[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-detail-118709-en":3,"doc-seo-118709-105":30,"detail-sidebar-cat-0-en-105":92},{"code":4,"msg":5,"data":6},0,"success",{"doc_id":7,"user_id":8,"nickname":9,"user_avatar":10,"doc_module":4,"category_id":11,"category_name":12,"doc_title":13,"doc_description":14,"doc_content":15,"file_id":16,"file_url":17,"file_type":18,"file_size":19,"view_count":20,"is_deleted":4,"is_public":20,"is_downloadable":20,"audit_status":20,"page_count":21,"language":22,"language_code":23,"site_id":24,"html_lang":23,"table_of_contents":25,"faqs":26,"seo_title":27,"seo_description":14,"update_tm":28,"read_time":29},118709,1099513958607,"Jiven","https://ap-avatar.wpscdn.com/avatar/100002390cf8733938c?x-image-process=image/resize,m_fixed,w_180,h_180&k=1778829742770036399",8,"Research & Report","Privacy-preserving machine learning with tensor networks - Research and analysis","Privacy-preserving machine learning using tensor-network architectures is examined to address vulnerabilities that can leak information through model parameters, including in feedforward neural networks. The work introduces a privacy vulnerability, demonstrates it on synthetic and real datasets, and derives rigorous, gauge-symmetry–based conditions that guarantee robustness. It proves these conditions for tensor-network models and defines a novel canonical form for matrix product states. Practical training on medical-record datasets shows strong reductions in an attacker’s ability to infer sensitive training data, enabling privacy without sacrificing predictive accuracy.","Privacy-preserving machine learning with tensor networks  \nAlejandro Pozas-Kerstjens 1,2 , Senaida Hernndez-Santana3 , Jos Ramn Pareja Monturiol 1,2 , Marco Castrilln Lpez4 , Giannicola Scarpa5 , Carlos E. Gonzlez-Guilln3 , and David Prez-Garc1,2  \n1 Instituto de Ciencias Matemticas (CSIC-UAM-UC3M-UCM), 28049 Madrid, Spain  \n2 Departamento de Anlisis Matemtico, Universidad Complutense de Madrid, 28040 Madrid, Spain  \n3 Departamento de Matemtica Aplicada a la Ingenier´ıa Industrial, Universidad Politcnica de Madrid, 28006 Madrid, Spain 4 Departamento de lgebra, Geometr´ıa y Topolog´ıa, Universidad Complutense de Madrid, 28040 Madrid, Spain  \n5 Escuela Tcnica Superior de Ingenier´ıa de Sistemas Informticos, Universidad Politcnica de Madrid, 28031 Madrid, Spain  \narXiv :2202 . 123 19v2 [ cs .CR] 14 Jul 2023  \nTensor networks, widely used for providing eﬃcient representations of low-energy states of local quantum many-body systems, have been recently proposed as machine learning architectures which could present advantages with respect to traditional ones. In this work we show that tensor network architectures have especially prospective properties for privacypreserving machine learning, which is important in tasks such as the processing of medical records. First, we describe anew privacy vulnerability that is present in feedforward neural networks, illustrating it in synthetic and real-world datasets. Then, we develop well-deﬁned conditions to guarantee robustness to such vulnerability, which involve the characterization of models equivalent under gauge symmetry. We rigorously prove that such conditions are satisﬁed by tensor-network architectures. In doing so, we deﬁne a novel canonical form for matrix product states, which has a high degree of regularity and ﬁxes the residual gauge that is left in the canonical forms based on singular value decompositions. We supplement the analytical ﬁndings with practical examples where matrix product states are trained on datasets of medical records, which show large reductions on the probability of an attacker extracting information about the training dataset from the model’s parameters. Given the growing expertise in training tensor-network architectures, these results imply that one may not have to be forced to make a choice between accuracy in prediction and ensuring the privacy of the information processed.  \n1 Introduction  \nVast amounts of data are routinely processed in machine learning pipelines, every time covering more aspects of our interactions with the world. When the models processing the data are made public, is the safety of the data used for training it guaranteed? This is a question of utmost importance when processing sensitive data such as medical records, but also for businesses whose competitive advantage lies in data quality.  \nThe gold standard in privacy protection within machine learning [1, 2] is provided by di􀀋erential privacy [3], which consists of inserting carefully crafted noise either in the training dataset [4, 5], in the 􀀌nal model parameters [3], in the objective function [6], or in the gradient updates [7], in order to hide the presence or absence of any particular sample in the training dataset. There exist, however, privacy-related issues that do not directly fall in this category. Imagine a machinelearning algorithm designed to diagnose a speci􀀌c disease, which uses patients' records as training data, and that these records have a strong imbalance in a particular morbidity which turns out to have no association to the disease target of the model. Even if irrelevant for the 􀀌nal task of the algorithm, knowing this imbalance may have consequences even at the individual level, if the participation of a patient in the study (in contrast with the knowledge of their full record) is disclosed by other means. As a 􀀌rst result, we show that this concern is a reality in machine learning architectures based on neural networks, caused by the driving of the corres","cbCail95goQeH5NM","https://ap.wps.com/l/cbCail95goQeH5NM","pdf",801143,1,16,"English","en",105,"# Introduction\n## Differential privacy and its limits\n## Vulnerability in neural-network architectures\n## Tensor-network viewpoint and matrix product states\n## Informal observation and main theorem","[{\"question\":\"What privacy vulnerability does the work focus on in neural-network architectures?\",\"answer\":\"It presents a privacy vulnerability present in feedforward neural networks, and illustrates it using both synthetic and real-world datasets.\"},{\"question\":\"How does the paper guarantee robustness against the described vulnerability?\",\"answer\":\"It develops well-defined conditions that ensure robustness, based on characterizing models equivalent under gauge symmetry.\"},{\"question\":\"Why are tensor-network architectures, especially matrix product states, highlighted as promising?\",\"answer\":\"The paper rigorously proves that the robustness conditions hold for tensor-network architectures, defines a novel canonical form for MPS, and shows that training MPS on medical-record datasets reduces an attacker’s ability to extract training information from model parameters.\"}]","Privacy-preserving machine learning with tensor networks - Research and analysis | PDF",1785719852,40,{"code":4,"msg":31,"data":32},"ok",{"site_id":24,"language":23,"slug":33,"title":13,"keywords":34,"description":14,"schema_data":35,"social_meta":87,"head_meta":89,"extra_data":91,"updated_unix":28},"privacy-preserving-machine-learning-with-tensor-networks-research-and-analysis","",{"@graph":36,"@context":86},[37,54,69],{"@type":38,"itemListElement":39},"BreadcrumbList",[40,44,48,51],{"item":41,"name":42,"@type":43,"position":20},"https://docshare.wps.com","Home","ListItem",{"item":45,"name":46,"@type":43,"position":47},"https://docshare.wps.com/document/","Document",2,{"item":49,"name":12,"@type":43,"position":50},"https://docshare.wps.com/document/research-report/",3,{"item":52,"name":13,"@type":43,"position":53},"https://docshare.wps.com/document/privacy-preserving-machine-learning-with-tensor-networks-research-and-analysis/118709/",4,{"url":52,"name":13,"@type":55,"author":56,"headline":13,"publisher":58,"fileFormat":61,"inLanguage":23,"description":14,"dateModified":62,"datePublished":63,"encodingFormat":61,"isAccessibleForFree":64,"interactionStatistic":65},"DigitalDocument",{"name":9,"@type":57},"Person",{"url":41,"name":59,"@type":60},"DocShare","Organization","application/pdf","2026-08-04","2026-08-03",true,{"@type":66,"interactionType":67,"userInteractionCount":20},"InteractionCounter",{"@type":68},"ViewAction",{"@type":70,"mainEntity":71},"FAQPage",[72,78,82],{"name":73,"@type":74,"acceptedAnswer":75},"What privacy vulnerability does the work focus on in neural-network architectures?","Question",{"text":76,"@type":77},"It presents a privacy vulnerability present in feedforward neural networks, and illustrates it using both synthetic and real-world datasets.","Answer",{"name":79,"@type":74,"acceptedAnswer":80},"How does the paper guarantee robustness against the described vulnerability?",{"text":81,"@type":77},"It develops well-defined conditions that ensure robustness, based on characterizing models equivalent under gauge symmetry.",{"name":83,"@type":74,"acceptedAnswer":84},"Why are tensor-network architectures, especially matrix product states, highlighted as promising?",{"text":85,"@type":77},"The paper rigorously proves that the robustness conditions hold for tensor-network architectures, defines a novel canonical form for MPS, and shows that training MPS on medical-record datasets reduces an attacker’s ability to extract training information from model parameters.","https://schema.org",{"og:url":52,"og:type":88,"og:title":13,"og:site_name":59,"og:description":14},"article",{"robots":90,"canonical":52},"index,follow",{"doc_id":7,"site_id":24},{"code":4,"msg":5,"data":93},[94,98,102,106,111,116,120,123,128,131,135],{"id":20,"doc_module":4,"doc_module_name":46,"category_name":95,"show_sort_weight":96,"slug":97},"Story & Novel",90,"story-novel",{"id":47,"doc_module":4,"doc_module_name":46,"category_name":99,"show_sort_weight":100,"slug":101},"Literature",80,"literature",{"id":53,"doc_module":4,"doc_module_name":46,"category_name":103,"show_sort_weight":104,"slug":105},"Exam",70,"exam",{"id":107,"doc_module":4,"doc_module_name":46,"category_name":108,"show_sort_weight":109,"slug":110},5,"Comic",60,"comic",{"id":112,"doc_module":4,"doc_module_name":46,"category_name":113,"show_sort_weight":114,"slug":115},6,"Technology",50,"technology",{"id":117,"doc_module":4,"doc_module_name":46,"category_name":118,"show_sort_weight":29,"slug":119},7,"Healthcare","healthcare",{"id":11,"doc_module":4,"doc_module_name":46,"category_name":12,"show_sort_weight":121,"slug":122},30,"research-report",{"id":124,"doc_module":4,"doc_module_name":46,"category_name":125,"show_sort_weight":126,"slug":127},9,"Religion & Spirituality",20,"religion-spirituality",{"id":126,"doc_module":4,"doc_module_name":46,"category_name":129,"show_sort_weight":126,"slug":130},"World Cup","world-cup",{"id":132,"doc_module":4,"doc_module_name":46,"category_name":133,"show_sort_weight":132,"slug":134},10,"Lifestyle","lifestyle",{"id":136,"doc_module":4,"doc_module_name":46,"category_name":137,"show_sort_weight":107,"slug":138},19,"General","general"]