Uploaded June 2026 | Updated September 2026, 3 weeks ago
The Emperor's New Embeddings: Obfuscating ML Inputs Doesn't Provide Privacy
Jack Fitzsimons, Oblivious
When you think about PETs in machine learning, you likely think about protecting the training data: there are well-developed tools and approaches to ensuring that your model doesn't leak user data it was trained on. But that's only half of the story: what about protecting the data used for inference?
In the last few years, there's been a growing thread of research and some commercial offerings that promise just that: to protect model inputs while still allowing inference. These tools transform data so that it is hard to recover the original input, but in a way that still allows a model to make accurate predictions.
Does that sound too good to be true? That's because it is! This talk will look at the (bad) ways that these tools are measuring "privacy", the fundamental limits of how much we can protect, and whether there are any alternative approaches.
This work is based on a collaboration by Jack Fitzsimons, Daniel Simmons-Marengo, Tudor Cebere and Damien Desfontaines.
View the full PEPR '26 program at usenix.org/conference/pepr26/program
The Emperor's New Embeddings: Obfuscating ML Inputs Doesn't Provide Privacy
Jack Fitzsimons, Oblivious
When you think about PETs in machine learning, you likely think about protecting the training data: there are well-developed tools and approaches to ensuring that your model doesn't leak user data it was trained on. But that's only half of the story: what about protecting the data used for inference?
In the last few years, there's been a growing thread of research and some commercial offerings that promise just that: to protect model inputs while still allowing inference. These tools transform data so that it is hard to recover the original input, but in a way that still allows a model to make accurate predictions.
Does that sound too good to be true? That's because it is! This talk will look at the (bad) ways that these tools are measuring "privacy", the fundamental limits of how much we can protect, and whether there are any alternative approaches.
This work is based on a collaboration by Jack Fitzsimons, Daniel Simmons-Marengo, Tudor Cebere and Damien Desfontaines.
View the full PEPR '26 program at usenix.org/conference/pepr26/program










