PEPR 26 - The Emperors New Embeddings: Obfuscating ML Inputs Doesnt Provide Privacy @UsenixOrg
PEPR 26 - The Emperors New Embeddings: Obfuscating ML Inputs Doesnt Provide Privacy  @UsenixOrg
Uploaded June 2026 | Updated September 2026, 3 weeks ago
The Emperor's New Embeddings: Obfuscating ML Inputs Doesn't Provide Privacy

Jack Fitzsimons, Oblivious

When you think about PETs in machine learning, you likely think about protecting the training data: there are well-developed tools and approaches to ensuring that your model doesn't leak user data it was trained on. But that's only half of the story: what about protecting the data used for inference?
In the last few years, there's been a growing thread of research and some commercial offerings that promise just that: to protect model inputs while still allowing inference. These tools transform data so that it is hard to recover the original input, but in a way that still allows a model to make accurate predictions.
Does that sound too good to be true? That's because it is! This talk will look at the (bad) ways that these tools are measuring "privacy", the fundamental limits of how much we can protect, and whether there are any alternative approaches.
This work is based on a collaboration by Jack Fitzsimons, Daniel Simmons-Marengo, Tudor Cebere and Damien Desfontaines.

View the full PEPR '26 program at usenix.org/conference/pepr26/program
PEPR 26 - The Emperors New Embeddings: Obfuscating ML Inputs Doesnt Provide PrivacyNSDI 26 - RLBoost: Harvesting Preemptible Cloud Resources for Cost-Efficient Reinforcement LearningPEPR 26 - CA-CI: A Normative Framework for Evaluating Privacy and Dignity in AI GovernanceNSDI 26 - Decoding RSSI Compression in RFID: Dynamic RCS Modeling and Tag-Intrinsic Power Metrics..NSDI 26 - Over-Threshold Multiparty Private Set Intersection for Collaborative...SREcon24 Europe/Middle East/Africa - Dude, You Forgot the Feedback: How Your Open Loop Control...NSDI 26 - Queue-Mem: Energy-Efficient Hardware Storage for Advanced Network Function AccelerationPEPR 26 - Dismantling the Barriers to Personal Data PortabilityNSDI 26 - Defending against Traffic Analysis Attacks with Flexible In-Network ObfuscationUSENIX Security 24 - HYPERPILL: Fuzzing for Hypervisor-bugs by Leveraging the Hardware...NSDI 26 - QCON: Seamless QoE-Aware 5G Streaming via Multi-ConnectivityPEPR 26 - Architecting Scalable Data Lineage Graph for Privacy Compliance and Agentic Analysis
USENIX |

PEPR '26 - The Emperor's New Embeddings: Obfuscating ML Inputs Doesn't Provide Privacy

SHARE TO X SHARE TO REDDIT SHARE TO FACEBOOK WALLPAPER