetic and real datasets.
Edwige Cyffers, Muni Sreenivas Pydi, Jamal Atif, Olivier Cappé
NeurIPS1
2023 From Noisy Fixed-Point Iterations to Private ADMM for Centralized and Federated Learning
abstract
We study differentially private (DP) machine learning algorithms as instances of noisy fixed-point iterations, in order to derive privacy and utility results from this well-studied framework. We show that this new perspective recovers popular private gradient-based methods like DP-SGD and provides a principled way to design and analyze new private optimization algorithms in a flexible manner. Focusing on the widely-used Alternating Directions Method of Multipliers (ADMM) method, we use our general framework derive novel private ADMM algorithms for centralized, federated and fully decentralized learning. We establish strong privacy guarantees for these algorithms, leveraging privacy amplification by iteration and by subsampling. Finally, we provide utility guarantees for the three algorithms using a unified analysis that exploits a recent linear convergence result for noisy fixed-point iterations.
Edwige Cyffers, Aurélien Bellet, Debabrota Basu
ICML1
2022 Privacy Amplification by Decentralization
abstract
Analyzing data owned by several parties while achieving a good trade-off between utility and privacy is a key challenge in federated learning and analytics. In this work, we introduce a novel relaxation of local differential privacy (LDP) that naturally arises in fully decentralized algorithms, i.e., when participants exchange information by communicating along the edges of a network graph without central coordinator. This relaxation, that we call network DP, captures the fact that users have only a local view of the system. To show the relevance of network DP, we study a decentralized model of computation where a token performs a walk on the network graph and is updated sequentially by the party who receives it. For tasks such as real summation, histogram computation and optimization with gradient descent, we propose simple algorithms on ring and complete topologies. We prove that the privacy-utility trade-offs of our algorithms under network DP significantly improve upon what is achievable under LDP, and often match the utility of the trusted curator model. Our results show for the first time that formal privacy gains can be obtained from full decentralization. We also provide experiments to illustrate the improved utility of our approach for decentralized training with stochastic gradient descent.
Edwige Cyffers, Aurélien Bellet
AISTATS1
2022 Muffliato: Peer-to-Peer Privacy Amplification for Decentralized Optimization and Averaging
abstract
Decentralized optimization is increasingly popular in machine learning for its scalability and efficiency. Intuitively, it should also provide better privacy guarantees, as nodes only observe the messages sent by their neighbors in the network graph. But formalizing and quantifying this gain is challenging: existing results are typically limited to Local Differential Privacy (LDP) guarantees that overlook the advantages of decentralization. In this work, we introduce pairwise network differential privacy, a relaxation of LDP that captures the fact that the privacy leakage from a node u to a node v may depend on their relative position in the graph. We then analyze the combination of local noise injection with (simple or randomized) gossip averaging protocols on fixed and random communication graphs. We also derive a differentially private decentralized optimization algorithm that alternates between local gradient descent steps and gossip averaging. Our results show that our algorithms amplify privacy guarantees as a function of the distance between nodes in the graph, matching the privacy-utility trade-off of the trusted curator, up to factors that explicitly depend on the graph topology. Remarkably, these factors become constant for expander graphs. Finally, we illustrate our privacy gains with experiments on synthetic and real-world datasets.
Edwige Cyffers, Mathieu Even, Aurélien Bellet, Laurent Massoulié
NeurIPS1
2022 FLamby: Datasets and Benchmarks for Cross-Silo Federated Learning in Realistic Healthcare Settings
abstract
Federated Learning (FL) is a novel approach enabling several clients holding sensitive data to collaboratively train machine learning models, without centralizing data. The cross-silo FL setting corresponds to the case of few ($2$--$50$) reliable clients, each holding medium to large datasets, and is typically found in applications such as healthcare, finance, or industry. While previous works have proposed representative datasets for cross-device FL, few realistic healthcare cross-silo FL datasets exist, thereby slowing algorithmic research in this critical application. In this work, we propose a novel cross-silo dataset suite focused on healthcare, FLamby (Federated Learning AMple Benchmark of Your cross-silo strategies), to bridge the gap between theory and practice of cross-silo FL.FLamby encompasses 7 healthcare datasets with natural splits, covering multiple tasks, modalities, and data volumes, each accompanied with baseline training code. As an illustration, we additionally benchmark standard FL algorithms on all datasets.Our flexible and modular suite allows researchers to easily download datasets, reproduce results and re-use the different components for their research. FLamby is available at~\url{www.github.com/owkin/flamby}.
Jean Ogier du Terrail, Samy-Safwan Ayed, Edwige Cyffers, Felix Grimberg, Chaoyang He 0001, Régis Loeb, Paul Mangold, Tanguy Marchand, Othmane Marfoq, Erum Mushtaq, Boris Muzellec, Constantin Philippenko, Santiago Silva 0001, Maria Telenczuk, Shadi Albarqouni, Amir Salman Avestimehr, Aurélien Bellet, Aymeric Dieuleveut, Martin Jaggi, Sai Praneeth Karimireddy, Marco Lorenzi, Giovanni Neglia, Marc Tommasi, Mathieu Andreux
NeurIPS3