Cardiff University | Prifysgol Caerdydd ORCA
Online Research @ Cardiff 
WelshClear Cookie - decide language by browser settings

Conformal prediction for privacy-preserving machine learning: uncertainty quantification on encrypted data

Balinsky, Alexander D., Krzeminski, Dominik and Balinsky, Alexander ORCID: https://orcid.org/0000-0002-8151-4462 2026. Conformal prediction for privacy-preserving machine learning: uncertainty quantification on encrypted data. Applied Mathematics & Information Sciences 20 (5) , pp. 1261-1268. 10.18576/amis/200511

Full text not available from this repository.

Abstract

We study whether Conformal Prediction (CP), a distribution-free framework for quantifying the uncertainty of machine- learning predictions, can be applied directly on encrypted data, without ever decrypting it. The motivation is privacy-preserving learning: ideally a model should produce calibrated, statistically valid prediction sets while the underlying data remains hidden. Our key observation is theoretical: because a fixed-key deterministic cipher is a single, fixed transformation applied identically to every record, it preserves exchangeability, the only assumption CP requires. CP guarantees therefore transfer to the encrypted domain unchanged. We test this on AES-encrypted MNIST and compare the classical p-value conformal predictor against the more recent e-value (BB) predictor of Balinsky and Balinsky. Empirically, a simple feed-forward network trained only on deterministically encrypted images still reaches 33.58% test accuracy, far above the near-chance 11.35% obtained when each image is encrypted with its own key (which destroys the consistent plaintext-to-ciphertext mapping and reduces learning to chance). At a nominal miscoverage of α = 0.4 (a 60% coverage target), the e-value predictor is highly conservative: its guarantee of at least 60% coverage is met with a realized coverage of 97.46% (4873/5000), at the cost of large prediction sets; the p-value predictor produces much smaller sets but realizes only 59.4% coverage. These results demonstrate the feasibility of uncertainty quantification on encrypted data.

Item Type: Article
Date Type: Publication
Status: Published
Schools: Schools > Computational & Mathematical Sciences
Schools > Computer Science & Informatics
Publisher: NATURAL SCIENCES PUBLISHING CO
ISSN: 1935-0090
Date of First Compliant Deposit: 12 September 2026
Date of Acceptance: 1 August 2026
Last Modified: 14 Sep 2026 11:20
URI: https://orca.cardiff.ac.uk/id/eprint/189541

Actions (repository staff only)

Edit Item Edit Item