Bridging ML and Threat Landscapes: Inference Attacks and Cryptographic Defenses for Training-Phase Data Protection
- Authors
-
-
Pramod Prakash
Author
-
- Keywords:
- Privacy-Preserving Machine Learning, Differential Privacy, Homomorphic Encryption, Membership Inference Attacks, Secure Multi-Party Computation, Trusted Execution Environments
- Abstract
-
Machine learning systems use sensitive personal data to train and infer models, but developers are largely unaware of privacy attack vectors that evade conventional data security controls. This paper surveys the privacy threat landscape inherent to ML workflows, including membership inference attacks, model inversion attacks, reconstruction attacks, and re-identification attacks, which can occur even when data is transmitted over encrypted channels or is explicitly de-identified. It then catalogues cryptographic and perturbation-based defense mechanisms, including homomorphic encryption protocols, garbled circuits, secret-sharing architectures, secure processors, and differential privacy frameworks, that enable privacy-preserving machine learning (PPML) without sacrificing model utility. The extensive study of commercial systems (ShareMind, RAPPOR, local DP in Chrome, etc.) and academic systems shows what is being deployed in practice and what limitations remain. Finally, the paper provides an overview of the important barriers to adoption, namely algorithmic rigidity, the trade-off between computational scalability and privacy, non-collusion assumptions, gaps in policy enforcement, and human-data-interaction principles (legibility, agency, negotiability) for realizing the right to be forgotten and granting data owners control over the processes of inference.
- References
- Downloads
- Published
- 2026-09-25
- Issue
- Vol. 1 No. 5 (2026)
- Section
- Articles
- License
-
Copyright (c) 2026 International Journal of Intelligent Systems and Data Science

This work is licensed under a Creative Commons Attribution 4.0 International License.
