Beyond Private Training: The New Landscape of AI Privacy
Abstract
The rapid deployment of Large Language Models has underscored privacy as a critical and evolving frontier in artificial intelligence. Historically, the pursuit of privacy-preserving AI has been heavily anchored to the training phase, relying predominantly on Differentially Private Stochastic Gradient Descent. However, as the landscape of AI applications rapidly shifts toward efficient, inference-time, and non-finetuning paradigms, a significant mismatch in the current research ecosystem has been exposed. While academic literature remains disproportionately focused on privacy problems tied to the training and fine-tuning stages, industry practitioners are actively confronting novel vulnerabilities that training-stage interventions simply cannot address. These emerging challenges include the generation of differentially private synthetic data strictly at inference time, cascading data leakages within multi-step autonomous agentic systems, and privacy risks in in-context learning. The primary objective of the "Beyond Private Training: The New Landscape of AI Privacy" workshop is to call for a paradigm shift, moving the privacy discourse forward beyond the training stage. By gathering privacy researchers from both industry and academia, alongside non-privacy AI domain experts, we aim to collectively define the most pressing emerging privacy problems and synchronize theoretical rigor with production-level deployments. Furthermore, this workshop will invert the traditional paradigm by exploring how advanced foundation models can actively enforce data sanitization, verify mathematical privacy guarantees, and advance the theoretical foundations of differential privacy. Ultimately, this workshop seeks to establish robust privacy frameworks for non-finetuning scenarios before they become locked-in legacy infrastructure.