Privacy-Preserving Conformal Prediction Under Local Differential Privacy

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Penso, Coby, Mahpud, Bar, Goldberger, Jacob, Sheffet, Or
Format: Preprint
Published: 2025
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866918232822120448
author Penso, Coby
Mahpud, Bar
Goldberger, Jacob
Sheffet, Or
author_facet Penso, Coby
Mahpud, Bar
Goldberger, Jacob
Sheffet, Or
contents Conformal prediction (CP) provides sets of candidate classes with a guaranteed probability of containing the true class. However, it typically relies on a calibration set with clean labels. We address privacy-sensitive scenarios where the aggregator is untrusted and can only access a perturbed version of the true labels. We propose two complementary approaches under local differential privacy (LDP). In the first approach, users do not access the model but instead provide their input features and a perturbed label using a k-ary randomized response. In the second approach, which enforces stricter privacy constraints, users add noise to their conformity score by binary search response. This method requires access to the classification model but preserves both data and label privacy. Both approaches compute the conformal threshold directly from noisy data without accessing the true labels. We prove finite-sample coverage guarantees and demonstrate robust coverage even under severe randomization. This approach unifies strong local privacy with predictive uncertainty control, making it well-suited for sensitive applications such as medical imaging or large language model queries, regardless of whether users can (or are willing to) compute their own scores.
format Preprint
id arxiv_https___arxiv_org_abs_2505_15721
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle Privacy-Preserving Conformal Prediction Under Local Differential Privacy
Penso, Coby
Mahpud, Bar
Goldberger, Jacob
Sheffet, Or
Machine Learning
Conformal prediction (CP) provides sets of candidate classes with a guaranteed probability of containing the true class. However, it typically relies on a calibration set with clean labels. We address privacy-sensitive scenarios where the aggregator is untrusted and can only access a perturbed version of the true labels. We propose two complementary approaches under local differential privacy (LDP). In the first approach, users do not access the model but instead provide their input features and a perturbed label using a k-ary randomized response. In the second approach, which enforces stricter privacy constraints, users add noise to their conformity score by binary search response. This method requires access to the classification model but preserves both data and label privacy. Both approaches compute the conformal threshold directly from noisy data without accessing the true labels. We prove finite-sample coverage guarantees and demonstrate robust coverage even under severe randomization. This approach unifies strong local privacy with predictive uncertainty control, making it well-suited for sensitive applications such as medical imaging or large language model queries, regardless of whether users can (or are willing to) compute their own scores.
title Privacy-Preserving Conformal Prediction Under Local Differential Privacy
topic Machine Learning
url https://arxiv.org/abs/2505.15721