Research Projects

Differential Privacy, Machine Learning, and Information Theory

Istanbul, Turkey
Ongoing
Potential Privacy Risk in Machine Learning

December 2024 – Present

We consider the problem of advanced estimation of privacy risk of adding a data point to the training set of a machine learning model with standard optimisation methods. The goal is to develop principled tools that help practitioners assess the privacy cost before committing to training decisions.

Differential Privacy Machine Learning Privacy Risk
Accepted · ICML 2026
Magnitude Distance: A Geometric Measure of Dataset Similarity

2025 – 2026

We propose magnitude distance, a novel distance metric on finite datasets based on the magnitude of a metric space, with a tunable scaling parameter controlling sensitivity to global structure versus finer detail. We prove key theoretical properties, show it remains discriminative in high dimensions, and demonstrate its use as a training objective for push-forward generative models.

Metric Space Magnitude Dataset Distances Generative Modelling
View on ICML 2026
Under Review
Generalization in Neural Networks Through the Lens of Magnitude Potential

2025 – 2026

We introduce the magnitude potential, a quantity based on metric magnitude theory that reflects how well a point is represented by a given set. Computed at the logit layer, the ratio between class-conditional and full-dataset magnitude potential correlates with Feldman memorization scores, detects structural changes in decision boundaries, and provides a geometric indicator of grokking.

Magnitude Potential Generalization Grokking Memorization
View on OpenReview
Workshop · EuroTDP 2026
Privacy Requires Slicing: Differentially Private Magnitude via Projections

2025 – 2026

We introduce sliced magnitude (SMag), with global sensitivity bounded uniformly in the scale parameter and dimension, enabling ε-differentially private release of magnitude-based quantities via the Laplace mechanism.

Differential Privacy Metric Space Magnitude Sliced Projections
Completed
Secure Data Scoring and Selection for ML Models with Zero-Knowledge Proofs

December 2024 – April 2025

We describe secure protocols that make use of a small subset of the data to perform an assessment and output a score that can be used to determine the final price of a data transaction. The protocols are based on zero-knowledge proofs of properties of the data and model inference, ensuring both correctness and confidentiality of the underlying data.

Zero-Knowledge Proofs Data Markets Secure Computation
Completed
Continual Observation with Differential Privacy

March 2024 – September 2024

We consider the problem of counting under continual observation and present a new generalization of the binary tree mechanism that uses a k-ary number system with negative digits to improve the privacy-accuracy trade-off. This leads to improved error bounds compared to previous approaches.

Differential Privacy Continual Observation Counting Mechanisms
Completed
Sparse MultiDecoder Recursive Projection Aggregation for Reed-Muller Codes

March 2022 – September 2022

The Sparse Recursive Projection Aggregation (SRPA) decoder for Reed-Muller codes achieves performance close to the maximum likelihood decoder for short-length RM codes. We simulated an algorithm based on a neural network to lower the computational budget while keeping performance close to that of the SRPA decoder by performing a better selection of projections in each sparsified decoder.

Reed-Muller Codes Neural Networks Coding Theory
Completed
Algorithms and Differential Privacy via Graphs

March 2021 – February 2024

In this project, we generalized the previous framework for designing utility-optimal differentially private (DP) mechanisms via graphs in two main directions. First, heterogeneous mechanisms where the partial mechanism can have different probability distributions at the boundary. Secondly, we solved the problem in a general heterogeneous privacy setting on neighboring datasets to provide different levels of privacy for each data point.

Differential Privacy Graph Theory Utility Optimization Heterogeneous Privacy