Hadal: Centralized Label DP Training without a Trusted Party

James Choncholas
Stanislav Peceny
Amit Agarwal
Baiyu Li
2026 IEEE Symposium on Security and Privacy (SP)

Abstract

In the Label Differential Privacy (Label DP) setting where machine learning training data is vertically partitioned between feature and label holders, centralized Differential Privacy approaches have shown superior utility compared to local approaches in high-privacy regimes. However, these centralized approaches typically require a trusted third party to compute the gradient. We introduce POSTSCALE, a novel training protocol based on Homomorphic Encryption with a ciphertext multiplicative depth of one, and no ciphertext rotations for models with affine gradient functions and few output classes. Furthermore, we present Hadal, a dataflow-based framework for encrypted computation, and Hadal-ml, a machine learning package tailored for Label DP, implementing our POSTSCALE protocol. Our approach leverages HE to enable centralized Differential Privacy without relying on a trusted third party. By integrating with TensorFlow, our framework Hadal supports both eager and deferred execution modes, while providing HE-specific optimizations and comprehensive performance profiling capabilities. Experimental results demonstrate that our approach achieves model utility comparable to existing centralized label DP techniques, surpasses local DP, and maintains privacy guarantees without relying on a trusted party.

Research Areas

×